Jurisdiction
Region
Requirement
Policy
Cyberbeveiligingswet (Cybersecurity Act) — implements NIS2 Directive (EU) 2022/2555, replacing the Wet beveiliging netwerk- en informatiesystemen (Wbni)
Applies to
CSIRTs; by extension, essential/important entities across NIS2 Annex I/II sectors operating in the Netherlands, and any party wishing to report a vulnerability
Provision
Artikel 17, eerste lid, Cyberbeveiligingswet — designation of a CSIRT as national CVD coordinator (mirrors NIS2 Article 12)
Description

Dutch (original): "Bij of krachtens algemene maatregel van bestuur wordt een CSIRT aangewezen als de coördinator met het oog op een gecoördineerde bekendmaking van kwetsbaarheden." 

English (translation): "By or pursuant to a general administrative order, a CSIRT shall be designated as the coordinator with a view to the coordinated disclosure of vulnerabilities." 

The designated CSIRT coordinator's tasks (Art. 17(2), per secondary summary — not independently re-verified verbatim) include acting as intermediary between reporters and affected manufacturers/providers, identifying and contacting affected entities, and coordinating with counterpart coordinators in other EU Member States.

Date
August 15, 2026
Organization
Dutch Ministry of Justice and Security (Ministerie van Justitie en Veiligheid); National Cyber Security Centre (NCSC-NL)
Jurisdiction
Region
Requirement
Policy
Gesetz zur Umsetzung der NIS-2-Richtlinie und zur Regelung wesentlicher Grundzüge des Informationssicherheitsmanagements in der Bundesverwaltung (NIS-2-Umsetzungsgesetz / NIS2UmsG)
Applies to
Approximately 29,000 entities across NIS2 Annex I (highly critical) and Annex II (other critical) sectors operating in Germany
Provision
§ 30 Absatz 2 Satz 2 Nummer 5 BSIG (as amended by NIS2UmsG) — risk-management measures including "vulnerability handling and disclosure" (transposes NIS2 Directive (EU) 2022/2555 Article 21(2)(e))
Description

Transposes NIS2 Article 21(2)(e): "security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure." The amended BSIG requires "besonders wichtige Einrichtungen" (essential) and "wichtige Einrichtungen" (important) entities to implement appropriate and proportionate technical, operational, and organisational measures, including vulnerability handling and disclosure. The BSI is empowered to coordinate vulnerability disclosure and issue public warnings about IT-product vulnerabilities.

Date
March 6, 2026
Organization
Bundestag; Federal Ministry of the Interior and Community (BMI); Federal Office for Information Security (BSI)
Jurisdiction
Region
Requirement
Policy
Cyber Security (Security Standards for Smart Devices) Rules 2025 (F2025L00276), made under the Cyber Security Act 2024
Applies to
Manufacturers of relevant connectable products (consumer IoT/smart devices) acquired by consumers in Australia
Provision
Schedule 1, Part 1, clause 3 — Requirements relating to reports of security issues
Description

"(1) The manufacturer of a relevant connectable product must publish the information in subclause (2) on how a person is to report security issues in relation to the product... (2) The information that must be published is: (a) at least one point of contact to allow a person to report security issues to the manufacturer; and (b) when a person who makes such a report will receive: (i) an acknowledgement of the receipt of the report; and (ii) status updates until the resolution of the reported security issues. (3) The information published must be accessible, clear and transparent, and must be made available to a person: (a) without prior request... (b) in English; and (c) free of charge; and (d) without requesting the provision of personal information about the person."

Date
March 4, 2026
Organization
Department of Home Affairs
Jurisdiction
Region
Requirement
Policy
Protective Security Policy Framework - Policy 11 - Robust ICT Systems
Applies to
Australian Government entities
Provision
C.6
Description

C.6 Vulnerability Disclosure Program 

60. Requirement 4 mandates that all entities must have in place a vulnerability disclosure program. This includes having a publicly available vulnerability disclosure policy supported by processes and procedures for receiving, verifying, resolving and reporting on security vulnerabilities disclosed by both internal and external sources. 

61. Implementing a vulnerability disclosure program, based on responsible disclosure, can assist entities, vendors and service providers to improve the security of their products and services as it provides a way for security researchers, customers and members of the public to responsibly notify them of potential security vulnerabilities in a coordinated manner. Furthermore, following the verification and resolution of a reported security vulnerability, it can assist entities, vendors and service providers in notifying their customers of any security vulnerabilities that have been discovered in their products and services and any recommended security patches, updates or mitigations. 

62. For guidance on the creation and maintenance of vulnerability disclosure programs, see the Information Security Manual and Guidelines for Software Development.

A new iteration of the Guidelines for Software Development, including updated guidance on vulnerability disclosure programs, was published in March 2025.

Date
July 29, 2022
Organization
Australian Department of Home Affairs
Jurisdiction
Region
Requirement
Policy
Act Nº 2436, Requisitos Mínímos de Segurança Cibernética Para Avaliação da Conformidade de Equipamentos CPE (Minimum Cybersecurity Requirements for Assessing Compliance of CPE (Customer Premises Equipment))
Applies to
Vendors of Customer Premises Equipment (CPE) used by the general public to connect to ISPs
Provision
Sections 7.1.4, 7.1.5
Description

7.1.4. Item 6.1.5 - Disponibilizar um canal de comunicação que possibilite aos seus clientes, usuários finais e terceiros notificarem vulnerabilidades de segurança identificadas nos produtos. 

7.1.4.1. Este canal deve: a) ser exclusivo para a notificação de vulnerabilidades; e b) implementar comunicações seguras como, por exemplo: formulário web com uso de HTTPS, e-mail criptografado com PGP ou outro esquema de chave pública (a chave pública associada ao endereço de e-mail deve ser disponibilizada para que os interessados possam, se assim desejarem, enviar mensagens cifradas). 

7.1.5. Item 6.1.6 - Possuir implementado processo de Divulgação Coordenada de Vulnerabilidades baseados em boas práticas e recomendações reconhecidas internacionalmente, tais como as referências 2.6 a 2.8 deste documento. 

7.1.5.1. A Política de Divulgação Coordenada de Vulnerabilidade do fornecedor deve ser publicada em sua página na Internet e deve contemplar, no mínimo, os seguintes itens: a) Os objetivos do fornecedor, suas responsabilidades, bem como o que ele espera de outras partes interessadas. b) Como deseja ser notificado (ex.: e-mail, formulário em página na Internet) e os respectivos contatos (ex.: endereço de e-mail, URL de formulário web). c) Detalhamento das opções de comunicação segura (ex.: chave PGP para e-mail, formulário seguro via HTTPS). d) Quais informações o notificador deve incluir na notificação. e) O que o notificador deve esperar após reportar uma vulnerabilidade como, por exemplo: reconhecimento do recebimento da notificação, reconhecimento da vulnerabilidade, atualizações na evolução do caso e seus respectivos prazos. f) Orientação sobre o que está dentro e fora do escopo do processo de notificação, suas limitações, etc. 

7.1.4. Item 6.1.5 - Provide a communication channel that allows its customers, end users and third parties to report security vulnerabilities identified in the products. 

7.1.4.1. This channel must: a) be exclusive for the notification of vulnerabilities; and b) implement secure communications such as: web form using HTTPS, email encrypted with PGP or another public key scheme (the public key associated with the email address must be made available so that interested parties can, if they so wish, send encrypted messages). 

7.1.5. Item 6.1.6 - Have implemented a Coordinated Vulnerability Disclosure process based on internationally recognized good practices and recommendations, such as references 2.6 to 2.8 of this document. 7.1.5.1. The supplier's Coordinated Vulnerability Disclosure Policy must be published on its website and must address, at a minimum, the following items: a) The supplier's objectives, its responsibilities, as well as what it expects from other interested parties. b) How you wish to be notified (e.g. email, web form) and your contact details (e.g. email address, web form URL). c) Details of secure communication options (e.g.: PGP key for email, secure form via HTTPS). d) What information the notifier must include in the notification. e) What the notifier should expect after reporting a vulnerability, such as: acknowledgement of receipt of the notification, acknowledgement of the vulnerability, updates on the evolution of the case and their respective deadlines. f) Guidance on what is within and outside the scope of the notification process, its limitations, etc. 

Date
March 10, 2024
Organization
ANATEL
Region
Requirement
Policy
Regulations on the Management of Security Vulnerabilities in Network Products
Applies to
Network product providers, network operators and network product security vulnerability collection platforms
Provision
Article 5, Article 6
Description
Article 5: Network product providers, network operators and network product security vulnerability collection platforms shall establish and improve channels for receiving network product security vulnerability information and keep them open, and retain network product security vulnerability information receiving logs for no less than 6 months.  Article 6: "Encourages relevant organizations and individuals to report security vulnerabilities in their products to network product providers" and "Encourage network product providers to establish a reward mechanism for security vulnerabilities in the network products they provide, and reward organizations or individuals who discover and report security vulnerabilities in the network products they provide."
Date
July 2021
Organization
Ministry of Industry and Information Technology
Jurisdiction
Region
Requirement
Policy
Cyber ​​Security Law of the Republic of Lithuania No. XII-1428 Law amending Articles 1, 2, 6, 8, 9, 13, the title of Chapter V, the appendix and supplementing the Law with Article 17 and Chapter VI
Applies to
Reporters of Vulnerabilities
Provision
Article 8 (Adding Article 17)
Description
Provides a definition for what constitutes the legitimate disclosure of a vulnerability by a private person; it also determines the following restrictions: 1. The operation, functionality, services and data availability or integrity of the communication and information system may not be disrupted or altered. 2. When a vulnerability is identified, the search activity is terminated. 3. Within 24 hours of the start of the search activity, information on search results must be submitted to the NCSC under the Ministry of National Defence or CSE. 4. It is not unnecessarily sought to validate, monitor, record, intercept, acquire, store, disclose, copy, modify, corrupt, delete, destroy data managed by a cybersecurity entity. 5. No attempts are made to guess passwords. Passwords obtained illegally are not used and employees of the CSE or other persons who have the right to use non-public information relevant to the search for loopholes are not exploited or manipulated in order to obtain the information. 6. Information about the detected vulnerability is shared only with the NCSC under the Ministry of National Defence or CSE and made public according to the amendment. 
Date
June 2021
Organization
Ministry of National Defense
Jurisdiction
Region
Requirement
Policy
Law for a Digital Republic
Applies to
ANSSI (French government agency)
Provision
Article 47
Description
Creates a safe harbor for vulnerability reporters if they are acting in good faith, and if they report it to ANSSI exclusively.
Date
October 2016
Organization
Congrès du Parlement
Jurisdiction
Region
Requirement
Policy
M-23-16, update to memorandum M-22-18, Enhancing the Security of the Software Supply Chain through Secure Software Development Practices
Applies to
Software producers that serve the Federal government
Provision
Section 4.b of the Self-Attestation Common Form
Description

Requires software producers attest that they have a policy or process to address discovered security vulnerabilities prior to product release. This requirement is part of the U.S. federal government's secure software development initiative under OMB Memorandum M-22-18, and was further clarified in OMB Memorandum M-23-16 (June 2023), which extended agency deadlines for collecting attestations and introduced the use of Plans of Action and Milestones (POA&Ms) when full compliance is not immediately feasible.

Date
June 9, 2023
Organization
OMB