4 Hours Total Duration | Full Course Position | Digital + Live Delivery | Foundation Portfolio Role |
The course establishes the baseline capability practitioners need to understand the cyber vulnerability reporting ecosystem, distinguish vulnerability disclosure from incident reporting, identify relevant stakeholders, and map the end-to-end vulnerability reporting lifecycle.
It's designed for product security officers, PSIRT leads, compliance managers, vulnerability response teams, engineering leads, QA staff, importers and distributors involved in CRA vulnerability handling and reporting.
The emphasis is practical and work-based. Learners do not simply learn definitions — they begin mapping how vulnerability reports currently enter, move through and escalate within their own organisation or a supplied case-study organisation.
The course prepares learners to understand how vulnerability reporting connects to:
– Vulnerability disclosure – Vulnerability handling – Coordinated Vulnerability Disclosure (CVD) – Product security response | – Incident reporting – Regulatory reporting – Manufacturer obligations under CRA Article 13 and Annex I |
This course is grounded in the following standards, frameworks and regulatory instruments:
Reference | Scope |
ISO/IEC 29147 | Vulnerability disclosure requirements and vendor recommendations |
ISO/IEC 30111 | Vulnerability handling and remediation processes |
CERT/CC CVD Guidance | Coordinated vulnerability disclosure stakeholders, process phases and operational failure points |
FIRST PSIRT Services Framework | PSIRT responsibilities, policy, triage, remediation and communications |
OWASP Vulnerability Disclosure Cheat Sheet | Researcher and organisational expectations for vulnerability disclosure |
NCSC Vulnerability Disclosure Toolkit | Practical implementation of vulnerability disclosure processes |
ENISA CRA Single Reporting Platform | Future reporting route for actively exploited vulnerabilities and incidents |
By the end of the course, learners will be able to:
1 | Explain the vulnerability reporting and coordinated disclosure lifecycle. |
2 | Distinguish between a vulnerability, weakness, exploit, exposure, threat, risk, incident and impact. |
3 | Identify the key internal and external stakeholders involved in vulnerability reporting. |
4 | Differentiate private disclosure, coordinated vulnerability disclosure, public disclosure, bug bounty reporting and incident reporting. |
5 | Recognise common vulnerability reporting failure modes. |
6 | Apply ethical and legal principles including authorisation, proportionality, safe harbour, researcher conduct and evidence handling. |
7 | Produce a first-version stakeholder map, current-state reporting process map and vulnerability lifecycle diagram. |
The course follows the standard four-component digital learning model used across the programme. All four components are mandatory and contribute to the learner’s portfolio.
Component | Mode | Duration | |
Part 1 | Foundation Digital Lesson | Pre-Recorded Digital Lesson | 60 Minutes |
Part 2 | Deep Dive Session 1 | Pre-Recorded Trainer-Led Session | 60 Minutes |
Part 3 | Deep Dive Session 2 | Pre-Recorded Trainer-Led Session | 60 Minutes |
Part 4 | Scenario / Simulation Assessment | Applied Assessment | 60 Minutes |
| # | Artefact |
| 1 | Stakeholder map |
| 2 | Current-state vulnerability reporting process map |
| 3 | Vulnerability lifecycle diagram |
| 4 | Glossary and terminology check |
| 5 | Initial maturity reflection |
Assessment is portfolio-based. The following standards describe the expected level of learner performance.
Level | Descriptor |
Competent | – Can explain who is involved in vulnerability reporting – Understands how vulnerability reports should enter an organisation – Can distinguish reporting, handling, disclosure and incident response – Identifies where early-stage communication and escalation risks arise – Understands why a structured reporting process matters for CRA readiness |
Strong | – All Competent descriptors, plus: – Identifies practical process weaknesses and unclear hand-offs – Recognises missing evidence requirements and documentation gaps – Flags early regulatory risk indicators relevant to the CRA – Produces a stakeholder and process map that is operationally credible and audit-ready |
€325.00