Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.




Industry Leadership
Strategic Initiatives
CSA's strategic programs driving innovation in AI, cloud, and Zero Trust.
A public-interest 501(c)(3) dedicated to secure and trustworthy AI.

CSAI FoundationChaptersEventsBlog
Share how your organization secures AI-generated data and uses AI to strengthen data security in this short survey →

STAR Registry Listing for

CVD Portal

CVD Portal

CVD Portal is a multi-tenant SaaS compliance and coordinated vulnerability disclosure platform for manufacturers selling products with digital elements into the European Union under the EU Cyber Resilience Act (Regulation (EU) 2024/2847).

Core Capabilities
  • Coordinated Vulnerability Disclosure (CVD): Provides RFC 9116 security.txt generation and hosting, whitelabel HTTPS researcher intake portals, and 48-hour acknowledgment SLA tracking aligned with ISO/IEC 29147.
  • Statutory Authority Reporting (Article 14): Automates mandatory CRA reporting workflows, preparing ready-to-file packages for 24-hour early warnings, 72-hour notifications, and 14-day final reports for national CSIRTs and the ENISA Single Reporting Platform (SRP).
  • Vulnerability Triage & Security Advisories: Implements CVSS v3.1 and CVSS v4.0 scoring engines, CISA KEV exploitation correlation, PGP-encrypted researcher communications, and automated CSAF 2.0 (Common Security Advisory Framework) JSON advisory publishing.
  • Software Supply Chain & SBOM Management: Built-in in-house conformance engine for CycloneDX (v1.4–v1.6) and SPDX (v2.2–v3.0) SBOMs, continuous CVE tracking, and Annex I essential requirements verification.
  • Technical Documentation & Conformity: Generates CRA Annex VII technical files and EU Declarations of Conformity for CE marking.
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).
Information about CVD Portal
Listed Since: 08/21/2026

STAR Level 1

Cloud Controls Matrix

CAIQ Self-assessment v4.0.2

Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).

Created or renewed 3 days ago, on August 21, 2026.