What must the public vulnerability disclosure policy include?
The public policy is not just a security mailbox. EN 303 645 provision 5.2-1 says the manufacturer shall make a vulnerability disclosure policy publicly available and that the policy includes contact information for reporting issues plus a timetable for initial acknowledgement and status updates until reported issues are resolved.
For visitors, buyers, researchers, and assessors, the policy should make the reporting path visible without requiring private documentation. TS 103 701 turns that into both a conceptual and functional assessment: the test laboratory checks the publication route described in IXIT 2-UserInfo and verifies that the policy is publicly accessible.
- Publish a clear external location for the vulnerability disclosure policy, such as a security page or support path that remains reachable without authentication.
- Include contact information that lets security researchers and other reporters submit potential vulnerabilities.
- State timelines for initial acknowledgement and for status updates until resolution, avoiding vague process text that gives reporters no expectation.
- Keep product documentation, app help, or support pages aligned with the public policy location if those channels direct users to report security issues.
Primary ETSI requirement for publishing a vulnerability disclosure policy with reporting contact information and acknowledgement/status-update timelines.
Assessment method for checking that the vulnerability disclosure policy publication is available and publicly accessible through IXIT 2-UserInfo.