Cyber Resilience Act Response Center Demo anfragen

Richtlinie zur koordinierten Offenlegung von Schwachstellen

CRA Response Center (Anbieter siehe Impressum). Version 1.0, erstellt am 8. Oktober 2026, nächste Prüfung spätestens im Oktober 2027. English version below.

Wir danken allen, die uns Schwachstellen melden. Diese Richtlinie beschreibt, wie Sie uns eine Schwachstelle melden, was Sie von uns erwarten dürfen und was wir von Ihnen erwarten. Sie folgt der Technischen Richtlinie BSI TR-03183-3, Abschnitt 4.4.

1. Geltungsbereich

Die Richtlinie gilt für die Software und die Dienste von CRA Response Center sowie für die Website cra-response-center.de mit ihren Formularen, Werkzeugen und Servern. Nicht erfasst sind Systeme von Dienstleistern, die wir nutzen; Hinweise dazu leiten wir weiter.

2. So melden Sie eine Schwachstelle

Bitte senden Sie vertrauliche Angaben verschlüsselt und signiert per E-Mail. Wir bearbeiten Meldungen auf Deutsch und Englisch. Hilfreich sind: betroffene Adresse, Komponente oder Version, eine Beschreibung, Schritte zur Nachstellung, die mögliche Auswirkung und gegebenenfalls ein Machbarkeitsnachweis. Bitte nennen Sie mindestens eine Kontaktmöglichkeit, am besten eine E-Mail-Adresse; eine Telefonnummer akzeptieren wir ebenso. Fragen nach dem Stand Ihrer Meldung sind jederzeit willkommen.

3. Was wir als Schwachstelle ansehen

Auch Hinweise auf bereits behobene Schwachstellen nehmen wir an und prüfen sie.

4. Unsere Zusagen

5. Was wir von Ihnen erwarten

Wer sich nicht daran hält, wird nicht in den Danksagungen genannt. Die Meldung bearbeiten wir trotzdem so gut wie möglich. Alle Beteiligten gehen respektvoll miteinander um; für Diskriminierung, Sexismus oder Beleidigungen ist kein Platz.

6. Ablauf und Fristen

Die Fristen gelten nicht für anonyme Meldungen.

7. Anonyme Meldungen

Über das Webformular können Sie anonym melden. Ohne Kontaktmöglichkeit können wir keine Rückfragen stellen; anonyme Meldungen können wir deshalb nur eingeschränkt oder unter Umständen gar nicht bearbeiten. Gerade bei komplexen Sachverhalten brauchen wir oft weitere Erläuterungen.

8. Aktiv ausgenutzte Schwachstellen

Wird eine Schwachstelle in unserer Software, unseren Diensten oder unserer Infrastruktur aktiv ausgenutzt, informieren wir unverzüglich das zuständige nationale CSIRT, in Deutschland CERT-Bund beim BSI, und stimmen weitere Schritte mit ihm ab. Für unsere Produkte melden wir aktiv ausgenutzte Schwachstellen außerdem nach Artikel 14 der Verordnung (EU) 2024/2847, unabhängig vom Stand dieses Verfahrens.

9. Veröffentlichung

Bestätigte Schwachstellen veröffentlichen wir binnen 90 Tagen. Gibt es einen triftigen Grund für eine längere Behebung, verlängern wir die Frist einmal um weitere 90 Tage in enger Abstimmung mit dem nationalen CSIRT; darüber hinaus nur, wenn das CSIRT zustimmt. Die Veröffentlichung erfolgt mindestens in der Europäischen Schwachstellendatenbank (EUVD) der ENISA. Den Zeitpunkt stimmen wir mit Ihnen ab.

10. Abschluss des Verfahrens

Wir betrachten ein Verfahren als abgeschlossen, wenn

Den Abschluss teilen wir Ihnen unverzüglich mit, außer bei anonymen Meldungen.

11. Datenschutz

Wie wir Ihre Daten bei einer Meldung verarbeiten, steht in unserer Datenschutzerklärung.

Coordinated Vulnerability Disclosure policy

CRA Response Center (provider: see legal notice). Version 1.0, created 8 October 2026, next review by October 2027 at the latest. This policy follows BSI TR-03183-3, section 4.4. The German version above is authoritative.

Scope

The software and services of CRA Response Center and the website cra-response-center.de with its forms, tools and servers.

How to report

Products and services (PSIRT): psirt@cra-response-center.de, key psirt.asc, fingerprint 3920 2416 872C 3ADE 73A9 EACC 3EEF 5D21 63A8 B393. Website and infrastructure (CSIRT): csirt@cra-response-center.de, key csirt.asc, fingerprint D82B 2661 BA06 B29D 7F56 71A2 F476 2447 105E 11D0. Web form, anonymous if you wish: cra-response-center.de/security-contact/. Please send confidential information encrypted and signed. We work in English and German. Please include the affected URL, component or version, a description, steps to reproduce, the possible impact and, if available, a proof of concept, plus at least one way to contact you (email preferred, phone accepted). Status enquiries are welcome.

What we consider a vulnerability

It affects our software, services or infrastructure; it is preferably not yet public; results of automated tools or scans without supporting documentation do not qualify. We also check reports about issues that have already been fixed.

Our commitments

We treat every report confidentially to the extent permitted by law, except for information needed for public disclosure. We do not share your personal data without your explicit consent. We will not pursue criminal charges as long as you follow this policy, unless criminal intent is evident. We remain available throughout the process and never require an NDA. On request, we list you by name or alias with a reference of your choice in our acknowledgements.

What we expect from you

Do not exploit the vulnerability beyond what is needed to demonstrate it and cause no damage; do not attack our systems (social engineering, spam, denial of service, brute force); do not manipulate or compromise third-party systems or data; do not offer exploitation tools to anyone; keep names, aliases and references free of offensive content. Reporters who do not comply will not be acknowledged, but we still handle their reports as well as we can. Everyone involved treats each other with respect; there is no room for discrimination, sexism or insults.

Response times

A human replies within 5 working days to each report or update (no automated reply). Detailed feedback follows within 10 working days: confirmation or rejection, meaningful questions, or an explanation why the analysis takes longer with a further update within 10 working days. No report is closed by a single analyst. These times do not apply to anonymous reports.

Anonymous reports

You can report anonymously through the web form. Without a way to contact you we cannot ask questions, so anonymous reports can only be processed to a limited extent or possibly not at all.

Actively exploited vulnerabilities

We notify the competent national CSIRT (CERT-Bund at BSI in Germany) without undue delay and coordinate with it. For our products we also report actively exploited vulnerabilities under Article 14 of Regulation (EU) 2024/2847.

Disclosure

Confirmed vulnerabilities are disclosed within 90 days, extendable once by 90 days in consultation with the national CSIRT and beyond that only with its consent, at least in ENISA's European Vulnerability Database (EUVD). We agree the timing with you.

End of the process

The process ends when the report proves unfounded; when a vulnerability in a service has been fixed and disclosed; when a vulnerability in our software has been fixed or mitigated by an update and disclosed; when the reporter has not responded to questions for at least 30 days; or when the vulnerability is public and, in consultation with the national CSIRT, a fix can no longer be expected. We tell you without undue delay, except for anonymous reports.

Privacy

See our privacy policy (German).