Introduction
The European Union Agency for Cybersecurity (ENISA) is committed to maintaining the highest standards of cybersecurity across its digital infrastructure. ENISA recognises the vital role that security researchers and members of the cybersecurity community play in identifying vulnerabilities that might otherwise go undetected.
This Responsible Disclosure Policy establishes the framework under which any Internet user including security researchers may report, in a structured, coordinated, and responsible manner, potential vulnerabilities found in ENISA's systems. ENISA commits to working collaboratively with good-faith reporters, acknowledging their contributions, and resolving confirmed vulnerabilities in a timely and transparent way.
For the purpose of this Policy, “good faith security research” means research conducted solely to identify and responsibly report security vulnerabilities.
Scope
This policy applies for all ENISA owned Internet facing services and applications, either resolving under enisa.europa.eu domain name or not.
How to report
Submission channel
All vulnerability reports must be submitted by email to: responsible-disclosure@enisa.europa.eu
All communications including Proof of Concept (PoC) and/or vulnerabilities exploitation information is recommended to be sent encrypted using the ENISA's public PGP key.
Encryption
To protect the confidentiality of your report, all communications is recommended to be encrypted using the ENISA public PGP key which is available at:
https://www.enisa.europa.eu/responsible-disclosure-pgp-key.txt
Required information
Your report should include the following where appropriate:
| Field | Description |
|---|---|
| Reporter identity | Name, affiliation (optional), email, PGP public key |
| Vulnerability type | CWE or OWASP category if applicable |
| Affected asset | URL, service, or application name |
| Technical description | Clear, detailed description of the vulnerability |
| Steps to reproduce | Step-by-step reproduction procedure |
| Proof of concept | Screenshots, HTTP requests/responses, scripts, logs ) |
| Discovery date & IP | Date, time, and IP address(es) used during research |
| Potential impact | Assessment of exploitability and impact |
| Suggested remediation | Optional, appreciated but not required |
| Public acknowledgment | Whether you consent to be publicly acknowledged on ENISA’s website. |
Guidelines
Please follow the below guidelines to submit a report:
- Report the vulnerability to ENISA promptly, before any other public or private disclosure.
- Maintain full confidentiality for at minimum 90 days from first notification. Within this timeframe ENISA will have acknowledged the vulnerability to the reporter and planned the remediation where applicable.
- Notify swiftly ENISA if inadvertent access to personal data or any other possibly sensitive information has been achieved.
- Provide sufficient information to allow ENISA to reproduce and assess the issue.
- Reporting vulnerabilities discovered through automated scanning tools, including AI tools, should always be accompanied with PoC and validation information by the reporter. Raw output from automated scanners will not be accepted.
- Reporters must act in good faith, without disrupting ENISA’s systems or services while finding flaws.
ENISA response process and disclosure timeline
ENISA commits to the following structured disclosure timeline. Day 0 is defined as the date ENISA receives a responsible disclosure report.
| Deadline | Trigger | ENISA action |
|---|---|---|
| Working day +7 days | Receipt of report | Acknowledgement is sent to the reporter along with assessment information, such as validity, CVSS score, expected resolution date. |
Concerning the CVE ID assignment to newly discovered vulnerabilities on ENISA Internet facing apps and services:
As a Common Vulnerability and Exposure (CVE) Numbering Authority (CNA), ENISA is authorised to assign CVE Identifiers (CVE IDs) and to publish CVE Records for Vulnerabilities in IT products discovered by European Union (EU) Computer Security Incident Response Teams (CSIRTs) or reported to EU CSIRTs for coordinated disclosure, as long as they do not fall under a CNA with a more specific scope. For vulnerabilities affecting multiple systems or vendors, ENISA may assign a CVE number. The vulnerability must meet the requirements of the CVE Program and align with the ENISA’s CNA role.
About the CVE IDs assignment for vulnerabilities discovered on ENISA public apps and/or services, the reporter may request it him/herself directly to the last resort, aka MITRE https://mitre.github.io/mitre-cve-roles/cve-id-request/#cvePortal or if agreed, ENISA can do it on his/her behalf.
In case there is a double submission for the same vulnerability, we will give precedence to the first reporter.
Recognition program
ENISA maintains a Hall of Recognition at https://www.enisa.europa.eu/hall-of-fame for reporters whose submissions are confirmed as valid and in scope. Recognition is subject to the reporter's explicit written consent and will acknowledge:
- Reporter name or pseudonym (at their discretion);
- Nature of the finding (general category, no sensitive technical details);
- Date of responsible disclosure
Data protection and confidentiality
ENISA will treat all reporter information as strictly confidential. Reporter details will not be shared with third parties except if the reporter has given his/her consent to publish their name in the ENISA’s Hall of Recognition or where required by applicable EU law.
The processing of personal data submitted as part of a vulnerability report is governed by Regulation (EU) 2018/1725.