Skip to main content

CVD (Coordinated Vulnerability Disclosure)

CVD (Coordinated Vulnerability Disclosure) is the coordinated process through which security researchers and other reporters report vulnerabilities to the manufacturer, with details published only after a remedy is available. The EU Cyber Resilience Act makes a CVD policy a manufacturer obligation. The underlying idea: manufacturers get time for a solution before attackers learn of the vulnerability — and reporters get a reliable, fair point of contact.

How does Coordinated Vulnerability Disclosure work?

The CVD process typically involves three roles: the reporter (such as a security researcher or customer), the manufacturer and, if needed, a coordinator such as a national CSIRT when several parties are affected or direct communication fails. The process follows a fixed pattern:

  1. Report: the reporter submits the vulnerability via the manufacturer’s published channel — ideally with reproduction steps or a proof of concept.
  2. Triage and confirmation: the manufacturer assesses the report, confirms receipt and classifies the vulnerability.
  3. Remediation: the manufacturer develops and distributes a remedy — patch, update or mitigation measure.
  4. Coordinated publication: only then are the details disclosed, usually as a security advisory, often with a CVE ID.

This is to be distinguished from full disclosure, where details are published immediately, and from silent non-disclosure, where users never learn of the vulnerability. CVD is the middle way that has established itself as the industry standard.

CVD in the Cyber Resilience Act

Annex I Part II of the CRA requires manufacturers to publish and enforce a CVD policy: with a central point of contact for vulnerability reports and the active promotion of the exchange of information on potential vulnerabilities. These obligations become legally binding with full applicability on 11 December 2027.

One should not rely on this buffer: from 11 September 2026, the reporting obligations under Article 14 apply, and the 24-hour deadline for the early warning starts with awareness — external reports from researchers, customers or CSIRTs are one of the most frequent ways in which this awareness arises. A manufacturer without a functioning reporting channel installs the smoke detector only after the fire: the clock runs anyway, just unnoticed. A published reporting channel — for example a security.txt according to RFC 9116 plus a monitored security mailbox — therefore belongs among the first work packages of CRA preparation, not the last.

CVD in practice: one entry point, clear ownership

A CVD policy is only as good as the process behind it. Four building blocks have proven themselves: exactly one documented, monitored entry point for vulnerability reports with clear ownership for triage; a designated role that is authorised to determine awareness and documents this decision with a timestamp; prepared advisory templates and a publication location that customers know; and the connection to the company’s own vulnerability handling, so that the report is followed by remediation and — where necessary — notification to the authorities. If the reported vulnerability lies in a purchased component, reporting it back to the party responsible for that component is also part of the process.

Frequently asked questions

Is a CVD policy mandatory under the Cyber Resilience Act?
Yes. Annex I Part II of the CRA requires manufacturers to have a published CVD policy with a designated central point of contact; this becomes legally binding with full applicability on 11 December 2027. In practice, the reporting channel is needed earlier: the reporting obligations under Article 14 apply from 11 September 2026, and external reports are one of the most frequent triggers of the 24-hour deadline.
What belongs in a CVD policy?
A published reporting channel — for example a security.txt according to RFC 9116 with a monitored security mailbox —, a designated point of contact, the promised response steps and timeframes, rules for coordinated publication, and assurances for reporters who play by the rules.
What is the difference between CVD and a bug bounty programme?
CVD is the fundamental process through which vulnerability reports arrive and are handled in an orderly manner — without rewards. A bug bounty programme builds on top of it and rewards reporters financially in order to specifically attract security researchers. A bounty programme can complement a CVD policy, but not replace it.

Related terms

Reviewed by Dirk Leopold, Executive Vice President Digital Engineering on July 20, 2026