Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The UK National Cyber Security Centre (NCSC) recommends starting with three essentials: a discoverable, secure reporting channel; a clear policy that sets expectations and testing boundaries; and a security.txt file that points researchers to the right contact and policy. The process must also assign responsibility for acknowledging reports, triaging them and communicating through remediation.

What the NCSC guide covers

The NCSC’s Vulnerability Disclosure Toolkit is a starter guide for organisations of all sizes, not a comprehensive vulnerability-management manual. It was published on 14 September 2020 and reviewed on 7 November 2024. The NCSC’s vulnerability-management collection, published on 28 November 2024, reviewed on 1 May 2026 and marked version 2.1, lists it under “Vulnerability reporting & disclosure.”

The NCSC summarises the aim this way: “A vulnerability disclosure process should: enable the reporting of found vulnerabilities; be clear, simple, and secure; define how the organisation will respond.”

How to set up the process

1. Provide a discoverable reporting channel

Set up a dedicated email address or contact form for vulnerability reports. A secure web form is preferable where practical. Make the route easy to find on the organisation’s website, rather than leaving researchers to guess which general support or sales address to use.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Publish a policy

Explain how to contact the organisation, which secure communication options are available, what information a report should include, what the finder can expect after submitting it, and which systems and testing activities are in or out of scope. The policy should make the route and boundaries understandable before someone begins testing.

3. Add a security.txt file

Publish an IETF security.txt file at /.well-known/security.txt. The NCSC toolkit identifies CONTACT, POLICY and EXPIRES as fields to include; ENCRYPTION is optional. The file advertises the reporting route and policy at a standard location, so keep its contact and policy details current.

What a vulnerability disclosure policy should say

A useful policy answers four practical questions:

  • Where should I report? Give the dedicated email address or form and explain any secure reporting option.
  • What should my report contain? Ask for enough information to locate and understand the issue, including affected assets and safe reproduction steps.
  • What happens next? Describe acknowledgement, triage, progress updates and how the organisation will notify the finder when the issue is fixed.
  • What testing is permitted? Specify in-scope systems and prohibited or out-of-scope activity.

The GOV.UK vulnerability disclosure policy example asks reporters to identify the affected website, IP address or page, provide a short description, and give benign, non-destructive reproduction steps. These details help an organisation investigate without requiring the finder to access more data or cause disruption.

Set safe testing boundaries

Define limits clearly. The GOV.UK example prohibits breaking the law; accessing unnecessary or excessive data; modifying data; high-intensity, invasive or destructive scanning; denial-of-service activity; and disruptive testing. A policy should direct researchers toward demonstrating the minimum necessary to explain an issue, not expanding access or impact.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Organisations should also identify which products or services are in scope and name exclusions. Clear scope helps a finder decide whether a report belongs with the organisation and gives internal responders a basis for routing it to the right owner.

What to do when a report arrives

  1. Acknowledge promptly and thank the finder. Confirm that the report has reached the organisation and that it is being handled.
  2. Route it to the responsible product or service owner. Make ownership and escalation clear internally so the report does not stall in a general inbox.
  3. Ask politely for missing details. Request only information needed to assess or reproduce the issue safely.
  4. Keep the finder informed. If remediation takes time, provide periodic updates rather than leaving the reporter uncertain about the status.
  5. Notify the finder when the issue is fixed. Consider publicly acknowledging the person who reported it, where appropriate.

The NCSC toolkit advises against requiring the finder to sign a non-disclosure agreement as a condition of reporting. The organisation should set expectations for communication and disclosure in its policy instead.

Make response targets explicit

The GOV.UK example says the organisation will respond within 5 working days and aims to triage within 10 working days. These are the example policy’s targets, not a universal deadline imposed by the NCSC. An organisation should publish service levels it can meet, distinguish an initial response from triage and remediation, and explain how it will communicate if a fix takes longer. The example says remediation priority considers impact, severity and exploit complexity.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Standards and further guidance

The NCSC toolkit points to ISO/IEC 29147:2018, International standard for vulnerability disclosure, and ETSI TR 103 838, Guide to coordinated vulnerability disclosure, as useful references for organisations seeking standards-oriented detail.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The GOV.UK Software Security Code of Practice defines a vulnerability disclosure process as “A process whereby individuals can, safely and accessibly, report vulnerabilities to the organisation.” It also says the process should be supported by a policy that details how reports are handled internally.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.