Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    Topic hub

    Coordinated Vulnerability Disclosure (CVD)

    Coordinated Vulnerability Disclosure (CVD) is now table-stakes postmarket evidence: the FDA's 2016 postmarket guidance, the 2026 premarket guidance, AAMI TIR97, and ISO/IEC 29147 + 30111 all expect a published, monitored intake channel and a documented triage/remediation process. This hub pulls together our CVD policy, the services that stand it up, the postmarket guides that wrap around it, and the standards reference - so you can ship a CVD program reviewers can audit, not a security.txt file no one watches.

    The short answer

    Coordinated vulnerability disclosure is a Section 524B(b)(1) requirement, not a nice-to-have. A compliant program publishes a reachable intake path (security.txt, a disclosure page, a monitored mailbox), commits to acknowledgment and status timelines, defines triage and severity assignment tied to patient safety, coordinates with CISA and the relevant ISAC where appropriate, and issues customer security advisories. The FDA expects the policy in the submission and the records in the QMS.

    Start here: FDA Postmarket Cybersecurity 11 resources in this hub · 4 in-depth guides · 4 FAQs
    Topic FAQ

    Coordinated Vulnerability Disclosure (CVD) - frequently asked questions

    Ready when you are

    Get FDA cleared without the cybersecurity headaches.

    30-minute strategy session. No cost, no commitment - just answers from people who've shipped 250+ FDA submissions.