Jurisdiction
Region
Requirement
Policy
Law for a Digital Republic
Applies to
ANSSI (French government agency)
Provision
Article 47
Description
Creates a safe harbor for vulnerability reporters if they are acting in good faith, and if they report it to ANSSI exclusively.
Date
October 2016
Organization
Congrès du Parlement
Jurisdiction
Region
Policy
Cyber Security Strategy for Germany 2021
Applies to
Government agencies
Provision
Section 8.1.8
Description
8.1.8 Responding responsibly to vulnerabilities – promoting coordinated vulnerability Our aim is for the Federal Government to develop a framework to ensure that those reporting bugs have legal certainty if they approach companies to inform them that they have become aware of vulnerabilities, with a view to fostering proactive vulnerability governance. There will be reliable points of contact for them to report their findings. These can take the form of internal contact points which companies themselves are obligated to set up, or the BSI as a public liaison office. The legislator will obligate the companies affected to provide points of contact and processes to enable them to fix reported vulnerabilities in a suitable time frame. The extent to which the rights and duties are set out on both sides of the CVD process will be examined. These rights and duties could include a holdback period before making vulnerabilities public or a binding deadline for patches or updates. A coordinated process will be put in place between the BSI and manufacturers which extends beyond the simple exchange of information. This will also apply to vulnerabilities in the IT supply chains of products and services (supply chain security).
Date
2021
Organization
Federal Ministry of the Interior, Building, and Community
Jurisdiction
Region
Policy
The Danish National Strategy for Cyber and Information Security
Applies to
Government agencies
Provision
Appendix 1.12
Description

A pilot for a government CVD (Coordinated Vulnerability Disclosure) policy was initiated. This policy aims to provide a framework for government agencies to allow private individuals (“helpful hackers”) to identify and report vulnerabilities in ICT systems. The finalized government-wide CVD policy is still forthcoming.

Date
December 2021
Organization
Danish Government
Jurisdiction
Region
Policy
Action Plan for the National Cybersecurity Strategy of the Czech Republic 2021-2025
Applies to
TBD
Provision
Code 11
Description

Czechia's NUKIB will "draft a national policy proposal for the coordinated disclosure of vulnerabilities" by Q4 2021. Originally targeted for Q4 2021, publication is pending as of mid-2025.

Date
TBD
Organization
National Cyber and Information Security Agency (NÚKIB)
Jurisdiction
Region
Requirement
Policy
Guide to Coordinated Vulnerability Disclosure Policies, Part II: Legal Aspects
Applies to
Companies and organizations
Provision
N/A
Description

Outlines the specific legal consequences of a CVD as they relate to Intrusion into an IT system; Manipulation of IT data; IT forgery and IT fraud; Crimes concerning the secrecy of communications; and Compliance with other legal provisions.

Date
December 2020
Organization
Centre for Cyber Security Belgium
Jurisdiction
Region
Requirement
Policy
Guide to Coordinated Vulnerability Disclosure Policies, Part I: Good Practices
Applies to
Companies and organizations
Provision
N/A
Description

Outlines "good practices" for the content of a CVD and for the overall process of Discovery, Report, Investigate, Deploy a Solution, and (Possibly) Disclose Publicly.

Date
December 2020
Organization
Centre for Cyber Security Belgium
Jurisdiction
Region
Requirement
Policy
Cybersecurity Strategy Belgium 2.0 2021-2025
Applies to
Companies and organizations
Provision
Section 3.2.2
Description

Companies and organizations are urged to publish a “Coordinated Vulnerability Disclosure Policy.” Through sectoral authorities, professional organizations and the Cyber Security Coalition Belgium, they will be informed of significant threats or vulnerabilities. Organizations of Vital Interest will also receive targeted and non-public alerts through the CCB’s Early Warning System (EWS).  Additionally, Belgium has established a legal framework (effective February 15, 2023) providing protections for ethical hackers who report vulnerabilities in good faith, ensuring they are not subject to prosecution under certain conditions.

Date
May 2021
Organization
Centre for Cyber Security Belgium
Jurisdiction
Region
Requirement
Policy
Coordinated Vulnerability Disclosure Policies in the EU
Applies to
EU Member States
Provision
Section 4
Description

Encourages EU member states to implement CVD policies by providing recommendations for how to overcome the associated legal, economic, political, operational, and crisis management challenges. In the document, ENISA also hinted that, in the future, it might provide clear guidance to countries about how to establish a CVD policy, publish countries’ best practices and challenges, and publishing templates upon which countries can draft their policies. Since April 2022, ENISA has published updated guidance and practical templates to assist member states in establishing effective CVD policies.

Date
April 2022
Organization
European Union Agency for Cybersecurity (ENISA)
Jurisdiction
Region
Requirement
Policy
NIS 2 Directive (Directive (EU) 2022/2555)
Applies to
Important and essential entities (as defined, similar to critical infrastructure)
Provision
Article 21.2(e)
Description

2. The measures referred to in paragraph 1 shall be based on an all-hazards approach that aims to protect network and information systems and the physical environment of those systems from incidents, and shall include at least the following: (a) policies on risk analysis and information system security; (b) incident handling; (c) business continuity, such as backup management and disaster recovery, and crisis management; (d) supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers; (e) security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure;

Date
October 17, 2024
Organization
European Parliament / Commission / Council