National Coordinated Vulnerability Disclosure (CVD)
Last updated 21st September 2026: Page Published
Protecting Ireland's digital infrastructure requires an active partnership between organisations and the security research community.
Addressing vulnerabilities in systems before threat actors can exploit them is essential to strengthening our national cyber resilience.
To support this, the NCSC has published the Guidelines for Implementing a Coordinated Vulnerability Disclosure (CVD) Policy document. This provides organisations with a framework for defining clear boundaries for researchers, through to developing an internal vulnerability management policy and encouraging collaborative communication throughout the remediation life cycle.
Guidelines for Implementing a CVD Policy (PDF)
Jump to: For Organisations | For Security Researchers | Role of the NCSC
Organisations: Move from Reactive to Proactive
Security vulnerabilities in digital products and services are inevitable. Without a structured CVD policy that allows security researchers acting in good faith to report these flaws, your organisation risks unidentified security flaws being exploited.
Adopting a CVD policy costs very little to implement but can significantly reduce your exposure to cyberattacks.
What you need to do:
- Establish an internal process to securely receive, triage, and handle vulnerability reports.
- Publish a security.txt file and CVD policy that clearly defines the assets and systems in scope for testing.
- Commit to a "Safe Harbour" for security researchers acting in good faith and within the bounds of your policy.
- Engage with researchers in a timely manner, providing updates throughout the remediation lifecycle.
- Avoid non-disclosure agreements that will discourage reporting.
- Credit researcher contribution and agree disclosure once the flaw is remediated.
Researchers: Rules of Engagement
The role of independent security researcher is vital to Irelands cyber resilience as they act as early warning partners in discovering security flaws in our digital infrastructure.
To ensure this testing is conducted safely and legally, the NCSC encourages a collaborative approach and based on clear boundaries.
How security researchers should behave:
- Conduct all activities ethically ensuring no disruption to the confidentiality, integrity or availability of systems and data.
- No pre-conditions to sharing a report.
- Data boundaries should be respected and activity stopped immediately if PII is encountered.
- Report the vulnerability as soon as possible after discovery.
- Allow sufficient time for the organisation to develop and deploy a patch before public disclosure.
- Utilise the NCSC as intermediary if communication difficulties are encountered.
What is the role of the NCSC?
As the national CSIRT, the NCSC is a trusted intermediary ensuring that vulnerabilities are securely handled, coordinated, and resolution is prioritised.
- The NCSC can act as a neutral party to ensure reports reach and are actioned by the appropriate organisation.
- While direct contact with the organisation is the preferred approach for reporting, notifying the NCSC helps maintain a critical national overview of potential threats.
- The NCSC can assist where multiple organisations are involved or if there is a cross border element to the vulnerability.
- Once a reported vulnerability is resolved, the NCSC supports appropriate recognition such as inclusion in a future NCSC Hall of Fame.
While the NCSC facilitates anonymous reporting as a service to build trust, the role is to assist organisations in receiving and thus addressing vulnerability reports.
We would encourage all parties to engage in the spirit of these Guidelines. However, researchers should note that while the NCSC acts as a neutral intermediary, it may be legally obliged to provide the appropriate authorities with all information available to them.
Researchers are encouraged to read the section 'Legal Context of CVD in Ireland' in the Guidelines.