Skip to main content

How do I triage a vulnerability report?

Open the report in Submissions, acknowledge it first, then score it with the CVSS calculator and record a report classification. Acknowledge first because the acknowledgment clock is what the SLA measures, and a breached acknowledgment is visible evidence of a process that is not working.

Key takeaways

  • Acknowledge first, investigate second.
  • Score severity with the built-in CVSS calculator.
  • The report classification sets whether Article 14 obligations apply.
  • Every action is written to the append-only audit log.
Silent walkthrough. Follow the numbered steps below for the full text.

Steps

  1. Open Submissions and select the report.
  2. Select Acknowledge report.
  3. Set CVSS Severity with the calculator.
  4. Set the Report Classification, for example an actively exploited vulnerability.
  5. Select Apply to Submission to record the assessment.

Last updated 17 September 2026.