Responsible Vulnerability Disclosure Program
20 Jul 2026

Responsible Vulnerability Disclosure Program

Public Cybersecurity Resources

Description

Cyberzaintza’s Responsible Vulnerability Disclosure Program is guided by a disclosure policy aimed at fostering a society that is better protected against cyber threats. The process begins once an incident is confirmed, at which point the affected entities are immediately notified through secure channels so they can take the appropriate measures.

Following that initial notification, a 45-day period is generally established to correct the flaw, which may be extended by an additional 14-day grace period or another estimated period if the impact is critical. Finally, once the problem has been resolved, the information is disclosed jointly, with the option to publicly alert potentially affected individuals should the entity show a lack of interest or fail to act.