What CRA Requires
CRA Annex I Part II, §5 mandates a coordinated vulnerability disclosure policy.
Step 1: Security Contact
Create security@yourcompany.com monitored by your security team.
Step 2: security.txt
Use our free generator for RFC 9116 compliant /.well-known/security.txt.
Step 3: Write VDP
- Scope — products/domains covered
- How to report — email, web form, or platform
- Acknowledgement timeline — 48-72 hours
- Resolution timeline — ≤90 days
- Safe harbour — legal protection for researchers
Step 4: Internal Process
Define triage, tracking, and patch release procedures. Document for CRA evidence.
Get the CRA deadline calendar
A one-page PDF showing every CRA date that matters for your product team. Free — no spam, unsubscribe anytime.
Related articles
Ready to Take Action?
Start your CRA compliance journey with our free assessment tool.