CVD Portal integration (retired handoff)
This page described the Vulnerability Disclosure page in the standalone PortaRegulus CRA app, which registered products with CVD Portal and signed you in through a handoff. That app has been retired and its address redirects to https://cvdportal.com/cra.
There is no handoff any more. Coordinated vulnerability disclosure and CRA compliance are one product, reached with one sign-in at https://cvdportal.com. Registering a product with CVD Portal, opening it in a second tab and re-registering after a rename are all obsolete steps.
What replaces it
- Your CVD policy sets up the public disclosure portal that satisfies CRA Annex I Part II point 5.
- Products, the CRA compliance workspace holds the compliance work for each product. Vulnerability reports filed against a product feed its monitoring review triggers directly.
- Submission lifecycle covers what happens to a report after a researcher files it.
- Article 14 reporting covers reporting an actively exploited vulnerability to ENISA.
If you still use the shared integration workspace
Accounts created through the old sign-in handoff landed in a shared read-only workspace, which still holds the products and reports from that integration. CRA Compliance Tool integration explains how it behaves and where to find those reports.