Glossary · NIS2
Vulnerability Disclosure (CVD)
Coordinated Vulnerability Disclosure — a structured process for receiving, handling, and remediating vulnerability reports from third parties.
Explained in depth: The 10 NIS2 security requirements
Coordinated vulnerability disclosure (CVD) lets security researchers and other outsiders report vulnerabilities to an organisation safely and in a structured way, so the flaw can be fixed before details become public. NIS2 promotes CVD at two levels: entities are expected to handle and disclose vulnerabilities as part of Article 21(2)(e), and member states must designate a CSIRT as coordinator for CVD, with ENISA maintaining a European vulnerability database. A minimal CVD setup includes a published security contact (commonly a `security.txt` file), a disclosure policy stating what researchers may test and what the organisation commits to, internal routing so reports reach the right team, and defined remediation timelines.
Why it matters
Without a CVD channel, vulnerability reports land in the wrong inbox or go public untriaged. A published policy costs little, signals maturity to auditors and customers, and is the practical prerequisite for the vulnerability handling that Article 21 expects.
