Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · OT security engineering

Coordinated vulnerability disclosure (CVD)

Also known as: CVD, Responsible disclosure

German: Koordinierte Schwachstellenoffenlegung (CVD)

In product security, coordinated vulnerability disclosure (CVD) is the process in which a vulnerability reporter, the affected manufacturer and, where needed, coordinators such as CSIRTs work together so that a vulnerability is fixed or mitigated before details are published, and users are informed through an advisory.

  • Security engineering
  • OT security
  • Standards

In one sentence

Coordinated vulnerability disclosure (CVD) lets reporters, manufacturers and CSIRTs fix a vulnerability before details are published in an advisory.

Example

A researcher reports a flaw in a PLC web interface to the vendor's security contact; the vendor confirms it, develops a fix, and publishes an advisory with a CVE ID on an agreed date.

Explained in context

Context cards connect this term with others to answer one question. Also in British English and German.

How it applies

  • Product development: Suppliers publish a CVD policy with a contact point, accept reports, acknowledge them, agree timelines with reporters and credit them where wanted. ISO/IEC 29147 covers disclosure; ISO/IEC 30111 covers the internal handling process.
  • Compliance: The Cyber Resilience Act (CRA) requires manufacturers to put in place and enforce a coordinated vulnerability disclosure policy and to provide a contact address for reporting. NIS 2 establishes CSIRTs as coordinators for CVD.
  • Operation: OT fixes take time to reach plants; advisories should therefore also offer mitigations for users who cannot update immediately.
  • Documentation: The CVD policy, the security contact and the location of advisories should appear in product documentation and on the manufacturer's website, so that reporters and customers can find them easily.

Coordinated vulnerability disclosure vs. full disclosure

Full disclosure publishes vulnerability details immediately, before a fix exists. CVD delays publication until users can protect themselves, within an agreed time frame.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: ISO/IEC 29147:2018, Information technology — Security techniques — Vulnerability disclosure

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Knowledge and are not part of any standard.

Seen a mistake? Send us a note!