Definition
Coordinated vulnerability disclosure (CVD)
A published policy and process for receiving vulnerability reports from third parties and fixing and disclosing them in coordination — required by Annex I Part II.
The process by which a manufacturer receives vulnerability reports from researchers, customers and other third parties, acknowledges them, remediates and discloses the fix in coordination with the reporter. Annex I Part II(5) requires manufacturers to put in place and enforce a CVD policy; Part II(6) requires a contact address. ISO/IEC 29147 describes disclosure and ISO/IEC 30111 the internal handling process; RFC 9116 (security.txt) is the conventional way to publish the contact.
Reference: Annex I Part II(5)–(6); ISO/IEC 29147; RFC 9116 · Regulation (EU) 2024/2847 on EUR-Lex
Updated 2026-09-12 · Paraphrase for orientation, not legal advice.