A coordinated vulnerability disclosure policy is not optional under the CRA — it is a manufacturer obligation under Article 13(6). The policy must be in place before the product enters the EU market. It must cover reception of vulnerability reports, triage and verification procedures, remediation timelines, and disclosure coordination with reporters. CRACheck generates a CVD Policy document structured against Art. 13(6) as one of 8 CRA compliance documents. €149 per product. 15–25 minutes. 100% browser-side.
€149 one-time · 8-document ZIP · 15–25 minutes · Browser-side
A security.txt file (RFC 9116) is a contact pointer. It is not a coordinated vulnerability disclosure policy. Article 13(6) of Regulation (EU) 2024/2847 requires a documented policy covering reception, triage, remediation, and disclosure — not just a contact address.
A bug bounty programme incentivises vulnerability discovery. A CVD policy governs how discovered vulnerabilities are handled, triaged, and disclosed. They are different instruments. The CRA requires the policy. The bug bounty is optional.
Article 13(6) states that manufacturers shall put in place a coordinated vulnerability disclosure policy. This obligation applies at the time of placing the product on the market — not retroactively.
8 PDF documents generated from your data. Each cites the specific article of Regulation (EU) 2024/2847 it complies with.
Determines product category under Annex III / IV.
Art. 31 + Annex VII file that references the CVD policy.
Annex I risk assessment. Part II covers vulnerability handling processes.
Annex II. Includes the contact point for vulnerability reports.
Art. 28 + Annex V.
The primary deliverable. Structured per Art. 13(6): scope, reception channels, triage process, response timelines, remediation commitments, coordinated disclosure procedure, and safe harbour statement for good-faith researchers.
Art. 14 ENISA notification template. Works in tandem with the CVD policy.
Timeline including Art. 14 activation date (11 Sept 2026).
See before you buy — Download sample dossier (PDF, fictional company) — Real structure, real articles, real format. Fictional data.
Generated from your data, in your browser. No data leaves your device.
CRACheck generates the CVD Policy per Art. 13(6), integrated with the Technical Documentation, Risk Assessment, ENISA Notification Template, and 4 additional CRA documents.
CRACheck does not operate your PSIRT. It does not receive, triage, or respond to vulnerability reports on your behalf. It does not submit Art. 14 notifications to ENISA. The CVD policy is a document — executing it requires your security team.
The policy is the framework. CRACheck builds the framework. Your team operates within it.
For failure to meet manufacturer obligations under Art. 13, including the CVD policy requirement in Art. 13(6).
For non-compliance with vulnerability reporting obligations under Art. 14.
For providing incomplete or misleading information about vulnerability handling.
| Criterion | security.txt only | ISO 29147 template | Security consultancy | CRACheck |
|---|---|---|---|---|
| CRA Art. 13(6) compliance | No | Partial (ISO ≠ CRA) | Yes, but slow | Yes, structured |
| Integration with CRA docs | None | None | Separate engagement | Built-in (8 docs) |
| Cost | Free | Free (template only) | €3K–€10K | €149 |
| Time | 10 min (contact only) | 1–2 weeks | 3–8 weeks | 15–25 min |
| CRACheck | Yes | Built-in | €149 | 15-25 min |
If you maintain multiple products with different scopes, each needs its own CVD policy. Pack pricing: €99/product (10), €79/product (30).
Request volume pricingCRACheck generates a structured CVD Policy document according to Article 13(6) of Regulation (EU) 2024/2847 based on the information you enter. The accuracy of the contact details, response timelines, and scope declarations is your responsibility as the manufacturer.
We guarantee that the document structure follows Art. 13(6) requirements and that the legal references cited are correct. We do not guarantee that the policy will satisfy a market surveillance authority in a specific inspection.
CRACheck is not legal advice. For complex vulnerability disclosure scenarios, consult a qualified legal or security advisory firm.
CRACheck generates the CVD policy per Art. 13(6) plus 7 additional documents. €149 per product. Browser-side.