EM2 - CRA Sequence
To view this email as a web page, click here
HackerOne

CYBER RESILIENCE ACT

Are you audit ready?

Hi ala,

Most organisations already have somewhere to send security issues, usually a shared inbox. Under the CRA, that is the gap.


A shared mailbox cannot timestamp when you become aware, classify severity quickly, route the right details to the right owners, or produce the audit trail a regulator will expect. When reporting windows are measured in hours, the process has to be structured.


A vulnerability disclosure programme (VDP) on the H1 Platform is built for exactly this. It gives you:

  • Structured intake with full metadata, so every report is captured and tracked in one place, not lost in an email thread.
  • A process aligned to ISO/IEC 29147 and 30111, the standards that govern vulnerability disclosure and handling, so your process is consistent, defensible, and audit-ready.
  • SLA setting and reporting, so you can define response targets, track them, and evidence the timelines the CRA expects.

This is the front door. It is also the foundation everything else builds on.

Warm regards,
Rebecca Taylor