← All tools
Free Tool

CVD Policy Generator

Build a complete, publication-ready CVD policy document using a guided five-step wizard. Configure your response timelines, CRA Article 13 and 14 obligations, and product scope, then export a finished Markdown policy you can publish immediately.

Last updated 1 September 2026

Key takeaways

  1. Article 13(8) requires manufacturers to have a coordinated vulnerability disclosure policy, and the policy must be publicly accessible.
  2. A compliant CVD policy must specify reporting channels, acknowledgment timelines, remediation targets, and coordinated disclosure rules.
  3. The policy must include commitments to report actively exploited vulnerabilities to ENISA under Article 14 obligations.
  4. Coordinated vulnerability disclosure standard practice relies on an agreed embargo period of 90 days to develop remediation patches.

Step 1Company

Required by CRA Article 13 — a single, publicly accessible contact.

Live preview
# Coordinated Vulnerability Disclosure Policy
**[COMPANY NAME]** | https://[YOURDOMAIN.COM]/security

## 1. Introduction
[COMPANY NAME] is committed to the security of our products and services. We welcome reports from security researchers, customers, and partners who discover potential security vulnerabilities. This Coordinated Vulnerability Disclosure (CVD) Policy describes how to report vulnerabilities and what you can expect from us in return.

This policy is maintained in compliance with the EU Cyber Resilience Act (Regulation (EU) 2024/2847), Article 13, and ISO/IEC 29147.

## 2. Scope
This policy applies to all [COMPANY NAME] products and services.

This policy also covers associated cloud services and APIs operated by [COMPANY NAME].

## 3. How to Report
Report security vulnerabilities to our security team via:

- **Email:** security@[YOURDOMAIN.COM]

Please include:
- Product name and version
- Description of the vulnerability and its potential impact
- Step-by-step reproduction instructions
- Proof of concept (screenshots, code, or video)

## 4. Our Commitments
[COMPANY NAME] commits to the following response timeline:

| Milestone | Target |
|---|---|
| Acknowledgment | Within 48 hours |
| Initial severity assessment | Within 5 business days |
| Status updates | At least every 30 days |
| Critical patch | Within 7 days |
| High patch | Within 30 days |
| Medium patch | Within 90 days |

## 5. Coordinated Disclosure
[COMPANY NAME] requests a coordinated disclosure period of 90 days from the date of your report. We ask that you refrain from publishing vulnerability details until a patch or advisory is available, or until the 90-day period has elapsed.

If a vulnerability is actively being exploited, we may accelerate the timeline and issue an advisory with or without a complete fix. We will always notify you before public disclosure.

## 6. Safe Harbour
[COMPANY NAME] will not pursue legal action against researchers who:

- Discover and report vulnerabilities in good faith under this policy
- Limit testing to systems they own or have explicit permission to test
- Avoid intentional service disruption or data access beyond proof of concept
- Notify us before any public disclosure
- Comply with applicable law

Safe harbour does not extend to the following prohibited activities:

- Introducing malware, backdoors, or other malicious code
- Copying, editing, or deleting data beyond minimal proof of access
- Making changes to the system or its configuration
- Repeatedly accessing the system or sharing obtained access with others
- Brute-force attacks against systems or accounts
- Denial-of-service attacks
- Social engineering against our employees

## 7. Recognition
[COMPANY NAME] does not currently offer monetary rewards for vulnerability reports.

With your permission, we will acknowledge your contribution in the security advisory for the vulnerability.

## 8. CRA Article 14 Obligations
Where a reported vulnerability is actively exploited in the wild or constitutes a severe security incident, [COMPANY NAME] will notify ENISA within 24 hours (early warning) and 72 hours (full notification) under Article 14 of the EU Cyber Resilience Act.

---
*Last updated: 2026-09-13*

Copy the Markdown and publish it at https://yourcompany.com/security. CVD Portal hosts your policy and tracks compliance automatically.

Frequently asked

Is a CVD policy required under the CRA?+

Yes. Article 13(8) of the Cyber Resilience Act requires manufacturers of products with digital elements to have a policy for coordinated vulnerability disclosure in place. The policy must be publicly accessible and describe how vulnerability reports are handled, acknowledged, and remediated.

What should a CRA-compliant CVD policy include?+

A CRA-compliant policy requires several elements at minimum. It must define a contact channel for receiving reports, an acknowledgment timeline, and a remediation target. It must also set rules on coordinated public disclosure and include a commitment to notify ENISA under Article 14 when active exploitation is discovered. This generator covers all required sections.

Does the generated policy need legal review?+

The output provides a solid starting point based on CRA requirements, ISO 29147 good practice, and standard CVD practices. Have your legal counsel review it before publishing, especially if you operate across multiple EU member states.

What is an embargo period in a CVD policy?+

An embargo period is the agreed window - typically 90 days - during which the researcher and the vendor work together to produce a fix before the vulnerability details are publicly disclosed. The 90-day norm is established by Google Project Zero and widely adopted.

Other free CRA tools

CVSS CalculatorCalculate CVSS 3.1 base scores for vulnerability severity assessment. Includes guidance on whether the score triggers Article 14 notification obligations under the EU Cyber Resilience Act.Disclosure Deadline TrackerEnter a vulnerability report date and instantly see every critical deadline: Article 14 early warning, full notification, final report to ENISA, researcher 90-day embargo, and your internal acknowledgment SLA. Colour-coded status keeps you on track.Article 14 Notification Template BuilderBuild a complete Article 14 early-warning notification based on the fields required by CRA Article 14(2). Fill in your product details, exploitation status, and mitigation actions, then copy the finished notification text ready for submission to ENISA or your national CSIRT.CSAF 2.0 Advisory ValidatorPaste your CSAF 2.0 JSON advisory and instantly validate the structure against the OASIS CSAF 2.0 schema. Identifies missing mandatory fields, invalid values, and flags common issues that would cause rejection by automated consumers and ENISA tooling.SBOM Checker and Component CVE LookupThe SBOM checker matches software components against the NVD CVE database. Paste a component list in package@version form and the tool returns one NVD search link for each component, with no upload and no account.security.txt GeneratorGenerate a standards-compliant security.txt file (RFC 9116) for your product or website. The EU Cyber Resilience Act names no file format, and Annex I Part II point 6 requires a contact address for reporting vulnerabilities. security.txt is the machine-readable way to publish it.

Ready to automate your CVD programme?

CVD Portal integrates all these tools and handles your Article 13 and 14 obligations automatically.

Start your free portal →