Get started in 5 minutes

Setting up your CVD portal is a critical step towards CRA compliance. Here's how our framework simplifies the process from registration to managing your first vulnerability disclosure.

1

Create your account

Sign up with your work email. Your branded portal will be instantly created.

  • Derived from your email domain (e.g., yourcompany.cvdportal.com)
  • Verify your email address
2

Customize your portal

Add your branding and CVD policy. Customize the submission form fields.

  • Upload your logo and set brand colors
  • Edit your CVD policy from our template
  • Add your PGP key for encrypted submissions
  • Configure email notifications
3

Share your portal

Publish your security contact page link for researchers to submit disclosures.

  • Add link to your website footer
  • Include in security.txt file
  • Share with security researchers
4

Manage submissions

Review and respond to vulnerability disclosures through your dashboard.

  • Receive instant email notifications
  • Acknowledge within 48 hours, a configurable portal default, then reply in person within five working days (BSI TR-03183-3)
  • Track status and communicate
  • Generate compliance reports
5

Meet Article 14 filing obligations

For actively exploited vulnerabilities and significant incidents, the CRA mandates three filing milestones to ENISA and your national CSIRT via the Single Reporting Platform (SRP).

  • 24h early warning, notify ENISA/CSIRT upon becoming aware
  • 72h detailed notification, full technical filing
  • Final report +14 days (exploited) or +1 month (incidents), with remediation details
  • Enterprise gets automated pre-filled ENISA reports. Free and Reporting use the guided manual workflow.

Why CVD Portal?

The EU Cyber Resilience Act requires all manufacturers of connected devices to have a vulnerability disclosure process. We make it easy for small and medium enterprises to comply without the overhead of building their own infrastructure.

0
Cost to start
<5 min
Setup time
48h
Acknowledgment SLA (portal default)