CVD Portal
by Aida Besic from Porta Regulus
(0 reviews)
Taxonomy:
Description
CVD Portal is a compliance platform for the EU Cyber Resilience Act (CRA) vulnerability disclosure obligations. Here are the major functions it provides.
Core Workflows
Vulnerability Intake and Management
- A branded public submission portal (company.cvdportal.com)
- Dashboard for triaging submissions, status tracking, CVSS 3.1 scoring, severity classification, coordinator assignment
- 48-hour acknowledgement tracking, aligned with ISO/IEC 29147 best practice
CRA Article 14 Reporting Workflow
- Tracks "actively exploited vulnerability" and "severe incident" flags
- Prepares the staged reports required from 11 September 2026, 24h early warning, 72h notification, 14-day final report for vulnerabilities or one month for severe incidents
- Reports route to the designated coordinator CSIRT via the ENISA Single Reporting Platform (SRP), with ENISA holding parallel access
- SRP-ready workflow and schema preparation on Pro and above. ENISA provides no submission API, so filing remains manual by design
Compliance Analytics and Reporting
- SLA compliance rates, severity distributions, response time metrics
- Full audit log, logins, status changes, API activity, team changes
- Exportable evidence packages for regulatory audits
Configuration and Settings
- CVD policy generator and editor, auto-published to the public portal
- PGP key management for encrypted submissions
- Team management with RBAC, webhook and API integrations
- SBOM upload, hardware component registry, security review scheduling
Free Educational Tools (no account needed)
- CVSS 3.1 Calculator
- Security.txt Generator
- CVD Policy Generator
- Article 14 Timeline Tracker
- CRA Readiness Assessment
- CSAF Validator, SBOM Checker
- Role-specific guides for CISO, legal, firmware developer, PSIRT and others
- Industry-specific compliance checklists for IoT, healthcare, industrial and automotive
Solution properties
-
Cloud, SaaS, web-based
- Market independent/agnostic (Means the solution overlaps all markets, and is linked to all)
- Direct sales
- System integrator(s)
-
The vendor did not specify this data field
Summary on Pricing plans
-
FreeSubscription (monthly/yearly)Perpetual license
Solution details
-
Small businessMid-size businessLarge enterprise
-
Croatian
-
Dutch
-
English
-
Greek
- ISO/IEC 27019 (Information security management guidelines based on ISO/IEC 27002 for process control systems specific to the energy utility industry)
- NIST Framework for Improving Critical Infrastructure Cybersecurity (NIST Cybersecurity Framework)
- NIST SP 800-53 (Security and Privacy Controls for Federal Information Systems and Organisations)
- Other: ISO/IEC 29147 aligned
- Other: EN 40000 series (draft harmonised standards)
- Other: CSAF 2.0 advisory export
Support services offered by the vendor ensuring the right implementation and functioning of the solution
Email/Help Desk
Knowledge Base
Phone Support
FAQs/Forum
Training services offered by the vendor enabling the end-user to use the solution
Live Online
Documentation
Videos
In Person
Webinars