Vulnerability disclosure channel for NIS2 and the CRA
A vulnerability disclosure channel for NIS2 and the CRA gives an outside researcher one safe place to report a flaw in your product. The Cyber Resilience Act makes that channel a legal duty for manufacturers from 11 December 2027. NIS2 does not, and neither do the audit frameworks buyers ask about.
You must report an actively exploited vulnerability to a national CSIRT
You must publish a disclosure policy and a contact address for each new product
Reports coming in, reports going out
Two different obligations get called the same thing. To tell them apart, ask which direction the report travels.
Someone outside your company finds a flaw in your product and tells you about it. This is called coordinated vulnerability disclosure. You need a published address to receive it, a written policy, and a safe way to reply.
You tell a national cyber security team or a regulator that something has gone wrong. NIS2 Article 23 and CRA Article 14 both work this way, and both set short deadlines. Having a channel for researchers does not meet either obligation.
Which rules ask for a disclosure channel
Only one of these creates a legal duty for European companies. The other four are standards and guidance that customers often ask about.
Annex I requires a manufacturer to run a policy on coordinated vulnerability disclosure. It must also publish an address where flaws can be reported. There is no minimum company size. Fines reach 15 million euro or 2.5 percent of worldwide turnover. The duty falls on manufacturers, so a company that only buys software is not covered. For each product it starts the day that product goes on sale or is substantially changed, from 11 December 2027.
NIS2 does not require your company to run a public channel for researchers. Article 12 gives that job to each member state and the national cyber security team it appoints. Use of the EU vulnerability database is voluntary. Companies in scope get a single line, in Article 21(2)(e): vulnerability handling and disclosure. If a supplier tells you NIS2 requires a reporting channel, check your national law first.
29147 covers the part a researcher sees: how you receive a report, how you reply to the person who sent it, and how you publish the outcome. 30111 covers the investigation and repair work inside your own team. Neither is law and neither offers certification. Most published disclosure policies follow them, so a security team reviewing yours will expect the same structure.
Directive 20-01 requires United States federal agencies to publish a vulnerability disclosure policy. NIST SP 800-216 describes the same work in more detail. Neither applies to a European company. They are worth reading because they set the format buyers now look for. That means naming which systems a researcher may test, promising not to take legal action against someone acting in good faith, and giving one address for reports.
SOC 2 does not mention vulnerability disclosure. Cyber Essentials does not mention it either. ISO/IEC 27002 has no control covering an external reporting channel. In practice the request arrives through customer security questionnaires. The MVSP checklist asks for a published policy that says what may be tested, promises not to sue a good faith researcher, and gives contact details.
Dates and thresholds here come from the EU texts. Your own regulator or sector may require more.
Point your security.txt at the channel
RFC 9116 defines a short text file at /.well-known/security.txt so a researcher can find the right contact without searching. The file only applies to the domain it is served from, so it must stay on yours. The address inside it can be your WeMoral page.
The Expires field is required and should be less than a year ahead. Someone has to renew the file before it lapses. We checked 155 domains. Of the files we found, 48 percent broke the rules and 21 percent had already expired.
Contact: https://wemoral.com/report/demo Policy: https://example.com/security-policy Preferred-Languages: en, de Expires: 2027-03-01T00:00:00.000Z
What the channel covers
WeMoral receives the report and gives you a secure thread to answer it on. It is not a bug bounty platform.
It runs on the same account and the same case panel as your other reports. There is no second system to buy.
Frequently asked questions
Does my company have to run a vulnerability disclosure channel?
Only if you are a manufacturer under the Cyber Resilience Act. That duty begins on 11 December 2027 and applies to each product as it goes on sale or is substantially changed. A company that only buys software is not covered. Check your national rules first.
Is this the same as NIS2 incident reporting?
No, and the difference is direction. Incident reporting is outbound: you tell a regulator that something has happened to you, within a short deadline. A disclosure channel is inbound: someone outside tells you about a flaw. Most teams need both, and they stay separate.
Can WeMoral host our security.txt file?
No. RFC 9116 says the file applies only to the domain it is served from, so it has to live on yours. We can be the address it points at. Put your WeMoral reporting page on the Contact line.
Can one channel take both staff reports and security reports?
Yes, and many teams do. Keep the two kinds of report separate though. An employee reporting wrongdoing has legal protection that an outside researcher does not get. Use different handlers and different retention rules, in the same panel.