How do I triage a vulnerability report?
Open the report in Submissions, acknowledge it first, then score it with the CVSS calculator and record a report classification. Acknowledge first because the acknowledgment clock is what the SLA measures, and a breached acknowledgment is visible evidence of a process that is not working.
Key takeaways
- Acknowledge first, investigate second.
- Score severity with the built-in CVSS calculator.
- The report classification sets whether Article 14 obligations apply.
- Every action is written to the append-only audit log.
Steps
- Open Submissions and select the report.
- Select Acknowledge report.
- Set CVSS Severity with the calculator.
- Set the Report Classification, for example an actively exploited vulnerability.
- Select Apply to Submission to record the assessment.
Related
- Full procedure: SOP-05, Triaging a Vulnerability Report
- Reference: Risk assessment
Last updated 17 September 2026.