CVD Policy

ENISA is supporting the EU Member States since 2012 to develop, implement and evaluate their National Cyber Security Strategies (NCSS). Since 2017, all EU Member States have published their own NCSS.

CVD Policy

The state of implementation of national CVD policies across the Member States shows that substantial differences exist among them. The research shows that while evolving in a fragmented EU environment, multiple Member States are making progress in the development of national CVD policies but at different rates.

Most of the Member States without a CVD policy in place expressed the intention of establishing one in the future, especially in the context of the national transposition of the NIS2 directive. Very few Member States seem to be opposed to implementing a CVD policy. In some cases, this is because current practices or legal frameworks in place in the countries already allow CVD processes to take place even without a formal policy.

Austria flag
Austria
Belgium flag
Belgium
Bulgaria flag
Bulgaria
Croatia flag
Croatia
Cyprus flag
Cyprus
Czech Republic flag
Czech Republic
Denmark flag
Denmark
Estonia flag
Estonia
Finland flag
Finland
France flag
France
Germany flag
Germany
Greece flag
Greece
Hungary flag
Hungary
Iceland flag
Iceland
Ireland flag
Ireland
Italy flag
Italy
Latvia flag
Latvia
Liechtenstein flag
Liechtenstein
Lithuania flag
Lithuania
Luxembourg flag
Luxembourg
Malta flag
Malta
Netherlands flag
Netherlands
Norway flag
Norway
Poland flag
Poland
Portugal flag
Portugal
Romania flag
Romania
Slovakia flag
Slovakia
Slovenia flag
Slovenia
Spain flag
Spain
Sweden flag
Sweden
Switzerland flag
Switzerland
Belgium flag
Belgium

National Coordinated Vulnerability Disclosure policy: Belgium established one of Europe’s first national Coordinated Vulnerability Disclosure (CVD) frameworks in 2012, evolving it into a mature ecosystem under the Centre for CCB. The CCB serves as the trusted national intermediary, managing a formal disclosure policy that includes a 'safe harbor' provision to offer legal protection to ethical hackers who adhere to strict reporting guidelines. This framework is further operationalized through government-backed bug-bounty programs that incentivize responsible reporting of vulnerabilities in public sector assets.

Sources: https://ccb.belgium.be/regulation/cvdp

Attachments:
Related objective Establish a CVD Policy
Croatia flag
Croatia

Coordinated vulnerability disclosure (NCSC-HR): Croatia's CVD framework under the Cybersecurity Act (NN 14/24), which establishes a framework for coordinated vulnerability detection: any natural or legal person can report a vulnerability (anonymously if requested) to the CSIRT vulnerability-disclosure coordinator, a role performed by NCSC-HR. As the designated coordinator (per NIS2 Art. 12), NCSC-HR acts as trusted intermediary between the reporter and the affected ICT product/service manufacturer or provider, ensures diligent follow-up and preserves the reporter's anonymity. Vulnerabilities are reported by email to a dedicated address. 

Sources: https://ncsc.hr/hr/prijava-ranjivosti 
https://ncsc.hr/en/nis2-transposition 
https://ncsc.hr/UserDocsImages/ostalo/Cybersecurity_Act.pdf?vel=1434556 

Related objective Establish a CVD Policy
Cyprus flag
Cyprus

The CVD policy is planned as secondary legislation. Primary legislation harmonizing Directive (EU) 2022/2555 must be voted on in the House of Representatives. Expected availability: Q3 2025. Efforts are led by the Digital Security Authority and National CSIRT-CY. Recent DDoS attacks highlight the urgency of the policy.

Related objective Establish a CVD Policy
Czech Republic flag
Czech Republic

The National Cyber and Information Security Agency (NÚKIB) is finalizing its national CVD policy for publication in Q1–Q2 2025. Governmental CERT under NÚKIB will serve as the CVD coordinator. The policy aligns with NIS2 Directive requirements and involves a new CVD platform and resources. Legal aspects such as criminal law and GDPR are under consultation to support responsible disclosure.

https://www.nukib.gov.cz/en https://osveta.nukib.gov.cz/course/view.php?id=168 https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555

Attachments:
Related objective Establish a CVD Policy
Estonia flag
Estonia

RIA Vulnerability Disclosure Policy (VDP) + Bug Bounty pilot via HackerOne: RIA is testing a national Vulnerability Disclosure Policy and a bug-bounty programme through HackerOne. The disclosure policy covers selected critical infrastructure, including the .EE domain and government networks, while the bug bounty focuses on RIA services. Both pilots use invited researchers and a controlled reporting process through HackerOne. The experience gained is intended to support the development of a broader public disclosure policy.

Sources: https://www.enisa.europa.eu/topics/national-cyber-security-strategies/ncss-map/national-cyber-security-strategies-interactive-map/national-implementation/cvd-policy
https://www.ria.ee/en/cyber-security/handling-cyber-incidents-cert-ee/reporting-cyber-incident

Related objective Establish a CVD Policy
Finland flag
Finland

Coordinated vulnerability disclosure coordinator (NCSC-FI): The NCSC-FI acts as Finland's national coordinator for coordinated vulnerability disclosure within the EU framework, mediating between researchers and vendors and helping to publish fixes responsibly. The same team can act as a coordinator for voluntary cybersecurity information-sharing arrangements.

Sources: https://kyberturvallisuuskeskus.fi/en/our-services/tilannekuva-ja-verkostojohtaminen/vulnerability-coordination/coordinated-vulnerability-disclosure-cvd-process

Related objective Establish a CVD Policy
France flag
France

For information regarding the vulnerability policy (CVD Policy), please visit the ANSSI website.

Sources: https://cyber.gouv.fr/reglementation/cybersecurite-systemes-dinformation/declaration-de-vulnerabilit%C3%A9s/

Related objective Establish a CVD Policy
Germany flag
Germany

BSI CVD guideline: The guideline was developed by Germany’s Federal Office for Information Security (BSI) under the statutory foundation of Section 4b of the BSI Act. It serves as Germany’s national framework for Coordinated Vulnerability Disclosure, with the BSI acting as a neutral intermediary between security researchers and manufacturers. The BSI facilitates communication, coordinates disclosure timelines, and publishes a coordinated advisory once a fix is available (with acknowledgement of the reporter). Researchers can report vulnerabilities in federal products or web applications directly to CERT-Bund.

Sources: https://www.bsi.bund.de/EN/IT-Sicherheitsvorfall/IT-Schwachstellen/it-schwachstellen.html

https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/CVD/CVD-Leitlinie.pdf?__blob=publicationFile&v=4

Anonymous vulnerability reporting: The BSI-Portal offers a channel to report vulnerabilities to the BSI anonymously, lowering the barrier for finders who wish to stay unidentified while still enabling coordinated remediation.

Sources: https://portal.bsi.bund.de/ 

Related objective Establish a CVD Policy
Greece flag
Greece

Article 12 of Law 5160/2024 transposes Article 12 of the NIS2 Directive and designates the CSIRT of the National Cybersecurity Authority (NCSA) as the national coordinator for the CVD policy. NCSA is currently drafting secondary legislation to fully implement the CVD policy framework.

Attachments:
Related objective Establish a CVD Policy
Hungary flag
Hungary

Coordinated vulnerability disclosure - national CSIRT coordinator National Cyber Security Centre of Hungary (NCSC HU) and anonymous reporting channel: Hungary's CVD framework under the Cybersecurity Act (Act LXIX of 2024 The National Cyber Security Centre of Hungary (NCSC HU) - within the Special Service for National Security (SSNS) -  is the national CSIRT and acts as the coordinated vulnerability disclosure coordinator, serving as trusted intermediary between the reporter and the affected vendor/manufacturer. Anyone can report a detected vulnerability to NCSC HU, including anonymously, via a dedicated email address, and NCSC HU operates a statutory, cost-free vulnerability-assessment (ethical-hacking) service for in-scope electronic information systems, producing a written report with remediation recommendations.

Sources: https://en.nki.gov.hu/
https://nki.gov.hu/szolgaltatasok/tartalom/serulekenysegvizsgalat/
https://njt.jog.gov.hu/jogszabaly/en/2024-69-00-00
https://net.jogtar.hu/jogszabaly?docid=a2400069.tv

Related objective Establish a CVD Policy
Latvia flag
Latvia

Latvia's CVD policy is implemented under the National Cyber Security Law. CERT.LV is the national CVD coordinator as designated in Article 5. Vulnerability reporting platform launched in March 2023. Detailed responsibilities and rights are provided in Articles 39 and 40. Terms, data policy, and FAQs are published on the platform.

Main: https://cvd.cert.lv/ Terms: https://cvd.cert.lv/statictexts/view/terms-and-conditions Data Policy: https://cvd.cert.lv/statictexts/view/data-processing Law: https://likumi.lv/ta/id/353390-nacionalas-kiberdrosibas-likums (LV) FAQs: https://cvd.cert.lv/faq/answers/10, https://cvd.cert.lv/faq/answers/100

Terms & Conditions: https://cvd.cert.lv/statictexts/view/terms-and-conditions Law (LV): https://likumi.lv/ta/id/353390-nacionalas-kiberdrosibas-likums

Contact: cvd@cert.lv
Related objective Establish a CVD Policy
Lithuania flag
Lithuania

Lithuania's CVD policy is established in Article 25 of the Law on Cybersecurity and detailed in the Procedure for Vulnerability Disclosure. Entities may create their own policies, provided they are not more restrictive than the national policy. These are aligned with the Cybersecurity Requirements.

Law on Cybersecurity: https://e-seimas.lrs.lt/portal/legalAct/lt/TAD/f6958c2085dd11e495dc9901227533ee/asr Disclosure Procedure: https://e-seimas.lrs.lt/portal/legalAct/lt/TAD/270e6bd1e08911eb866fe2e083228059 Cybersecurity Requirements: https://e-seimas.lrs.lt/portal/legalAct/lt/TAD/94365031a53411e8aa33fe8f0fea665f/asr Vulnerability Reporting Form: https://www.nksc.lt/pranesti-spraga.html

Publicly available via the official legislative and institutional links.

Related objective Establish a CVD Policy
Malta flag
Malta

National Coordinated Vulnerability Disclosure Policy (NCVDP): Malta’s National Coordinated Vulnerability Disclosure Policy (NCVDP) provides a national framework for the responsible reporting, mitigation, and disclosure of vulnerabilities in ICT systems. Developed by the CIPD and MDIA under the National Cybersecurity Strategy 2023-2026 and Directive (EU) 2022/2555 (NIS 2), it encourages 'Responsible Organisations' to adopt and register their own CVDPs, sets clear procedures for Security Researchers conducting vulnerability research, and promotes cooperation with CSIRTMalta. 

Sources: https://mdia.gov.mt/services/ncvdp/ 
https://www.enisa.europa.eu/sites/default/files/ncss-map/strategies/national-implementation/P-SPG-001-National-Coordinated-Vulnerability-Disclosure-Policy.pdf 

Related objective Establish a CVD Policy
Netherlands flag
Netherlands

The Netherlands has a national Coordinated Vulnerability Disclosure (CVD) framework coordinated by the National Cyber Security Centre (NCSC). The NCSC published the 'Leidraad Coordinated Vulnerability Disclosure' (2018, updated 2019), setting out how researchers report vulnerabilities and how organisations adopt their own CVD policy. The NCSC acts as intermediary and, for multi-vendor vulnerabilities it coordinates, as a CVE Numbering Authority. Under the Cyberbeveiligingswet (NIS2 transposition, in force 15 August 2026) the NCSC is the designated national CSIRT.

National CVD guideline (Leidraad Coordinated Vulnerability Disclosure) + NCSC CVD form: The NCSC-NL 'Leidraad Coordinated Vulnerability Disclosure'  sets out how organisations should set up a CVD policy in five steps and how researchers and organisations should behave. Researchers who find a technical vulnerability in a Dutch central-government system report it through the NCSC CVD form. The NCSC encrypts reports with its PGP key, keeps the reporter's identity confidential (a pseudonym is allowed), responds within three days, credits the reporter on request, and acts as intermediary where a system owner is unresponsive. 

Source: https://www.ncsc.nl/wat-kun-je-zelf-doen/weerbaarheid/besturen/cvd-beleid 
https://www.ncsc.nl/en/services/report-a-vulnerability 

Guidance: https://www.ncsc.nl/wat-kun-je-zelf-doen/weerbaarheid/besturen/cvd-beleid

Reporting form: https://www.ncsc.nl/contact/kwetsbaarheid-melden/cvd-meldingen-formulier

Advisories URLs: https://advisories.ncsc.nl/

Related objective Establish a CVD Policy
Poland flag
Poland

CERT Polska coordinated vulnerability disclosure: CERT Polska operates a national coordinated vulnerability disclosure process for vulnerabilities affecting Polish organisations and products. It receives reports from researchers, validates and triages the technical findings, contacts the affected vendor or system owner, coordinates remediation and disclosure timelines, and may publish an advisory once mitigation is available. Reports can be submitted confidentially through CERT Polska’s dedicated CVD channel.

Sources: https://cert.pl/en/cvd/

CERT Polska CVE (CNA) and n6 platform: As an authorised CVE Numbering Authority, CERT Polska can assign CVE identifiers to eligible vulnerabilities within its scope and publish the corresponding records. Separately, its n6 Network Security Incident eXchange service provides registered organisations with free, infrastructure-specific information on malware infections, phishing, command-and-control servers, exposed applications and vulnerable services, supporting early detection and remediation.

Sources: https://cert.pl/en/cvd/
https://cert.pl/en/n6/

Related objective Establish a CVD Policy
Portugal flag
Portugal

Coordinated Vulnerability Disclosure policy ("Divulgação coordenada de vulnerabilidades"): Portugal has established a framework for coordinated vulnerability disclosure under the national cybersecurity regime. CNCS issued Technical Instruction No. 01/2026 on Coordinated Vulnerability Disclosure ("Divulgação coordenada de vulnerabilidades"). Decree-Law N.º 125/2025 (Cybersecurity Legal Framework) also introduces amendments to the Law N.º 109/2009 (Cybercrime Law) that protect ethical hacking in the context of responsible vulnerability disclosure. 

Sources: https://www.cncs.gov.pt/pt/instrucoes-tecnicas/ 
https://www.cncs.gov.pt/docs/1782487642.pdf 

Related objective Establish a CVD Policy
Romania flag
Romania

In the current stage of implementing the NIS2 Directive, DNSC has been designated as the CVD coordinator under Article 36 of Emergency Ordinance 155/2024, adopted on 30 December 2024. DNSC acts as the national CSIRT and a trusted intermediary, managing reporting, communication, timelines, legal compliance, and procedures for vulnerability disclosure. CVD procedures include anonymity, reporting responsibilities, researcher conduct, and timelines. Entities must establish vulnerability management processes and collaborate with DNSC. Strategic assessment published.

Policy page: https://dnsc.ro/pagini/CVD (RO) Strategic Assessment: https://dnsc.ro/doc/ghid (RO)

Strategic Assessment Document (RO): https://dnsc.ro/doc/ghid Emergency Ordinance 155/2024 (not linked as PDF but described)

Related objective Establish a CVD Policy
Slovakia flag
Slovakia

National Responsible Vulnerability Disclosure Policy (Politika pre zodpovedné oznamovanie zraniteľností): The National Security Authority established a national policy for coordinated vulnerability disclosure. The policy defines the national framework for receiving, coordinating and managing vulnerability reports, supporting responsible disclosure practices and reducing risks associated with vulnerabilities in products, services and information systems. The NBÚ also acts as the national authority coordinating disclosure activities and supporting affected entities.

Sources: https://www.nbu.gov.sk/politika-pre-zodpovedne-oznamovanie-zranitelnosti/
https://www.nbu.gov.sk/data/files/613_cvd.pdf

National Vulnerability Reporting Platform (CVD Portal): Slovakia operates a dedicated national platform for coordinated vulnerability disclosure.

Sources: https://cvd.nbu.gov.sk/#/

Related objective Establish a CVD Policy
Slovenia flag
Slovenia

National Coordinated Vulnerability Disclosure Framework (Usklajeno razkrivanje ranljivosti): Article 17 of the Information Security Act (ZInfV-1) established a national coordinator for coordinated vulnerability disclosure in Slovenia. The coordinator acts as a trusted intermediary between the person reporting a vulnerability and the affected ICT product manufacturer, service provider or system operator. Vulnerabilities may be reported anonymously and the coordinator facilitates responsible handling and disclosure of the vulnerability. 

Sources: https://pisrs.si/pregledPredpisa?id=ZAKO8934 (Article 17) 

https://www.gov.si/novice/2025-07-01-usklajeno-razkrivanje-ranljivosti-in-evropska-podatkovna-zbirka-ranljivosti/ 

SI-CERT Vulnerability Reporting and Coordination Service: Researchers, organisations and individuals who discover a technical vulnerability can report it directly to SI-CERT. SI-CERT coordinates communication with the affected operator or vendor, protects the identity of the reporter where requested, and follows a coordinated disclosure model under which parties agree on a reasonable remediation period before public disclosure. The reporting process includes submission of technical information about the vulnerability and affected systems. 

Sources: https://www.cert.si/koordinirano-razkrivanje-ranljivosti/ 

National Vulnerability Coordination Role under ZInfV-1: The Information Security Act assigns SI-CERT responsibility for coordinated vulnerability disclosure and requires it to act as a trusted intermediary. Where a reported vulnerability may affect entities in other EU Member States, the coordinator may cooperate with other CSIRTs through European networks. The framework also links Slovenia with the European Vulnerability Database established by ENISA. 

Sources: https://pisrs.si/pregledPredpisa?id=ZAKO8934 (Article 17, Article 59) 

https://www.gov.si/novice/2025-07-01-usklajeno-razkrivanje-ranljivosti-in-evropska-podatkovna-zbirka-ranljivosti/ 

Related objective Establish a CVD Policy
Spain flag
Spain

Spain is currently transposing the NIS2 Directive into national law. Although no CSIRT has yet been designated as the national coordinator for Coordinated Vulnerability Disclosure (CVD), the legislation provides for the creation of a National Cybersecurity Center, which will designate a CSIRT to fulfill this role. While the legal framework for vulnerability research and reporting is not yet formalized, both INCIBE-CERT and CCN-CERT actively facilitate vulnerability coordination and disclosure processes.

CVD Policy: https://www.incibe.es/incibe-cert/alerta-temprana/vulnerabilidades/asignacion-publicacion-cve https://www.incibe.es/en/incibe-cert/early-warning/vulnerabilities/cve-assignment-publication Advisories: https://www.incibe.es/incibe-cert/alerta-temprana/vulnerabilidades/avisos-cna https://www.incibe.es/en/incibe-cert/early-warning/vulnerabilities/advisories-cna https://www.ccn-cert.cni.es/es/seguridad-al-dia/vulnerabilidades?format=html

Related objective Establish a CVD Policy
Sweden flag
Sweden

CERT-SE is the coordinating CSIRT for Sweden. A national CVD policy is under development. CERT-SE has plans to launch a website with guidance for vulnerability discoverers and companies, though the timeline is still uncertain.

https://www.cert.se

Related objective Establish a CVD Policy