20 May 2026 5 min read Security
How to receive and handle externally reported vulnerabilities responsibly and to expectation.
Why you need a policy
A published CVD policy gives researchers a safe channel to report issues and sets expectations on acknowledgement and timelines. The CRA expects coordinated handling.
Minimum policy elements
- A clear contact point (e.g. security.txt / dedicated address).
- Scope and safe-harbour language.
- Acknowledgement and status-update commitments.
- A disclosure timeline.
Run it
Log every report, keep the reporter informed, and feed confirmed issues into your vulnerability-handling loop.
This is an educational explainer. For the canonical regulation reference, see the dedicated Security page — or run an assessment to see how it applies to your product.