Back to Knowledge Base
Knowledge Base · implementation

Coordinated vulnerability disclosure (CVD)

20 May 2026 5 min read Security

How to receive and handle externally reported vulnerabilities responsibly and to expectation.

Why you need a policy

A published CVD policy gives researchers a safe channel to report issues and sets expectations on acknowledgement and timelines. The CRA expects coordinated handling.

Minimum policy elements

  • A clear contact point (e.g. security.txt / dedicated address).
  • Scope and safe-harbour language.
  • Acknowledgement and status-update commitments.
  • A disclosure timeline.

Run it

Log every report, keep the reporter informed, and feed confirmed issues into your vulnerability-handling loop.

This is an educational explainer. For the canonical regulation reference, see the dedicated Security page — or run an assessment to see how it applies to your product.