AVT Audio Video Technologies GmbH
Nordostpark 91
90411 Nürnberg
Germany

Cyber Resilience Act (Regulation (EU) 2024/2847)

Coordinated Vulnerability Disclosure Policy

AVT Audio Video Technologies GmbH

PublisherAVT Audio Video Technologies GmbH, Nürnberg, Germany
Applies toAll AVT products with digital elements
Legal basisAnnex I Part II(5); Article 13. Structure per BSI TR-03183-3 v1.0.0
Document referenceAVT-CRA-CVD-006
Version / date1.0 / 04-09-2026 — reviewed at least annually
Corresponding national CSIRTCERT-Bund (operated by the BSI), Germany

Note: This is a company-wide process document (not per product). It is published on the AVT website and referenced from each product's technical documentation.

1  Scope and commitment

AVT welcomes reports of potential security vulnerabilities in its products and services. This policy sets out how to report a vulnerability, what reporters can expect, and how AVT coordinates disclosure. In scope are cybersecurity vulnerabilities that, upon exploitation, negatively affect the confidentiality, integrity, availability, authenticity, non-repudiation or reliability of a product or component.

2  How to report

3  Assurances to reporters

4  Guaranteed response times

StageTarget
Simple, non-automated acknowledgement of receiptWithin 5 working days
Detailed feedback / initial assessmentWithin 10 working days
Public disclosure after a fix/mitigation Within 90 days (extendable once by a further 90 days in consultation with CERT-Bund; further extension only by the CSIRT on request)

5  Coordination and public disclosure

6  Statutory reporting under Article 14 (from 11 September 2026)

For actively exploited vulnerabilities and severe incidents affecting AVT products, AVT notifies the corresponding national CSIRT and ENISA simultaneously via the single reporting platform (Article 16), on the following timeline:

StageActively exploited vulnerabilitySevere incident
Early warning Within 24 h of awareness; indicate affected Member States where known Within 24 h; state if suspected unlawful/malicious; affected Member States
Notification Within 72 h; product info, nature of the vulnerability/exploit, corrective/mitigating actions, user guidance Within 72 h; equivalent detail
Final report Within 14 days after a corrective/mitigating measure is available Within 1 month after the incident notification

Voluntary reports of other vulnerabilities, threats, incidents or near-misses may also be made to the CSIRT or ENISA (Article 15).

7  End of the CVD process

AVT considers the process complete when: the report is found unfounded; the vulnerability has been mitigated/fixed by an appropriate patch and publicly disclosed; a service vulnerability is fixed and disclosed; the reporter fails to respond to queries for at least 30 days; or, in consultation with CERT-Bund, it can no longer be assumed the vulnerability will be fixed. The reporter is informed without undue delay (unless the report was anonymous).