Book an Appointment

Bug Bounty & Vulnerability Disclosure

How to receive, process and reward vulnerability reports from external security researchers in a structured way – from a vulnerability disclosure policy to a private bug bounty program.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

2complementary standards: ISO/IEC 29147 & ISO/IEC 30111
90days — the widely established CVD deadline convention
24hours to the early warning under CRA Art. 14 (from 11 September 2026)
3basic operating models: in-house, platform, managed program

External security researchers find vulnerabilities – the question is whether your organization offers them an orderly channel. A vulnerability disclosure policy (VDP), a coordinated vulnerability disclosure process and, where appropriate, a bug bounty program are the maturity stages that turn uncoordinated chance findings into a manageable process. The standards ISO/IEC 29147 and ISO/IEC 30111, together with security.txt under RFC 9116, provide the established framework. With the Cyber Resilience Act, orderly vulnerability handling also becomes a regulatory obligation for manufacturers – including a CVD policy, a reporting contact and reporting obligations that apply from September 2026.

The Essentials at a Glance

Six topic blocks — tap to expand.

VDP, bug bounty and operating models compared

From a regulated reporting channel to a managed program — the maturity stages at a glance.

Reporting channel
  • A vulnerability disclosure policy establishes a regulated reporting channel: it defines the scope, the rules of engagement and legal assurances for external reporters — without promising any reward.
  • The proven sequence: first a VDP and an internal handling process, then a bounty program.
scoperules of engagementlegal assurancesreporting channel

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

ISO/IEC · 2018

ISO/IEC 29147:2018 – Information technology – Security techniques – Vulnerability disclosure

Requirements and recommendations for receiving vulnerability reports and publishing remediation information; edition 2, most recently confirmed in 2024.

ISO/IEC · 2019

ISO/IEC 30111:2019 – Information technology – Security techniques – Vulnerability handling processes

Requirements for the internal process of verifying, assessing and remediating reported vulnerabilities; edition 2, most recently confirmed in 2025.

IETF (RFC Editor) · 2022

RFC 9116: A File Format to Aid in Security Vulnerability Disclosure

Defines security.txt under /.well-known/ with the mandatory fields Contact and Expires as a machine-readable entry point for vulnerability reports.

Amtsblatt der EU / EUR-Lex · 2024

Verordnung (EU) 2024/2847 (Cyber Resilience Act)

Annex I Part II with the vulnerability handling obligations, including a CVD policy and a reporting contact; the reporting obligations under Art. 14 apply from 11 September 2026, the remaining obligations essentially from 11 December 2027.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2022

Leitlinie des BSI zum Coordinated Vulnerability Disclosure (CVD)-Prozess

Describes how the BSI handles vulnerability reports, its role as coordinator and its expectations of reporters (version 1.0, December 2022).

ENISA · 2022

Coordinated vulnerability disclosure policies in the EU

Stocktake of national CVD policies in the EU Member States, with an outlook on the obligation introduced by NIS2 to adopt national CVD policies.

Which model fits your organization?

From security.txt to a CVD policy to a private bug bounty program: in a no-obligation initial consultation, we help you determine which entry point makes sense for you.