← Back to CVD Portal
International StandardVulnerability Disclosure

ISO/IEC 29147

Information technology — Security techniques — Vulnerability disclosure. The international standard that defines how a vendor receives reports of potential vulnerabilities and discloses resolution information to affected users.

What ISO/IEC 29147 covers

ISO/IEC 29147 gives manufacturers guidelines for the external side of vulnerability disclosure. It describes how to establish a disclosure policy, provide a way for finders to report potential vulnerabilities, acknowledge and communicate through the process, and publish advisories so that affected users can protect themselves.

It is written as guidance, not a certifiable management-system standard. Applying it means running a disclosure process that matches the practices the standard documents, from a discoverable point of contact through to a published advisory.

ISO/IEC 29147 pairs with ISO/IEC 30111. 29147 governs the outward-facing interface with finders and users. 30111 governs the internal investigation and remediation of a reported vulnerability. Together they describe a complete handling and disclosure lifecycle.

How CVD Portal supports the disclosure process

Each phase of the ISO/IEC 29147 disclosure process maps to infrastructure in the portal, so a manufacturer can run the full external process from a single platform.

Process phaseWhat the standard describesPortal feature
Disclosure policyPublish a vulnerability disclosure policy that tells finders what is in scope, how to report, and what to expect in return.CVD policy page + security.txt generator
Receiving reportsAdvertise a discoverable contact and provide a reliable channel to receive potential vulnerability reports from finders.Branded public submission portal
AcknowledgementConfirm receipt to the reporter within a stated timeframe so the finder knows the report is being handled.Automatic acknowledgement + SLA timers
Verification and triageInvestigate the report to confirm the vulnerability, assess severity, and prioritise a response.Submission triage + CVSS calculator
Coordination and communicationMaintain a clear, ongoing dialogue with the reporter and any coordinator through resolution.Per-submission communication log
Advisory releaseDisclose resolution information to affected users through a security advisory once a remediation is available.CSAF 2.0 advisory export

This page describes how CVD Portal aligns with the disclosure practices in ISO/IEC 29147. It is informational and does not constitute certification against the standard.

Where this fits under the CRA

The EU Cyber Resilience Act requires manufacturers to run a coordinated vulnerability disclosure process and to handle reported vulnerabilities without delay. A disclosure process built to ISO/IEC 29147, paired with the internal handling of ISO/IEC 30111, gives manufacturers a recognised structure for meeting those Annex I vulnerability handling requirements.

See the EN 40000-1-3 coverage page for the CRA harmonized standard and its clause-to-feature mapping.

Run an ISO/IEC 29147 disclosure process out of the box

Publish a policy, receive reports, acknowledge finders, and export CSAF advisories from one platform.

Get Started for Free