Security and product compliance

Vulnerability disclosure channel for NIS2 and the CRA

A vulnerability disclosure channel for NIS2 and the CRA gives an outside researcher one safe place to report a flaw in your product. The Cyber Resilience Act makes that channel a legal duty for manufacturers from 11 December 2027. NIS2 does not, and neither do the audit frameworks buyers ask about.

11 Sep 2026

You must report an actively exploited vulnerability to a national CSIRT

11 Dec 2027

You must publish a disclosure policy and a contact address for each new product

Reports coming in, reports going out

Two different obligations get called the same thing. To tell them apart, ask which direction the report travels.

A security engineer reviewing code on two screens in a quiet office
Inbound, a researcher reports to you

Someone outside your company finds a flaw in your product and tells you about it. This is called coordinated vulnerability disclosure. You need a published address to receive it, a written policy, and a safe way to reply.

Outbound, you report to the state

You tell a national cyber security team or a regulator that something has gone wrong. NIS2 Article 23 and CRA Article 14 both work this way, and both set short deadlines. Having a channel for researchers does not meet either obligation.

The rules

Which rules ask for a disclosure channel

Only one of these creates a legal duty for European companies. The other four are standards and guidance that customers often ask about.

Cyber Resilience Act, Regulation (EU) 2024/2847
Creates a legal duty

Annex I requires a manufacturer to run a policy on coordinated vulnerability disclosure. It must also publish an address where flaws can be reported. There is no minimum company size. Fines reach 15 million euro or 2.5 percent of worldwide turnover. The duty falls on manufacturers, so a company that only buys software is not covered. For each product it starts the day that product goes on sale or is substantially changed, from 11 December 2027.

NIS2, Directive (EU) 2022/2555
Widely misread

NIS2 does not require your company to run a public channel for researchers. Article 12 gives that job to each member state and the national cyber security team it appoints. Use of the EU vulnerability database is voluntary. Companies in scope get a single line, in Article 21(2)(e): vulnerability handling and disclosure. If a supplier tells you NIS2 requires a reporting channel, check your national law first.

ISO/IEC 29147 and ISO/IEC 30111
Process standards

29147 covers the part a researcher sees: how you receive a report, how you reply to the person who sent it, and how you publish the outcome. 30111 covers the investigation and repair work inside your own team. Neither is law and neither offers certification. Most published disclosure policies follow them, so a security team reviewing yours will expect the same structure.

CISA BOD 20-01 and NIST SP 800-216
A template, not a duty

Directive 20-01 requires United States federal agencies to publish a vulnerability disclosure policy. NIST SP 800-216 describes the same work in more detail. Neither applies to a European company. They are worth reading because they set the format buyers now look for. That means naming which systems a researcher may test, promising not to take legal action against someone acting in good faith, and giving one address for reports.

Sector rules and audit frameworks
No requirement found

SOC 2 does not mention vulnerability disclosure. Cyber Essentials does not mention it either. ISO/IEC 27002 has no control covering an external reporting channel. In practice the request arrives through customer security questionnaires. The MVSP checklist asks for a published policy that says what may be tested, promises not to sue a good faith researcher, and gives contact details.

Dates and thresholds here come from the EU texts. Your own regulator or sector may require more.

A cold aisle between server racks in a data centre, with status lights glowing on the equipment
Blue and grey network cables plugged into a patch panel, with switches behind it
A large wall display showing lines of source code in a darkened office
security.txt

Point your security.txt at the channel

RFC 9116 defines a short text file at /.well-known/security.txt so a researcher can find the right contact without searching. The file only applies to the domain it is served from, so it must stay on yours. The address inside it can be your WeMoral page.

The Expires field is required and should be less than a year ahead. Someone has to renew the file before it lapses. We checked 155 domains. Of the files we found, 48 percent broke the rules and 21 percent had already expired.

Contact: https://wemoral.com/report/demo
Policy: https://example.com/security-policy
Preferred-Languages: en, de
Expires: 2027-03-01T00:00:00.000Z
Scope

What the channel covers

WeMoral receives the report and gives you a secure thread to answer it on. It is not a bug bounty platform.

A branded page anyone can reach, with no account to create
Asset, version, severity and steps to reproduce are ordinary form fields you set yourself
Attachments are virus scanned, and hidden data is stripped from every file
An encrypted two-way thread, so you can ask for detail with no email address on either side
Every read and every change is logged, and the case data stays in Frankfurt

It runs on the same account and the same case panel as your other reports. There is no second system to buy.

Frequently asked questions

Only if you are a manufacturer under the Cyber Resilience Act. That duty begins on 11 December 2027 and applies to each product as it goes on sale or is substantially changed. A company that only buys software is not covered. Check your national rules first.

No, and the difference is direction. Incident reporting is outbound: you tell a regulator that something has happened to you, within a short deadline. A disclosure channel is inbound: someone outside tells you about a flaw. Most teams need both, and they stay separate.

No. RFC 9116 says the file applies only to the domain it is served from, so it has to live on yours. We can be the address it points at. Put your WeMoral reporting page on the Contact line.

Yes, and many teams do. Keep the two kinds of report separate though. An employee reporting wrongdoing has legal protection that an outside researcher does not get. Use different handlers and different retention rules, in the same panel.

Launch your whistleblower reporting channel in less than 5 minutes!

A ready-made reporting page compliant with the EU Whistleblower Protection Directive. Deploy it without a developer.