Vulnerability found by a researcher or user
First find the manufacturer’s policy, security.txt file and security contact. Provide the affected product and version, a proportionate description, reproduction steps, impact and a secure return contact. Do not send unnecessary personal data, credentials or harmful content.
If the manufacturer cannot be identified, does not respond or multi-party coordination is required, use the NBÚ CVD portal and the national CVD policy. SK-CERT also directs a CRA-related vulnerability to CVD. Whether the submission is voluntary or mandatory under Article 14 depends on your role and the circumstances; choose the corresponding submission type.
Other concerns
- Possible CRA product non-compliance: see how to prepare a market-surveillance concern.
- Cyber threat or near miss: use the appropriate route on the official SK-CERT website.
- An incident in your organisation: check CRA and NIS2 for a separate reporting duty.
If you remain unsure, use reporting help. One event may require more than one separate notification.