Free Template Library

CVD Policy & CRA Compliance Templates

Free, CRA-compliant vulnerability disclosure policy templates and technical documentation starters for EU manufacturers. Copy, customise, and deploy, or use CVD Portal to manage the full process automatically.

General Vulnerability Disclosure Policies

Select the baseline policy template matching your specific regulatory scope, target audience, or terminology preference.

Which general policy should you choose?
  • CRA-Compliant: Full legal coverage explicitly referencing EU CRA Articles 13 & 14.
  • Basic: Simple baseline policy aligned with ISO/IEC 29147 for SMEs.
  • EU CVD Policy: Written specifically for EU market placement with ENISA alignment.
  • Responsible Disclosure: Uses researcher-friendly community terminology and Hall of Fame options.
  • Coordinated Disclosure: Standard 90-day disclosure lifecycle model.

Sector-Specific CVD Policies

Tailored policies for specialized hardware, supply chain roles, and regulated sector requirements.

CRA Technical Files & Regulatory Declarations

Mandatory technical documentation, user instructions, and regulatory declarations required under Regulation (EU) 2024/2847.

CRA Risk Assessment Starters

Pre-filled STRIDE threat models, starter asset inventories, and risk criteria ready to customize or seed into CVD Portal.

Article 13Article 32Annex I Part IAnnex VFree

Agricultural IoT gateway CRA Risk Assessment Starter

A pre-filled Cyber Resilience Act risk assessment for a field gateway aggregating soil, weather and machinery sensors over LPWAN, with a cloud backhaul and a farm-management app. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.

View
Article 13Article 32Annex I Part IAnnex VFree

Vehicle telematics backend CRA Risk Assessment Starter

A pre-filled Cyber Resilience Act risk assessment for a connected-vehicle telematics service and its backend, covering the digital elements an OEM or supplier places on the market outside type approval. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.

View
Article 13Article 32Annex I Part IAnnex VFree

Network management system CRA Risk Assessment Starter

A pre-filled Cyber Resilience Act risk assessment for a centralised controller that discovers, configures and monitors switching, routing and wireless infrastructure. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.

View
Article 13Article 32Annex I Part IAnnex VFree

Firewall / IDS-IPS appliance CRA Risk Assessment Starter

A pre-filled Cyber Resilience Act risk assessment for a next-generation firewall or intrusion detection and prevention appliance inspecting traffic at a network boundary. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.

View
Article 13Article 32Annex I Part IAnnex VFree

Industrial controller (PLC) CRA Risk Assessment Starter

A pre-filled Cyber Resilience Act risk assessment for a programmable logic controller or edge automation controller driving plant equipment, engineered and maintained by an integrator. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.

View
Article 13Article 32Annex I Part IAnnex VFree

Mobile robot controller CRA Risk Assessment Starter

A pre-filled Cyber Resilience Act risk assessment for a autonomous mobile robot or cobot controller with fleet management, teleoperation and over-the-air updates. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.

View
Article 13Article 32Annex I Part IAnnex VFree

Smart home security hub CRA Risk Assessment Starter

A pre-filled Cyber Resilience Act risk assessment for a consumer hub integrating smart locks, cameras and alarm sensors, paired to a mobile app and a vendor cloud. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.

View
Article 13Article 32Annex I Part IAnnex VFree

Smart meter gateway CRA Risk Assessment Starter

A pre-filled Cyber Resilience Act risk assessment for a smart metering gateway aggregating consumption data and mediating access between meters, grid operators and consumers. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.

View
Article 13Article 32Annex I Part IAnnex VFree

Carrier router / CPE CRA Risk Assessment Starter

A pre-filled Cyber Resilience Act risk assessment for a customer-premises or carrier-grade routing equipment with a remote management plane and operator-pushed firmware. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.

View
Article 13Article 32Annex I Part IAnnex VFree

Network camera / NVR CRA Risk Assessment Starter

A pre-filled Cyber Resilience Act risk assessment for a iP camera and recorder combination with motion analytics, remote viewing and operator-managed retention. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.

View

Need more than a template?

CVD Portal provides a complete vulnerability disclosure programme with a public submission portal, 48-hour acknowledgment tracking, audit trail, and CSAF advisory generation. Receiving and tracking reports is free. Article 14 filing is on Reporting (the September 2026 requirement).

Set up your free portal