Basic CVD Policy Template
A straightforward coordinated vulnerability disclosure policy aligned with ISO/IEC 29147. Covers the core commitments expected by security researchers and satisfies CRA Article 13 requirements.
Free Template Library
Free, CRA-compliant vulnerability disclosure policy templates and technical documentation starters for EU manufacturers. Copy, customise, and deploy, or use CVD Portal to manage the full process automatically.
Select the baseline policy template matching your specific regulatory scope, target audience, or terminology preference.
A straightforward coordinated vulnerability disclosure policy aligned with ISO/IEC 29147. Covers the core commitments expected by security researchers and satisfies CRA Article 13 requirements.
A comprehensive CVD policy structured specifically for the EU Cyber Resilience Act. Addresses Articles 13 and 14 obligations including 24-hour early warning, 72-hour full notification, and coordinated disclosure timelines.
A CVD policy template specifically written for EU manufacturers placing products on the European market. References EU-specific obligations (CRA, NIS2 intersection, ENISA), using terminology aligned with EU regulatory guidance.
A responsible disclosure policy template for manufacturers and software publishers. Uses 'responsible disclosure' terminology familiar to the security research community while meeting CRA Article 13 obligations.
A complete coordinated vulnerability disclosure policy following ISO/IEC 29147 best practice and CRA Article 13. Covers the full disclosure lifecycle: intake, triage, remediation, and coordinated publication.
Tailored policies for specialized hardware, supply chain roles, and regulated sector requirements.
A CVD policy template for manufacturers of medical devices with digital elements. Navigates the intersection of the EU Cyber Resilience Act, the Medical Device Regulation (MDR), and international medical device cybersecurity guidance. Emphasises patient safety as the primary escalation trigger.
A CVD policy template tailored to the specific challenges of IoT and connected device manufacturers: long product lifespans, constrained firmware update mechanisms, heterogeneous fleets, and supply chain complexity. Structured for CRA compliance.
A CVD policy template for manufacturers of industrial control systems (ICS), SCADA components, PLCs, HMIs, and other operational technology (OT) products. Addresses the unique challenges of OT environments: operational continuity requirements, long deployment cycles, critical infrastructure obligations, and sector-specific regulatory coordination.
A CVD policy template for Original Equipment Manufacturers (OEMs) that supply components, modules, chipsets, firmware, or subsystems to downstream branded product manufacturers. Addresses the CRA's supply chain security obligations and the unique coordination challenges of operating in the middle of the product value chain.
A CVD policy template for contract manufacturers (Electronics Manufacturing Services / EMS companies and Original Design Manufacturers / ODMs) that build products on behalf of brand owners. Addresses how to manage vulnerability disclosures for products you manufacture but do not own or sell under your own name, including coordination with brand owners and their CRA compliance obligations.
Mandatory technical documentation, user instructions, and regulatory declarations required under Regulation (EU) 2024/2847.
A structured template for the technical file required by Article 31 and Annex VII of the EU Cyber Resilience Act. Covers the required content areas, from product description and cybersecurity risk assessment through support period justification, standards applied, test reports, and the EU Declaration of Conformity.
A field-by-field EU Declaration of Conformity template structured on CRA Annex V. Each section covers one required element of the declaration, from product identification through to signature, with guidance on Article 28 obligations and the simplified Annex IX option.
A fill-in template for the user information and instructions required by Annex II of the Cyber Resilience Act. It covers all eight Annex II items, from manufacturer identity and the vulnerability reporting contact through to the support period end date and secure decommissioning instructions.
A structured notification template for the CRA Article 14 24-hour early warning obligation. Designed to be submitted to ENISA (or the relevant national CSIRT) when a manufacturer discovers an actively exploited vulnerability or severe security incident.
A ready-to-use security.txt file template following RFC 9116. The security.txt standard provides a standardised machine-readable location for vulnerability disclosure contact information, satisfying part of the CRA Article 13 requirement for a publicly accessible single point of contact for security researchers.
Formal charters and operational procedures for product security incident response teams.
A formal charter for establishing or formalising a Product Security Incident Response Team (PSIRT). Defines the team's mandate, authority, scope, membership, and operating procedures under the EU Cyber Resilience Act and ISO/IEC 30111.
An internal-facing vulnerability reporting process that documents how your security team handles incoming reports from intake through resolution. Complements your public CVD policy with operational procedures aligned to CRA Article 13 and 14.
An internal security incident notification policy for manufacturers, covering escalation procedures, Article 14 regulatory notification, and user communication. Designed to sit alongside your CVD policy as an internal-facing document.
Pre-filled STRIDE threat models, starter asset inventories, and risk criteria ready to customize or seed into CVD Portal.
A pre-filled Cyber Resilience Act risk assessment for a field gateway aggregating soil, weather and machinery sensors over LPWAN, with a cloud backhaul and a farm-management app. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.
A pre-filled Cyber Resilience Act risk assessment for a connected-vehicle telematics service and its backend, covering the digital elements an OEM or supplier places on the market outside type approval. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.
A pre-filled Cyber Resilience Act risk assessment for a centralised controller that discovers, configures and monitors switching, routing and wireless infrastructure. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.
A pre-filled Cyber Resilience Act risk assessment for a next-generation firewall or intrusion detection and prevention appliance inspecting traffic at a network boundary. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.
A pre-filled Cyber Resilience Act risk assessment for a programmable logic controller or edge automation controller driving plant equipment, engineered and maintained by an integrator. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.
A pre-filled Cyber Resilience Act risk assessment for a autonomous mobile robot or cobot controller with fleet management, teleoperation and over-the-air updates. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.
A pre-filled Cyber Resilience Act risk assessment for a consumer hub integrating smart locks, cameras and alarm sensors, paired to a mobile app and a vendor cloud. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.
A pre-filled Cyber Resilience Act risk assessment for a smart metering gateway aggregating consumption data and mediating access between meters, grid operators and consumers. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.
A pre-filled Cyber Resilience Act risk assessment for a customer-premises or carrier-grade routing equipment with a remote management plane and operator-pushed firmware. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.
A pre-filled Cyber Resilience Act risk assessment for a iP camera and recorder combination with motion analytics, remote viewing and operator-managed retention. It covers the Annex III/IV classification and the conformity route that follows from it, a starter asset inventory, a STRIDE threat analysis mapped to Annex I Part I essential cybersecurity requirements, and the likelihood and impact scales those threats are scored against. Treat it as a first draft to challenge and replace with your own product's specifics before it becomes a technical file.
CVD Portal provides a complete vulnerability disclosure programme with a public submission portal, 48-hour acknowledgment tracking, audit trail, and CSAF advisory generation. Receiving and tracking reports is free. Article 14 filing is on Reporting (the September 2026 requirement).
Set up your free portal