Coordinated Vulnerability Disclosure Policy (CVD)
1. Purpose and Scope
ETA a.s. (hereinafter referred to as "ETA") hereby establishes a Coordinated Vulnerability Disclosure (CVD) policy in accordance with Regulation (EU) 2024/2847 on Cyber Resilience (CRA).
The policy applies to all ETA products with digital elements placed on the market in the European Economic Area, including their firmware, accompanying mobile applications, and connected cloud services. The policy applies for the entire support period of each product, but for at least 5 years from placing on the market.
2. Contact Channel for Vulnerability Reporting
Vulnerabilities in ETA products can be reported through the following channels:
| Channel | Address |
|---|---|
| psirt@eta.cz | |
| Web | https://www.etasince1943.com/product-security/ |
| security.txt (RFC 9116) | https://www.eta.cz/.well-known/security.txt |
We accept reports in Czech, Slovak, and English. Anonymous reports are also possible.
2.1 What to Include in a Report
For quick assessment, please provide:
- name and version of the affected product or firmware,
- description of the vulnerability and its potential impact,
- steps to reproduce, if possible,
- contact information or a request to remain anonymous.
3. Deadlines for Report Processing
| Activity | Deadline |
|---|---|
| Confirmation of report receipt | within 3 business days |
| First substantive response (triage) | within 10 business days |
| Regular status update | at least once every 14 days |
| Remediation — critical vulnerability (CVSS 9.0–10.0) | within 7 calendar days |
| Remediation — high vulnerability (CVSS 7.0–8.9) | within 30 calendar days |
| Remediation — medium vulnerability (CVSS 4.0–6.9) | within 90 calendar days |
| Remediation — low vulnerability (CVSS 0.1–3.9) | within 180 calendar days |
Deadlines may be reasonably extended if coordination with a third-party supplier is necessary. ETA shall inform the finder thereof without undue delay.
4. Report Processing Procedure
| Step | Description |
|---|---|
| 1 — Receipt | The report is registered, a tracking number is assigned to the finder, and receipt is acknowledged within 3 business days. |
| 2 — Triage | The PSIRT team verifies reproducibility, determines severity (CVSS), and identifies affected products and versions. |
| 3 — Remediation | The responsible development team drafts a patch or mitigation within the stipulated deadlines. |
| 4 — Testing | The patch undergoes security testing and verification. |
| 5 — Update Release | The fix is released and distributed to users via standard update channels. |
| 6 — Publication | ETA publishes a security advisory containing the description of the vulnerability, CVSS score, and guidance for users. |
5. Coordinated Disclosure
Information about a vulnerability is published after the release of a patch or effective mitigation. ETA coordinates the publication date with the finder; the standard embargo is 90 days from the confirmation of the report.
5.1 Security Advisory Content
Each security advisory contains:
- CVE identifier and CVSS v3.1 severity rating,
- affected products and versions,
- description of the vulnerability and exploitation conditions,
- remediation instructions or recommended actions,
- machine-readable version in CSAF 2.0 format.
5.2 Publication Channels
- https://www.etasince1943.com/product-security/,
- e-mail notification of registered users and business partners,
- coordinated notification with CSIRT.CZ and ENISA.
6. Reporting Obligations
Upon detecting an actively exploited vulnerability or a severe security incident, ETA is obliged, starting from September 11, 2026, to report this fact to ENISA and the national CSIRT.CZ via the EU Single Reporting Platform:
For the purposes of this article, a severe security incident means an incident that (a) negatively affects the product's ability to protect the availability, authenticity, integrity, or confidentiality of data or functions, OR (b) has led or may lead to the introduction of malicious code into the product or the user's network.
| Event Type | Early warning | Initial notification | Final report |
|---|---|---|---|
| Actively exploited vulnerability | 24 hours | 72 hours | 14 days from patch availability |
| Severe security incident | 24 hours | 72 hours | 30 days from initial notification |
The deadlines for early warning and initial notification start from the moment ETA detects active exploitation or a severe incident — not from the moment the report is received from the finder. The deadline for the final report of an actively exploited vulnerability runs from the moment a corrective or mitigating measure is available. The deadline for the final report of a severe incident runs from the moment the initial notification is sent.
7. SBOM and Third-Party Component Management
ETA compiles and maintains a Software Bill of Materials (SBOM) for each product with digital elements. The SBOM is prepared in a machine-readable format (SPDX or CycloneDX) and contains at least the most critical product dependencies. The SBOM is updated with each release of a new version and is made available to market surveillance authorities upon request.
If third-party components (libraries, chipset firmware, SDKs) are included in an ETA product, ETA monitors security advisories from the respective suppliers and addresses vulnerabilities in such components in accordance with the deadlines set out in Section 3 of this policy. Upon detecting a vulnerability in a third-party component, ETA shall promptly inform the relevant supplier and coordinate remediation.