ISO/IEC 29147
Information technology — Security techniques — Vulnerability disclosure. The international standard that defines how a vendor receives reports of potential vulnerabilities and discloses resolution information to affected users.
What ISO/IEC 29147 covers
ISO/IEC 29147 gives manufacturers guidelines for the external side of vulnerability disclosure. It describes how to establish a disclosure policy, provide a way for finders to report potential vulnerabilities, acknowledge and communicate through the process, and publish advisories so that affected users can protect themselves.
It is written as guidance, not a certifiable management-system standard. Applying it means running a disclosure process that matches the practices the standard documents, from a discoverable point of contact through to a published advisory.
ISO/IEC 29147 pairs with ISO/IEC 30111. 29147 governs the outward-facing interface with finders and users. 30111 governs the internal investigation and remediation of a reported vulnerability. Together they describe a complete handling and disclosure lifecycle.
How CVD Portal supports the disclosure process
Each phase of the ISO/IEC 29147 disclosure process maps to infrastructure in the portal, so a manufacturer can run the full external process from a single platform.
| Process phase | What the standard describes | Portal feature |
|---|---|---|
| Disclosure policy | Publish a vulnerability disclosure policy that tells finders what is in scope, how to report, and what to expect in return. | CVD policy page + security.txt generator |
| Receiving reports | Advertise a discoverable contact and provide a reliable channel to receive potential vulnerability reports from finders. | Branded public submission portal |
| Acknowledgement | Confirm receipt to the reporter within a stated timeframe so the finder knows the report is being handled. | Automatic acknowledgement + SLA timers |
| Verification and triage | Investigate the report to confirm the vulnerability, assess severity, and prioritise a response. | Submission triage + CVSS calculator |
| Coordination and communication | Maintain a clear, ongoing dialogue with the reporter and any coordinator through resolution. | Per-submission communication log |
| Advisory release | Disclose resolution information to affected users through a security advisory once a remediation is available. | CSAF 2.0 advisory export |
This page describes how CVD Portal aligns with the disclosure practices in ISO/IEC 29147. It is informational and does not constitute certification against the standard.
Where this fits under the CRA
The EU Cyber Resilience Act requires manufacturers to run a coordinated vulnerability disclosure process and to handle reported vulnerabilities without delay. A disclosure process built to ISO/IEC 29147, paired with the internal handling of ISO/IEC 30111, gives manufacturers a recognised structure for meeting those Annex I vulnerability handling requirements.
See the EN 40000-1-3 coverage page for the CRA harmonized standard and its clause-to-feature mapping.
Run an ISO/IEC 29147 disclosure process out of the box
Publish a policy, receive reports, acknowledge finders, and export CSAF advisories from one platform.
Get Started for Free