CloudSignLab

Help centerRegisters and records

Track and fix vulnerabilities

Record weaknesses in your systems with severity, affected asset and a fix deadline, and follow them until they are fixed.

Updated September 29, 2026

In this section: Registers and records

NIS2 Article 21(2)(e) asks you to handle vulnerabilities in your systems. Vulnerabilities keeps them in one list, with a deadline for each fix.

Who does what

  • Everyone in the organization may report a vulnerability.
  • Owners and admins handle them: they set the status, the deadline and who is responsible.

How to report a vulnerability

  1. Open Vulnerabilities in the organization menu and click Report vulnerability.
  2. Enter a Title and choose the Severity: Low, Medium, High or Critical.
  3. Choose the Affected asset from your asset inventory.
  4. Choose how it was Found by: vulnerability scan, penetration test, vendor advisory, reported by someone, or other.
  5. If known, add the CVE (for example CVE-2026-12345) and the CVSS score.
  6. Enter Discovered on, the Responsible person and a Description.
  7. Save.

Fix deadlines

If you leave Fix by empty, the deadline follows the severity, counted from the discovery date:

  • Critical: 7 days
  • High: 30 days
  • Medium: 90 days
  • Low: 180 days

Overdue vulnerabilities are marked. The responsible person gets one reminder, or the owners and admins if nobody is set.

Status

A vulnerability is Open, Being fixed, Fixed, Risk accepted or False positive. Use Fix or reason for accepting to write what was done. By default the list shows Open and Being fixed vulnerabilities; click Show fixed and closed to see the rest.

The list

The header counts open, overdue and critical vulnerabilities. By default only open ones are shown; click Show fixed and closed to see the rest.

Tips

  • Always write the reason when you accept a risk, and who decided. Auditors will ask.
  • Link vulnerabilities to the right asset, so you see which systems need attention most.
  • Vulnerabilities are included from the Professional package.

Manufacturers of products with digital elements register them with Products (CRA).

See also