Cloud & SaaS PDEAll RoutesAll Product ClassesAudited: September 2026 (Active SRP Era)

CVD Portal

Turnkey Coordinated Vulnerability Disclosure (RFC 9116) & ENISA Intake Gateway

Executive Conformity Assessment Verdict

The most efficient way for hardware and software manufacturers to fulfill their statutory Article 10 coordinated vulnerability disclosure obligations without building custom security infrastructure.

Hosted Coordinated Vulnerability Disclosure (CVD) policy manager, security.txt generator, and encrypted vulnerability intake platform satisfying Article 10.

Verified Pricing TierFree tier to €299 / month
Deployment ModelSaaS
Applicable CRA RouteAll Routes
Target Product TierAll Product Classes
Statutory Audit

Statutory Capability & Article Coverage Matrix

How CVD Portal performs against non-negotiable statutory mandates of Regulation (EU) 2024/2847.

Technical Documentation Dossier
Annex VIINo
EU Declaration of Conformity
Annex VNo
Coordinated Vulnerability Disclosure (CVD)
Article 10 & RFC 9116Native Hosted Endpoint
24-Hour ENISA Early Warning Dispatch
Article 14 (Active Sept 2026)Direct SRP Schema Bridge
Substantial Modification Diff Engine
Article 22No
Binary Firmware Disassembly & SCA
Annex I Part I (1)(a)Ingest Only
Air-Gapped / Island-Mode Deployment
Data Sovereignty & IP ProtectionPublic Cloud Only
Multi-Act Cross-Walk Coverage:CRA Article 10CRA Article 14NIS2 Article 21
Technical Architecture

Architectural Fit & Deployment Analysis

Acts as the public-facing security boundary for the manufacturer. Connects security researchers discovering zero-day vulnerabilities in the wild directly to internal engineering and legal response teams.

Guarantees an auditable paper trail. When a vulnerability report arrives, CVD Portal starts the statutory 24-hour Article 14 early warning countdown timer, preventing missed regulatory deadlines.

Does not remediate or fix the vulnerability. Once the vulnerability report is triaged, internal software engineers must still develop, test, and distribute the firmware patch.

Verified Key Strengths
Zero-setup security.txt RFC 9116 automated endpoint generation and DNS hosting
Encrypted PGP security researcher intake forms protecting proprietary vulnerability disclosures
Audit-proof statutory timeline logging tracking researcher initial response within statutory windows
Pre-formatted export matching the official ENISA Article 14 Single Reporting Platform schema
Structural Limitations & Gaps
Point solution focused strictly on vulnerability disclosure intake and early warning alerts
Cannot generate the pre-market Annex VII technical documentation file or Annex V DoC
Does not analyze software binaries or scan repositories for vulnerabilities
Commercial Model

Pricing, Packaging & Total Cost of Ownership (TCO)

Free tier to €299 / month
Entry Tier
Free: €0 / month (Basic security.txt generator and hosted researcher intake inbox)
Mid / Scale Tier
Reporting: €99 / month (Article 14 24-hour early warning workflow, automated researcher acknowledgments)
Enterprise Tier
Compliance: €299 / month (Complete coordinated disclosure lifecycle, encrypted PGP intake, CSIRT notification dispatch)
Hidden Cost Factors:
  • Custom domain SSL certificates (included in compliance tier)
TCO Verdict:Inexpensive, dedicated gateway that solves the statutory Article 10 CVD requirement in minutes.
Statutory Honesty Notice • Article 32 & Article 24

Article 10 requires active vulnerability handling, not merely a static web form. Manufacturers must ensure human PSIRT personnel actively monitor the intake queue.

Recommended Complementary Directory ToolsView All 18 Evaluated Tools
Recommended Pair
Regulus Cyber
Inspect in Directory
Recommended Pair
Sbomify
Inspect in Directory
Recommended Pair
CRA Portal
Inspect in Directory

This Site Uses No Cookies

Eigenia does not set cookies. The only thing stored in your browser is one preference, saved in local storage, noting that you have seen this notice.