Topic
Coordinated vulnerability disclosure
The CVD policy duty and the single point of contact.
Manufacturers have a coordinated vulnerability disclosure policy in place with a contact address for reporting F-043, provide a single point of contact for users to report vulnerabilities and receive information F-042, and disclose fixed vulnerabilities once a security update is available F-044.
The minimum credible setup
A security.txt file pointing to a monitored mailbox is a practical way to publish the contact point F-042, bearing in mind that Article 13(17) also asks that users can choose their preferred means of communication; a practical policy states scope, safe-harbour posture and expected timelines; the advisory template is written before the first report arrives F-044.
Verified facts this page relies on
- F-043 Manufacturers have a coordinated vulnerability disclosure policy in place and a contact address for reporting. Annex I Part II(5)–(6)
- F-042 The manufacturer provides a single point of contact for users to report vulnerabilities and to receive information about vulnerabilities. Art. 13(17), Annex I Part II(6)
- F-044 Manufacturers publicly disclose information about fixed vulnerabilities after a security update is available, including a description, affected products, impacts, severity and remediation information. Annex I Part II(4)
Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).
Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.