Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What does the CRA require for coordinated vulnerability disclosure?
Updated
If the CRA applies, Annex I Part II of Regulation (EU) 2024/2847 requires manufacturers to put in place and enforce a coordinated vulnerability disclosure policy and a contact address for reporters. That duty is not Article 14. This page is not legal advice and does not start a clock.
CRA coordinated-vulnerability-disclosure guide, last verified 9 September 2026 against Regulation (EU) 2024/2847 Annex I Part II points (5) and (6), Article 13(6) and 13(8), Annex II point 2, Annex VII, Recitals 63 and 76, and Article 71(2), with ENISA coordinated-vulnerability-disclosure materials labelled as agency guidance, not the regulation, and ISO/IEC 29147:2018 and ISO/IEC 30111:2019 labelled as international standards — best practice, not the CRA. It is not legal advice, not a filing, not a determination that the CRA applies, not CE marking, and not a substitute for counsel.
This is coordinated disclosure, not YOUR policy and not Article 14
Audience: a security lead, CISO, or product owner at an organisation that might be a manufacturer of products with digital elements under Regulation (EU) 2024/2847. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the CRA applies, that you are a manufacturer, that a product with digital elements has been made available on the Union market, that a reporter submission has been received, that you have become aware, or that an Article 14 filing is due.
Coordinated vulnerability disclosure (CVD) on this page means the manufacturer's policy and contact channel for receiving vulnerability reports so the manufacturer can diagnose and remedy before detailed information is disclosed to third parties or to the public. That is Annex I Part II and Article 13(8). Article 14 is a different duty: notifying the CSIRT designated as coordinator and ENISA of an actively exploited vulnerability or a severe incident via the single reporting platform. A reporter email is not an Article 14 filing. Last verified 9 September 2026. Not legal advice.
- Statute versus guidance versus standards: Annex I Part II points (5) and (6), Article 13(6) and 13(8), Annex II point 2, and Annex VII are legal requirements only if the CRA applies. Recitals 63 and 76 aid interpretation; they are not operative articles. ENISA coordinated-vulnerability-disclosure pages and reports are agency guidance, not the regulation. ISO/IEC 29147:2018 and ISO/IEC 30111:2019 are international standards — best practice, not the CRA. This page quotes which kind of text it is relying on.
- The CRA overview on this site is the pillar page. The who-is-covered guide on this site is the economic-operator roles page. The SaaS-scope guide on this site is the remote-processing versus service page. The CRA-cluster Article 14 overview on this site is how Article 14 sits in the cluster. The statute-clock Article 14 guide on this site is the ladder under breach reporting. The where-to-submit guide on this site is the Article 14 channel page. The ENISA-workflow guide on this site is the single-reporting-platform walkthrough. The CSIRT guide on this site is the coordinator-interaction page.
- A dedicated vulnerability-management, security-updates, and readiness-checklist guide is not on this site yet. Naming them is not a link.
What Annex I Part II actually requires — not a determination
Annex I Part II sets essential cybersecurity requirements relating to vulnerability handling. The CVD rows are point (5) and point (6). Article 13(8) points manufacturers at those policies for reports from internal or external sources. Annex II point 2 is user information about the single point of contact and where the policy can be found. Those texts apply from 11 December 2027 (Article 71(2), first subparagraph). Article 14 reporting applies from 11 September 2026. Those two dates are not one number. This table is not YOUR policy. Last verified 9 September 2026. Not legal advice.
| Duty | What the cited text says | Kind of text | Last verified |
|---|---|---|---|
| Put in place and enforce a CVD policy | Annex I Part II point (5): manufacturers of products with digital elements shall put in place and enforce a policy on coordinated vulnerability disclosure. | Legal requirement — Annex I Part II point (5). Only if the CRA applies. This page does not find that YOUR policy exists or is enforced. | 9 September 2026 |
| Contact address for reporting | Annex I Part II point (6): take measures to facilitate the sharing of information about potential vulnerabilities in their product with digital elements as well as in third-party components contained in that product, including by providing a contact address for the reporting of the vulnerabilities discovered in the product with digital elements. | Legal requirement — Annex I Part II point (6). This page does not name YOUR contact address. | 9 September 2026 |
| Policies and procedures for internal and external reports | Article 13(8), third subparagraph: manufacturers shall have appropriate policies and procedures, including coordinated vulnerability disclosure policies, referred to in Part II, point (5), of Annex I to process and remediate potential vulnerabilities in the product with digital elements reported from internal or external sources. | Legal requirement — Article 13(8). Applies from 11 December 2027 (Article 71(2)). Not Article 14. | 9 September 2026 |
| Single point of contact in user information | Annex II point 2: the information and instructions to the user shall include the single point of contact where information about vulnerabilities of the product with digital elements can be reported and received, and where the manufacturer's policy on coordinated vulnerability disclosure can be found. | Legal requirement — Annex II point 2. This page does not write YOUR user information. | 9 September 2026 |
| Technical documentation includes the CVD policy | Annex VII: the technical documentation shall include the necessary information and specifications of the vulnerability handling processes put in place by the manufacturer, including the software bill of materials, the coordinated vulnerability disclosure policy, evidence of the provision of a contact address for the reporting of the vulnerabilities, and a description of the technical solutions chosen for the secure distribution of updates. | Legal requirement — Annex VII. This page does not keep YOUR technical documentation. | 9 September 2026 |
| Component vulnerabilities reported to the maintainer | Article 13(6): manufacturers shall, upon identifying a vulnerability in a component, including in an open-source component, which is integrated in the product with digital elements, report the vulnerability to the person or entity manufacturing or maintaining the component, and address and remediate it in accordance with Annex I Part II. Where they have developed a software or hardware modification to address that vulnerability, they shall share the relevant code or documentation with that person or entity, where appropriate in a machine-readable format. | Legal requirement — Article 13(6). This page does not find that YOUR component report is due. | 9 September 2026 |
Single point of contact — Annex II, Recital 63, and Annex I Part II point (6)
Three texts talk about how reporters reach the manufacturer. They are not the same kind of text. Annex I Part II point (6) is an essential requirement: a contact address. Annex II point 2 is user information: a single point of contact, and where the CVD policy can be found. Recital 63 explains that manufacturers should put in place a single point of contact so users can communicate easily, including to report and receive information about vulnerabilities, make it easily accessible, indicate availability, and keep it updated; where they choose automated tools, for example chat boxes, they should also offer a telephone number or other digital contact means, such as an email address or a contact form. Recital 63 is a recital, not an operative article. Last verified 9 September 2026. Not legal advice.
- This page does not name YOUR contact address, does not host YOUR public mailbox, and does not treat a signed-in product surface as the Annex II single point of contact.
- A security.txt file, a web form, or a mailbox may be how reporters find you. None of those formats is named as the exclusive CRA channel. Counsel maps YOUR facts to Annex I Part II point (6) and Annex II point 2.
| Text | What it says | Kind of text | Last verified |
|---|---|---|---|
| Annex I Part II point (6) | A contact address for the reporting of vulnerabilities discovered in the product with digital elements, as part of measures to facilitate sharing of information about potential vulnerabilities, including in third-party components. | Legal requirement — essential cybersecurity requirement. Only if the CRA applies. | 9 September 2026 |
| Annex II point 2 | The single point of contact where information about vulnerabilities can be reported and received, and where the manufacturer's CVD policy can be found — included in the information and instructions to the user. | Legal requirement — user information. This page does not find that YOUR packaging or website states it. | 9 September 2026 |
| Recital 63 | A single point of contact that is easily accessible, with availability indicated and kept updated. Automated tools (for example chat boxes) do not replace a telephone number or other digital contact means such as an email address or a contact form. | Recital — not an operative article. Aids interpretation of the contact-channel duties. | 9 September 2026 |
Handling reporter submissions — structured process, not a filing
Recital 76: manufacturers of products with digital elements should put in place coordinated vulnerability disclosure policies to facilitate the reporting of vulnerabilities by individuals or entities either directly to the manufacturer or indirectly, and where requested anonymously, via CSIRTs designated as coordinators for the purposes of coordinated vulnerability disclosure in accordance with Article 12(1) of Directive (EU) 2022/2555. The policy should specify a structured process through which vulnerabilities are reported to a manufacturer in a manner allowing the manufacturer to diagnose and remedy such vulnerabilities before detailed vulnerability information is disclosed to third parties or to the public. Recital 76 also says manufacturers should consider publishing their security policies in machine-readable format, and that they should be able to use programmes as part of those policies to incentivise reporting by recognition and compensation — so-called bug bounty programmes. Recital 76 is a recital, not an operative article. Last verified 9 September 2026. Not legal advice.
- Receiving a reporter submission is not becoming aware of an actively exploited vulnerability under Article 3(42). Counsel maps YOUR facts. This page does not start a clock.
- Indirect or anonymous reporting via a NIS2 CSIRT designated as coordinator is Recital 76 plus NIS2 Article 12(1). It is not the CRA Article 14 filing desk. The CSIRT guide on this site is Article 14 coordinator interaction. The NIS2 incident-reporting guide on this site is Article 23 — a different instrument.
| Point | What the cited text says | Kind of text | Last verified |
|---|---|---|---|
| Who may report | Recital 76: individuals or entities, either directly to the manufacturer or indirectly, and where requested anonymously, via CSIRTs designated as coordinators under NIS2 Article 12(1). | Recital — not an operative article. NIS2 Article 12(1) is a different instrument (national CVD coordinators). | 9 September 2026 |
| What the policy specifies | Recital 76: a structured process that lets the manufacturer diagnose and remedy before detailed vulnerability information is disclosed to third parties or to the public. | Recital — not an operative article. Annex I Part II point (5) is the legal requirement to put in place and enforce a policy; it does not write YOUR process steps. | 9 September 2026 |
| Internal and external sources | Article 13(8): process and remediate potential vulnerabilities reported from internal or external sources, using the CVD policies referred to in Annex I Part II point (5). | Legal requirement — Article 13(8). This page does not find that YOUR inbox has a report. | 9 September 2026 |
| Machine-readable publication and bug bounty | Recital 76: manufacturers should consider publishing their security policies in machine-readable format, and should be able to use recognition-and-compensation programmes as part of CVD policies. | Recital — not an operative article. A bug bounty is not a CRA essential requirement. This page does not require YOU to run one. | 9 September 2026 |
| Public information about fixed vulnerabilities | Annex I Part II point (4): once a security update has been made available, share and publicly disclose information about fixed vulnerabilities, including a description, how users identify the affected product, impacts, severity, and clear information helping users remediate; in duly justified cases, where manufacturers consider the security risks of publication to outweigh the security benefits, they may delay making public information regarding a fixed vulnerability until after users have been given the possibility to apply the relevant patch. | Legal requirement — Annex I Part II point (4). Distinct from the CVD intake policy in point (5). A dedicated security-updates guide is not on this site yet. Naming it is not a link. | 9 September 2026 |
How CVD sits next to Article 14 — two duties, two dates
A reporter submission to the manufacturer's CVD channel is intake. Article 14 is a manufacturer notification to the CSIRT designated as coordinator and to ENISA via the single reporting platform, of an actively exploited vulnerability or a severe incident. Those two duties can meet on the same facts. They are not the same filing. This page does not start an Article 14 clock. Last verified 9 September 2026. Not legal advice.
- If a reporter submission contains, or later becomes, reliable evidence that a malicious actor has exploited a vulnerability in a system without permission of the system owner, Article 3(42) and Article 14(1) may be in play. This page does not find that. A named human still files. The statute-clock Article 14 guide on this site is the ladder.
- Article 16(2) lets the CSIRT designated as coordinator delay dissemination of an Article 14 notification on justified cybersecurity-related grounds, including where a vulnerability is subject to a coordinated vulnerability disclosure procedure as referred to in NIS2 Article 12(1). That is a CSIRT decision after a filing, not the manufacturer's CVD policy. The CSIRT guide on this site is that delay. A manufacturer CVD process is not an Article 16(2) delay.
- Article 15 voluntary reporting of vulnerabilities is a different stream from both the manufacturer's CVD channel and the Article 14 mandatory ladder. This page does not treat a reporter email as an Article 15 notification.
| Point | CVD policy (Annex I Part II / Article 13(8)) | Article 14 reporting | Kind of text |
|---|---|---|---|
| What it is | Put in place and enforce a policy; provide a contact address; process reports from internal or external sources. | Notify an actively exploited vulnerability or a severe incident simultaneously to the CSIRT designated as coordinator and to ENISA via the single reporting platform. | Legal requirement — only if the CRA applies. This page does not apply either duty to YOU. |
| When it applies | 11 December 2027 — Article 71(2), first subparagraph (the rest of the Regulation, including Annex I essential requirements and Article 13). | 11 September 2026 — Article 71(2), second subparagraph. Article 69(3) applies those Article 14 duties to in-scope products placed on the market before 11 December 2027. | Article 71(2) and Article 69(3). Those two dates are not one number. |
| Recipient | Reporters (individuals or entities) to the manufacturer, via the contact address / single point of contact. Recital 76 also describes an indirect path via a NIS2 CVD coordinator CSIRT. | The CSIRT designated as coordinator and ENISA, via the Article 16 single reporting platform. The where-to-submit guide on this site is that channel. | Annex I Part II / Annex II versus Articles 14 and 16. |
| Clock | Annex I Part II point (5) does not state a 24-hour, 72-hour, or 14-day mark for acknowledging a reporter. This page does not invent one. | 24-hour early warning and 72-hour notification from becoming aware; 14-day final report after a corrective or mitigating measure is available on the actively-exploited track. The statute-clock Article 14 guide on this site is the ladder. | Legal requirement — Article 14. This page does not start that clock. |
| Does one discharge the other? | No. Hosting or enforcing a CVD policy does not file Article 14. | No. An Article 14 notification does not put a CVD policy in place. | This page does not treat either as a substitute for the other. |
ISO/IEC 29147 and 30111 are best practice, not the CRA
ISO/IEC 29147:2018 (Information technology — Security techniques — Vulnerability disclosure) provides requirements and recommendations to vendors on receiving reports about potential vulnerabilities and disclosing remediation information. ISO/IEC 30111:2019 (Information technology — Security techniques — Vulnerability handling processes) provides requirements and recommendations for how to process and remediate reported potential vulnerabilities; it is intended to be used with ISO/IEC 29147. Those documents are international standards. They are best practice. They are not Regulation (EU) 2024/2847. Last verified 9 September 2026. Not legal advice.
The CRA does not say that complying with ISO/IEC 29147 or ISO/IEC 30111 is the legal requirement. Annex I Part II point (5) is the CRA text: put in place and enforce a policy on coordinated vulnerability disclosure. A later harmonised standard under the CRA may cite those ISO/IEC documents; as of last verification this page does not treat a cited ISO/IEC standard as a rewrite of Annex I. Counsel maps YOUR facts.
| Text | What it is | What this page does not do |
|---|---|---|
| Regulation (EU) 2024/2847 Annex I Part II points (5) and (6), Article 13(6) and 13(8), Annex II point 2, Annex VII, Article 71(2) | Legal requirement — the regulation, only if it applies. | Does not apply those provisions to YOU, and does not treat an ISO/IEC standard as a substitute. |
| Recitals 63 and 76 | Recitals. Aid interpretation. Not operative articles. | Does not treat a recital as Annex I Part II point (5). |
| ISO/IEC 29147:2018 — Vulnerability disclosure | International standard. Best practice on receiving reports and disclosing remediation information. Not the CRA. | Does not treat ISO/IEC 29147 as the CRA, and does not find that YOUR policy conforms to it. |
| ISO/IEC 30111:2019 — Vulnerability handling processes | International standard. Best practice on processing and remediating reported potential vulnerabilities. Intended to be used with ISO/IEC 29147. Not the CRA. | Does not treat ISO/IEC 30111 as Annex I Part II. |
| ENISA coordinated-vulnerability-disclosure topic page and 2022 report on national CVD policies in the EU | Agency materials. The 2022 report surveys national CVD policies. It is not the CRA manufacturer duty in Annex I Part II. | Does not treat an ENISA report as Annex I, and does not treat a national CVD policy as YOUR manufacturer policy. |
Legal requirement versus Commission, ENISA, and ISO/IEC materials
The table below labels each text. Do not treat an ISO/IEC standard as the article, and do not treat the article as optional because a standard exists. Last verified 9 September 2026. Not legal advice.
| Text | What it is | What this page does not do |
|---|---|---|
| Regulation (EU) 2024/2847 Annex I Part II, Articles 13, 14, 15, 16 and 71, Annex II, Annex VII | Legal requirement — the regulation, only if it applies. | Does not apply those articles to YOU. |
| Directive (EU) 2022/2555 Article 12(1) | NIS2 — CSIRTs designated as coordinators for national coordinated vulnerability disclosure. Context for Recital 76 and for CRA Article 3(51). A different instrument. | Does not treat a NIS2 CVD coordinator path as discharging Annex I Part II point (5) or Article 14. |
| European Commission CRA policy page (updated 7 September 2026) and CRA summary page | Commission materials. Guidance, not the regulation. | Does not treat a Commission summary as a substitute for Annex I Part II. |
| ENISA vulnerability-disclosure topic page and Coordinated Vulnerability Disclosure Policies in the EU (April 2022) | Agency guidance and a 2022 survey of national CVD policies. Not the regulation. | Does not treat an ENISA report as starting YOUR clock or writing YOUR policy. |
| ISO/IEC 29147:2018 and ISO/IEC 30111:2019 | International standards. Best practice, not the CRA. | Does not treat those standards as the legal requirement. |
Policy checklist — not a template of record
This is a question list distilled from the cited CRA text. It is not a legal template, not YOUR policy, and not a finding that a hosted document meets Annex I Part II point (5). Walk it with counsel. ISO/IEC 29147 and 30111 may structure a draft; they are best practice, not the CRA.
- Does the CRA apply? Manufacturer of a product with digital elements made available on the Union market — Articles 2 and 3. This page does not run that test. Marking CRA in an obligation map is not that determination.
- Is there a coordinated vulnerability disclosure policy, put in place and enforced — Annex I Part II point (5)? Hosting a draft is not enforcement.
- Is there a contact address for reporting vulnerabilities in the product, including in third-party components — Annex I Part II point (6)?
- Do the information and instructions to the user name the single point of contact and where the CVD policy can be found — Annex II point 2?
- Do the policies and procedures process reports from internal and external sources — Article 13(8)?
- Does the technical documentation include the CVD policy and evidence of the contact address — Annex VII?
- Is the structured process (Recital 76 — recital, not an operative article) clear enough that a reporter can submit, and the manufacturer can diagnose and remedy, before detailed public disclosure?
- If a report is, or becomes, an actively exploited vulnerability under Article 3(42), is Article 14 in play? This page does not start that clock. The statute-clock Article 14 guide on this site is the ladder. The where-to-submit guide on this site is the channel.
- Do not treat ISO/IEC 29147 as the CRA. Do not treat a NIS2 CSIRT CVD path as an Article 14 filing. Do not treat this product as publishing YOUR policy to users.
- Document the assessment, including a not-in-scope decision. This page does not keep YOUR file.
What to do now
As of last verification on 9 September 2026, Article 14 applies from 11 September 2026 — two days from that verification date. The Annex I Part II CVD-policy essential requirement applies from 11 December 2027. The list below is operational preparation. It is not a determination that the CRA applies to YOU, that you are a manufacturer, or that a reporting clock has started. Walk it with counsel.
- Ask counsel whether YOU are a manufacturer of a product with digital elements made available on the Union market. This page does not run that test.
- If counsel says Annex I Part II may apply, draft and enforce a coordinated vulnerability disclosure policy and a contact address. This page is not that policy. ISO/IEC 29147 and 30111 are best-practice structure, not the CRA.
- If counsel says Article 14 may apply to a reporter submission that is an actively exploited vulnerability, open the statute-clock Article 14 guide on this site for the 24-hour / 72-hour / 14-day ladder and the where-to-submit guide on this site for the channel. This page does not start that clock.
- Do not treat an ISO/IEC standard as Annex I. Do not treat a recital as an operative article. Do not treat this product as publishing YOUR CVD policy or filing Article 14.
- A dedicated vulnerability-management, security-updates, and readiness-checklist guide is not on this site yet. Naming them is not a link.
Where this shows up in ShipReady Metrics
The signed-in app does not decide that the CRA applies, does not decide that you are a manufacturer, does not publish YOUR coordinated vulnerability disclosure policy to users, does not write Annex II user information, does not host YOUR public reporter mailbox, does not start an Article 14 clock, does not file with a CSIRT or ENISA, and does not affix a CE mark. None of the surfaces below is 'CRA applies', 'this policy is enforced', 'this clock has started', or an instruction to submit a filing.
If you already have a session: signed-in app → Compliance → Policies Library can host a coordinated vulnerability disclosure policy the organisation authors. The CRA starter set lists Vulnerability & Patch Management as a must-have template; the library also accepts another policy type the organisation creates. Hosting a document is not publishing it to users, not Annex II point 2, not the single point of contact, not enforcement of Annex I Part II point (5), and not CE marking. The template is a starter outline, not a CRA-conformant CVD policy, and not legal advice. signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour / 72-hour / 14-day ladder from recorded awareness for findings the organisation classified as CRA-in-scope. That tracker does not start an Article 14 clock, does not decide that a reporter submission is an actively exploited vulnerability, and does not file. A named human still publishes the policy and still submits Article 14 notifications. The obligation map lists frameworks marked in-scope, including cra if that mark is set. That mark is not a determination that the CRA applies.
Signed-in Security → Findings is vulnerability-management intake from scanners the organisation connected (Dependabot, code scanning, DAST, secret scanning). Signed-in admin Compliance Ops can record Vulnerability Disclosure Program reports the organisation already received (reporter contact stored as a hash) when that module is on. Neither surface is a public reporter mailbox for YOUR product, neither publishes the CVD policy, neither starts an Article 14 clock, and neither files with a CSIRT or ENISA. This page does not document a public demo URL. There is no public CRA demo path.
Primary sources (last verified 9 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2024/2847 of 23 October 2024 (Cyber Resilience Act), Annex I Part II points (4), (5) and (6), Article 13(6) and 13(8), Annex II point 2, Annex VII, Recitals 63 and 76, and Articles 14, 15, 16 and 71(2), is a legal requirement only if it applies. Recitals are not operative articles. Article 14 applies from 11 September 2026; Annex I essential requirements and Article 13 apply from 11 December 2027 (Article 71(2)). Directive (EU) 2022/2555 Article 12(1) is NIS2 — a different instrument; the NIS2 incident-reporting guide is on this site. The European Commission's CRA policy page (updated 7 September 2026) and CRA summary page are Commission materials, not the regulation. ENISA's vulnerability-disclosure topic page and Coordinated Vulnerability Disclosure Policies in the EU (April 2022) are agency materials, not the regulation. ISO/IEC 29147:2018 and ISO/IEC 30111:2019 are international standards — best practice, not the CRA. These are not a complete world list. Not legal advice.
The statute-clock Article 14 guide on this site is the live ladder under breach reporting. The CRA-cluster Article 14 overview on this site is how Article 14 sits in the cluster. The CRA overview on this site is the pillar page. The who-is-covered guide on this site is the economic-operator roles page. The SaaS-scope guide on this site is the remote-processing versus service page. The where-to-submit guide on this site is the Article 14 channel page. The ENISA-workflow guide on this site is the single-reporting-platform walkthrough. The CSIRT guide on this site is the coordinator-interaction page. A dedicated vulnerability-management, security-updates, and readiness-checklist guide is not on this site yet. Naming them is not a link.
Frequently asked questions
Is this legal advice?
No. It is a coordinated-vulnerability-disclosure page distilled from Regulation (EU) 2024/2847 Annex I Part II points (5) and (6), Article 13(8), Annex II point 2 and Annex VII, with Recitals 63 and 76 labelled as recitals, ENISA materials labelled as agency guidance, and ISO/IEC 29147:2018 and ISO/IEC 30111:2019 labelled as international standards — best practice, not the CRA. Whether the CRA applies, whether YOUR policy meets Annex I Part II, and whether a reporter submission starts an Article 14 clock are legal questions for counsel on your facts. This page does not start a clock.
Does ShipReady publish our CVD policy for us?
No. The signed-in Policies Library can host a coordinated vulnerability disclosure policy the organisation authors. Hosting a document is not publishing it to users, not the Annex II single point of contact, not enforcement of Annex I Part II point (5), and not CE marking. The CRA starter set lists a Vulnerability & Patch Management template as a must-have; that outline is not a CRA-conformant CVD policy. This product does not file Article 14 reports and does not start a clock. A named human still publishes the policy and still submits.
Is ISO/IEC 29147 the CRA?
No. ISO/IEC 29147:2018 is an international standard on vulnerability disclosure. ISO/IEC 30111:2019 is an international standard on vulnerability handling processes. Both are best practice. They are not Regulation (EU) 2024/2847. The CRA does not make those standards the legal requirement. Annex I Part II point (5) is the CRA text on a coordinated vulnerability disclosure policy. Last verified 9 September 2026. Not legal advice.
Does a reporter submission start an Article 14 clock?
No. A reporter submission to the manufacturer's CVD channel is intake under Annex I Part II and Article 13(8). Article 14 starts from the manufacturer becoming aware of an actively exploited vulnerability or a severe incident, as those articles define those terms. Receiving a report is not, by itself, that finding. This page does not start a clock. The statute-clock Article 14 guide on this site is the ladder. A named human still files.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.