Vulnerability disclosure policy generator
Write the coordinated vulnerability disclosure (CVD) policy that EU software vendors are expected to publish, in plain language, ready to paste into your site. See the Cyber Resilience Act guide for where it fits.
Runs entirely in your browser
This is a template, not legal advice. Have a lawyer read it, especially the safe-harbour wording, before you publish it.
A template, not legal advice. Have a lawyer read it, especially the safe-harbour wording, before you publish it. The policy is written in the language of this page; nothing you type leaves your browser.
How to write your disclosure policy
- Enter your organisation, the products and services in scope and where reports should go. If you already have a security.txt, paste it to fill in the contact details.
- Set how fast you will acknowledge, assess and fix reports, the disclosure timeline, and whether to include safe-harbour wording.
- Read the preview, then copy the Markdown or the HTML, or download the HTML page, and publish it on your site.
- Link the policy from your security.txt with the Policy field, and keep your promises: the clock starts when a report arrives.
What a disclosure policy does
A coordinated vulnerability disclosure policy tells outsiders what to do when they find a weakness in your software, and tells them what you will do in return. Without one, a researcher has to guess whom to write to, whether they might be sued, and how long you need. Guessing wrong ends with a public post and no fix, or with no report at all. A short, readable policy removes the guesswork.
For vendors in the EU it is also part of the Cyber Resilience Act setup: manufacturers are expected to have such a policy and a published contact. The reporting guide for small vendors lists the rest, including the reporting clock for actively exploited vulnerabilities.
What the generated policy says
It names the products in scope and what is excluded, says where to send a report and what to put in it, and states how quickly you will acknowledge, assess and fix. It sets rules for testing, offers safe harbour to researchers who follow them, fixes a disclosure timeline, and explains that some vulnerabilities must be reported to the authorities. Every promise in it is yours: only commit to response times your team can meet.
Tips
- Publish the policy on a stable address and link it from your security.txt with the Policy field.
- Make sure someone reads the reporting inbox every working day, and agree who decides that an exploit is real before the 24-hour clock starts. The CRA incident clock shows the deadlines.
- Need the Markdown as a web page? The Markdown to HTML converter does that, though this page already writes HTML.
Questions
Does the Cyber Resilience Act require a disclosure policy?
The regulation expects manufacturers to put a policy on coordinated vulnerability disclosure in place and to provide a contact address for reports (Annex I, Part II). It does not prescribe the wording. This generator gives you a plain starting point; the regulation and ENISA guidance prevail. See the guide for small vendors.
What is safe harbour?
A promise that you will not take legal action against researchers who follow your rules and act in good faith. It encourages reports, but what you can promise depends on your country and your contracts, so have a lawyer check the wording. You can switch it off.
Which disclosure timeline should I choose?
90 days from the report is a widely used default: long enough for most fixes, short enough to keep pressure on. Choose a shorter period for simple products or a longer one if your release cycle is slow, and remember that you can agree a later date with a reporter.
How fast should I answer?
Acknowledge within a few working days at most; many vendors promise one to three. Reporters who hear nothing tend to publish. The fix target should be a goal you can meet, since the policy publicly commits you to it.
Why does the policy mention reporting to authorities?
Under the Cyber Resilience Act you must report actively exploited vulnerabilities and severe incidents to the national CSIRT and ENISA, starting with a 24-hour early warning. The paragraph tells reporters that technical details may be shared. You can remove it. The CRA incident clock shows the deadlines.
Is my text sent anywhere?
No. The policy is built in your browser from what you type, and nothing is uploaded or stored.