• CRA
  • CVD
  • Vulnerability management
  • NIST CSF

Coordinated vulnerability disclosure (CVD): the policy the CRA requires, in practice

Annex I, Part II of Regulation (EU) 2024/2847 requires manufacturers to have a coordinated vulnerability disclosure policy. What the policy must contain, the ISO/IEC 29147 and 30111 standards that structure it, the French framework (L. 2321-4 and L. 2321-4-1) and a proportionate implementation for an SME.

Komplyo4 min read

Coordinated vulnerability disclosure (CVD) is the process by which a person who discovers a vulnerability in a product reports it to the manufacturer, who handles it and publishes a fix before any public disclosure. Voluntary until now, the practice becomes a regulatory obligation: Annex I, Part II of Regulation (EU) 2024/2847 (Cyber Resilience Act) requires manufacturers of products with digital elements to put in place and enforce a CVD policy. The requirement applies with the rest of the essential requirements, on 11 December 2027, but in practice it underpins the Article 14 notification obligation, active since 11 September 2026: without an organised reporting channel, a manufacturer learns that a vulnerability is being exploited from the press rather than from a reporter. This article sets out what the policy must contain and how an SME puts it in place.

What the CRA requires of manufacturers

Part II of Annex I groups the vulnerability handling requirements, which apply throughout the product's support period. The manufacturer must identify and document the product's vulnerabilities and components, including in the form of a software bill of materials (SBOM). It must address vulnerabilities without delay, test the product's security regularly, and publish information about fixed vulnerabilities once the update is available. It must put in place and enforce a CVD policy, facilitate the sharing of information about potential vulnerabilities, including in third-party components, and provide a contact address for reporting them. Finally, it must distribute security updates through secure mechanisms, without delay and, unless otherwise agreed for a tailor-made product, free of charge.

The CVD policy is therefore one piece of a wider set: it organises the intake of reports, which the other Part II requirements then take over (handling, remediation, dissemination).

The two standards that structure the exercise

Two ISO standards cover the two sides of the process, and authorities cite them as the implementation reference. ISO/IEC 29147 (vulnerability disclosure) deals with the external interface: how to receive reports, communicate with the reporter, publish security advisories. ISO/IEC 30111 (vulnerability handling processes) deals with the internal side: how to qualify, prioritise, remediate and verify. For an SME, the useful reading is the minimum requirements: a published point of contact, acknowledgments of receipt, defined handling timelines, a documented decision for every report.

The existing French framework

French law already contains two mechanisms worth knowing. Article L. 2321-4 of the defence code allows any person to report a vulnerability in good faith to ANSSI (CERT-FR), which preserves the confidentiality of their identity; this is the channel a researcher uses when the manufacturer does not respond or has no point of contact. Article L. 2321-4-1, introduced by the 2024-2030 military programming law, requires publishers of software supplied in France to notify ANSSI of significant vulnerabilities and incidents affecting their products, and to inform their users. A French SME software vendor is therefore already covered by a national notification obligation, even before the CRA provisions apply.

A proportionate CVD policy in practice

For an SME, the policy fits on one page published on the website and covers five points. The scope: which products and versions are covered. The channel: a dedicated address (for example security@company.com), where appropriate described in a security.txt file at the root of the site (RFC 9116), with an encryption key if the company can manage one. The commitments: acknowledgment of receipt within a defined time, updates to the reporter on the handling, an indicative remediation timeline. The publication rules: who publishes what and when, once the fix is available, which matches the disclosure requirement of Annex I. The good-faith framework: what the company undertakes not to do (legal action) when the reporter respects stated conditions (no data exfiltration, no impact on availability, no public disclosure before the fix).

The rest is internal tooling: a log of received reports, a link to the vulnerability management process (qualification, remediation, update) and, since 11 September 2026, the reflex of checking whether the report reveals active exploitation, which triggers the Article 14 notification.

Attaching CVD to what already exists

In NIST CSF 2.0, receiving and processing vulnerability reports belongs to ID.RA (risk identification and analysis, including vulnerabilities) and the qualification of incoming reports to RS.MA (incident management). An SME that already has a vulnerability management process and a structured incident response essentially adds the public entry point and the commitments towards the reporter.

The CVD policy is one of the documents Komplyo generates from the assessment, along with the associated policies: the content reflects the observed practices (channel, timelines, remediation process) rather than a boilerplate commitment the company would not keep. The free diagnostic (23 questions, around 5 minutes) gives a first reading of the functions involved.

Sources

Get the security policy template

An information security policy template in .docx format, structured around NIST CSF 2.0 and ISO 27001. Delivered by email, usable as a documentation baseline.

No spam. Unsubscribe in one click.