Jurisdiction
Region
Requirement
Policy
Cyberbeveiligingswet (Cybersecurity Act) — implements NIS2 Directive (EU) 2022/2555, replacing the Wet beveiliging netwerk- en informatiesystemen (Wbni)
Applies to
CSIRTs; by extension, essential/important entities across NIS2 Annex I/II sectors operating in the Netherlands, and any party wishing to report a vulnerability
Provision
Artikel 17, eerste lid, Cyberbeveiligingswet — designation of a CSIRT as national CVD coordinator (mirrors NIS2 Article 12)
Description

Dutch (original): "Bij of krachtens algemene maatregel van bestuur wordt een CSIRT aangewezen als de coördinator met het oog op een gecoördineerde bekendmaking van kwetsbaarheden." 

English (translation): "By or pursuant to a general administrative order, a CSIRT shall be designated as the coordinator with a view to the coordinated disclosure of vulnerabilities." 

The designated CSIRT coordinator's tasks (Art. 17(2), per secondary summary — not independently re-verified verbatim) include acting as intermediary between reporters and affected manufacturers/providers, identifying and contacting affected entities, and coordinating with counterpart coordinators in other EU Member States.

Date
August 15, 2026
Organization
Dutch Ministry of Justice and Security (Ministerie van Justitie en Veiligheid); National Cyber Security Centre (NCSC-NL)
Jurisdiction
Region
Requirement
Policy
Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung (NIS-2-Umsetzungsgesetz / NIS2UmsG)
Applies to
Approximately 29,000 entities across NIS2 Annex I (highly critical) and Annex II (other critical) sectors operating in Germany
Provision
§ 30 Absatz 2 Satz 2 Nummer 5 BSIG (as amended by NIS2UmsG) — risk-management measures including "vulnerability handling and disclosure" (transposes NIS2 Directive (EU) 2022/2555 Article 21(2)(e))
Description

Transposes NIS2 Article 21(2)(e): "security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure." The amended BSIG requires "besonders wichtige Einrichtungen" (essential) and "wichtige Einrichtungen" (important) entities to implement appropriate and proportionate technical, operational, and organisational measures, including vulnerability handling and disclosure. The BSI is empowered to coordinate vulnerability disclosure and issue public warnings about IT-product vulnerabilities.

Date
March 6, 2026
Organization
Bundestag; Federal Ministry of the Interior and Community (BMI); Federal Office for Information Security (BSI)
Jurisdiction
Region
Requirement
Policy
European Vulnerability Database (EUVD)
Applies to
EU CSIRTs; ICT product manufacturers; security researchers; the public
Provision
Legal basis: NIS2 Directive (EU) 2022/2555 Article 12(2) (ENISA mandate to develop and maintain an EU vulnerability database)
Description

ENISA-operated centralized repository of vulnerabilities affecting ICT products/services, mandated by NIS2 Article 12(2). Provides dashboards for critical vulnerabilities, actively exploited vulnerabilities, and EU-coordinated vulnerabilities. ENISA is a CVE Numbering Authority (CNA) since January 2024.

Date
May 13, 2025
Organization
European Union Agency for Cybersecurity (ENISA)
Jurisdiction
Region
Requirement
Policy
NCSC Coordinated Vulnerability Disclosure (CVD) Framework
Applies to
All digital infrastructures and ICT services within Switzerland’s jurisdiction, including systems operated by the Federal Administration and private sector entities whose vulnerabilities could impact national digital security. Participation is open to security researchers acting in good faith.
Provision
NCSC Coordinated Vulnerability Disclosure (CVD) Framework
Description

Switzerland’s National Cyber Security Centre (NCSC) established a national Coordinated Vulnerability Disclosure (CVD) framework in December 2022. The framework outlines non-binding but formalized procedures for the intake, triage, and remediation of reported security vulnerabilities. It provides safe harbor protections for good-faith researchers, supports anonymous submissions, and requires initial triage within five business days and remediation within sixty days. The NCSC also acts as a CVE Numbering Authority (CNA) for relevant cases. While participation is voluntary and the framework does not include financial incentives, it encourages the publication of vulnerability disclosure points of contact and fosters alignment with recognized CVD best practices. The framework remains active beyond the duration of the 2022–2025 “Promotion of Ethical Hacking” initiative and reflects Switzerland’s national commitment to structured vulnerability handling and disclosure.

Date
December 2022
Organization
National Cyber Security Centre (NCSC), under the Federal Department of Defence, Civil Protection and Sport (DDPS); transitioning to the Federal Office for Cybersecurity (BACS) as of 2024
Jurisdiction
Region
Requirement
Policy
ENISA Technical Implementation Guide for NIS2 Directive (Version 1.0)
Applies to
Essential and important entities subject to the Implementing Regulation (EU) 2024/2690, including DNS service providers, top-level domain registries, cloud computing and datacenter providers, content delivery networks, managed service and security service providers, online marketplaces, search engines, social networking platforms, and trust service providers.
Provision
Section 6.4.2 – Vulnerability handling and disclosure
Description

Section 6.4.2 of the ENISA Technical Implementation Guide for NIS2 (v1.0, June 2025) provides non-binding technical guidance on the implementation of Article 21(2)(f) of Directive (EU) 2022/2555 and Annex I, Section 6 of the Implementing Regulation (EU) 2024/2690. It emphasizes the establishment of formal vulnerability handling and disclosure processes, including the adoption of public Vulnerability Disclosure Policies (VDPs) and support for Coordinated Vulnerability Disclosure (CVD). The guidance outlines good practices such as the publication of VDPs on organizational websites, clear communication channels for external reporters, defined response timelines, and alignment with international standards (e.g., ISO/IEC 29147, ISO/IEC 30111). It also includes practical implementation steps and evidence examples for demonstrating conformity during supervision by competent authorities.

Date
June 26, 2025
Organization
European Union Agency for Cybersecurity (ENISA)
Region
Requirement
Policy
Decision No. 1202 - OSCE Confidence-Building Measures to Reduce the Risks of Conflict Stemming from the Use of Information and Communication Technologies
Applies to
OSCE Member States
Provision
CBM 16
Description
Participating States will, on a voluntary basis, encourage responsible reporting of vulnerabilities affecting the security of and in the use of ICTs and share associated information on available remedies to such vulnerabilities, including with relevant segments of the ICT business and industry, with the goal of increasing co-operation and transparency within the OSCE region. OSCE participating States agree that such information exchange, when occurring between States, should use appropriately authorized and protected communication channels, including the contact points designated in line with CBM 8 of Permanent Council Decision No. 1106, with a view to avoiding duplication.
Date
March 2016
Organization
Organization for Security and Co-operation in Europe (OSCE)
Region
Requirement
Policy
ETSI 303 645
Applies to
Manufacturers
Provision
Provision 5.2-1
Description

The manufacturer shall make a vulnerability disclosure policy publicly available. This policy shall include, at a minimum: 

• contact information for the reporting of issues; and 

• information on timelines for: 1) initial acknowledgement of receipt; and 2) status updates until the resolution of the reported issues.

Date
June 2020
Organization
ETSI - European Telecommunications Standards Institute
Region
Requirement
Policy
ESTI TR 103 838, Cyber Security; Guide to Coordinated Vulnerability Disclosure
Applies to
Companies and organizations
Provision
N/A
Description

Provides guidance regarding the "essential steps" companies should take when deciding to implement a VDP. ESTI explicitly states that the document is not intended to a 'comprehensive' guide.

Date
January 2022
Organization
ETSI - European Telecommunications Standards Institute
Jurisdiction
Region
Policy
Code of Practice for Software Vendors
Applies to
Software developers, distributors, and resellers
Provision
Principle 3.2
Description
3.2 Ensure the organisation implements and publishes an effective vulnerability disclosure process to support a transparent and open culture within the organisation.  Associated technical control: Implement a vulnerability disclosure policy. (The organisation publishes a vulnerability disclosure policy which provides a public point of contact in order that security researchers and others are able to report issues. Disclosed vulnerabilities are then reported to relevant parties (outlined in the implementation guidance) and acted on in a timely manner.)
Date
TBD
Organization
Department of Science, Innovation, & Technology