Glossary · NIS2

Vulnerability Disclosure (CVD)

Coordinated Vulnerability Disclosure — a structured process for receiving, handling, and remediating vulnerability reports from third parties.

Explained in depth: The 10 NIS2 security requirements

Coordinated vulnerability disclosure (CVD) lets security researchers and other outsiders report vulnerabilities to an organisation safely and in a structured way, so the flaw can be fixed before details become public. NIS2 promotes CVD at two levels: entities are expected to handle and disclose vulnerabilities as part of Article 21(2)(e), and member states must designate a CSIRT as coordinator for CVD, with ENISA maintaining a European vulnerability database. A minimal CVD setup includes a published security contact (commonly a `security.txt` file), a disclosure policy stating what researchers may test and what the organisation commits to, internal routing so reports reach the right team, and defined remediation timelines.

Why it matters

Without a CVD channel, vulnerability reports land in the wrong inbox or go public untriaged. A published policy costs little, signals maturity to auditors and customers, and is the practical prerequisite for the vulnerability handling that Article 21 expects.

Used in

See also

← All glossary terms