A vulnerability disclosure policy (VDP) establishes a regulated reporting channel: it defines the scope, the rules of engagement and legal assurances for external reporters – without promising any reward. A bug bounty program builds on top of it and pays for valid findings in order to deliberately direct testing effort at your own systems. Public programs are open to everyone and maximize reach, but generate considerable triage effort; private programs invite selected, vetted researchers and allow tighter control of scope and quality. The proven sequence is: first a VDP and an internal handling process, then a bounty program.
Bug Bounty & Vulnerability Disclosure
How to receive, process and reward vulnerability reports from external security researchers in a structured way – from a vulnerability disclosure policy to a private bug bounty program.
2complementary standards: ISO/IEC 29147 & ISO/IEC 30111
90days — the widely established CVD deadline convention
24hours to the early warning under CRA Art. 14 (from 11 September 2026)
3basic operating models: in-house, platform, managed program
External security researchers find vulnerabilities – the question is whether your organization offers them an orderly channel. A vulnerability disclosure policy (VDP), a coordinated vulnerability disclosure process and, where appropriate, a bug bounty program are the maturity stages that turn uncoordinated chance findings into a manageable process. The standards ISO/IEC 29147 and ISO/IEC 30111, together with security.txt under RFC 9116, provide the established framework. With the Cyber Resilience Act, orderly vulnerability handling also becomes a regulatory obligation for manufacturers – including a CVD policy, a reporting contact and reporting obligations that apply from September 2026.
The Essentials at a Glance
Six topic blocks — tap to expand.
VDP, bug bounty and operating models compared
From a regulated reporting channel to a managed program — the maturity stages at a glance.
- A vulnerability disclosure policy establishes a regulated reporting channel: it defines the scope, the rules of engagement and legal assurances for external reporters — without promising any reward.
- The proven sequence: first a VDP and an internal handling process, then a bounty program.
scoperules of engagementlegal assurancesreporting channel
- A bug bounty program builds on top of the VDP and pays for valid findings in order to deliberately direct testing effort at your own systems.
- Public programs are open to everyone and maximize reach, but generate considerable triage effort; private programs invite selected, vetted researchers and allow tighter control of scope and quality.
publicprivatevetted researcherstriage effort
- Rewards are usually tied to severity, most commonly based on FIRST's Common Vulnerability Scoring System (CVSS), currently in version 4.0 (2023).
- Fixed amounts or ranges per severity level are common; as a rule, only the first valid report of a vulnerability is rewarded — duplicates and out-of-scope findings are not.
CVSS 4.0FIRSTseverityduplicatesout-of-scope
- In-house: full control, but your own triage and payout effort.
- Commercial platforms: broad reach, but more noise in triage.
- Managed programs: curated, identified researchers with triage handled by the provider — VamiSec, for example, runs a private, curated bug bounty program as a managed service.
in-housecommercial platformsmanaged programstriage
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
ISO/IEC 29147:2018 – Information technology – Security techniques – Vulnerability disclosure
Requirements and recommendations for receiving vulnerability reports and publishing remediation information; edition 2, most recently confirmed in 2024.
ISO/IEC 30111:2019 – Information technology – Security techniques – Vulnerability handling processes
Requirements for the internal process of verifying, assessing and remediating reported vulnerabilities; edition 2, most recently confirmed in 2025.
RFC 9116: A File Format to Aid in Security Vulnerability Disclosure
Defines security.txt under /.well-known/ with the mandatory fields Contact and Expires as a machine-readable entry point for vulnerability reports.
Verordnung (EU) 2024/2847 (Cyber Resilience Act)
Annex I Part II with the vulnerability handling obligations, including a CVD policy and a reporting contact; the reporting obligations under Art. 14 apply from 11 September 2026, the remaining obligations essentially from 11 December 2027.
Leitlinie des BSI zum Coordinated Vulnerability Disclosure (CVD)-Prozess
Describes how the BSI handles vulnerability reports, its role as coordinator and its expectations of reporters (version 1.0, December 2022).
Coordinated vulnerability disclosure policies in the EU
Stocktake of national CVD policies in the EU Member States, with an outlook on the obligation introduced by NIS2 to adopt national CVD policies.
Related Services
Which model fits your organization?
From security.txt to a CVD policy to a private bug bounty program: in a no-obligation initial consultation, we help you determine which entry point makes sense for you.