InsideCRA
InsideCRA › Topics › Coordinated vulnerability disclosure

Topic

Coordinated vulnerability disclosure

The CVD policy duty and the single point of contact.

Manufacturers have a coordinated vulnerability disclosure policy in place with a contact address for reporting F-043, provide a single point of contact for users to report vulnerabilities and receive information F-042, and disclose fixed vulnerabilities once a security update is available F-044.

The minimum credible setup

A security.txt file pointing to a monitored mailbox is a practical way to publish the contact point F-042, bearing in mind that Article 13(17) also asks that users can choose their preferred means of communication; a practical policy states scope, safe-harbour posture and expected timelines; the advisory template is written before the first report arrives F-044.

Verified facts this page relies on

Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).

Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.

Related in the reference

Ready to work through your obligations? Get your CE readiness verdict on CEMarque.