Implementation

How to Write a CRA-Compliant Vulnerability Disclosure Policy

Step-by-step guide to creating a VDP that satisfies CRA Annex I Part II, §5. Includes templates, security.txt setup, and safe harbour language.

March 2026 · 9 min read

What CRA Requires

CRA Annex I Part II, §5 mandates a coordinated vulnerability disclosure policy.

Step 1: Security Contact

Create security@yourcompany.com monitored by your security team.

Step 2: security.txt

Use our free generator for RFC 9116 compliant /.well-known/security.txt.

Step 3: Write VDP

  1. Scope — products/domains covered
  2. How to report — email, web form, or platform
  3. Acknowledgement timeline — 48-72 hours
  4. Resolution timeline — ≤90 days
  5. Safe harbour — legal protection for researchers

Step 4: Internal Process

Define triage, tracking, and patch release procedures. Document for CRA evidence.

Get the CRA deadline calendar

A one-page PDF showing every CRA date that matters for your product team. Free — no spam, unsubscribe anytime.

Related articles

Ready to Take Action?

Start your CRA compliance journey with our free assessment tool.