STAR Registry Listing for
CVD Portal
CVD Portal
CVD Portal is a multi-tenant SaaS compliance and coordinated vulnerability disclosure platform for manufacturers selling products with digital elements into the European Union under the EU Cyber Resilience Act (Regulation (EU) 2024/2847).
Core Capabilities- Coordinated Vulnerability Disclosure (CVD): Provides RFC 9116 security.txt generation and hosting, whitelabel HTTPS researcher intake portals, and 48-hour acknowledgment SLA tracking aligned with ISO/IEC 29147.
- Statutory Authority Reporting (Article 14): Automates mandatory CRA reporting workflows, preparing ready-to-file packages for 24-hour early warnings, 72-hour notifications, and 14-day final reports for national CSIRTs and the ENISA Single Reporting Platform (SRP).
- Vulnerability Triage & Security Advisories: Implements CVSS v3.1 and CVSS v4.0 scoring engines, CISA KEV exploitation correlation, PGP-encrypted researcher communications, and automated CSAF 2.0 (Common Security Advisory Framework) JSON advisory publishing.
- Software Supply Chain & SBOM Management: Built-in in-house conformance engine for CycloneDX (v1.4–v1.6) and SPDX (v2.2–v3.0) SBOMs, continuous CVE tracking, and Annex I essential requirements verification.
- Technical Documentation & Conformity: Generates CRA Annex VII technical files and EU Declarations of Conformity for CE marking.

Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).
Information about CVD Portal
Listed Since: 08/21/2026
Listed Since: 08/21/2026
STAR Level 1
Cloud Controls Matrix

CAIQ Self-assessment v4.0.2
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).
Created or renewed 3 days ago, on August 21, 2026.