Bug Bounty
A bug bounty pays external researchers for reported vulnerabilities. How programs are structured, what they cost, and why they complement a pentest, not replace it.
Updated This page as Markdown
In short
A bug bounty program is a standing offer by an organisation to pay security researchers for vulnerabilities they find and report in a defined scope under published rules. It runs continuously, pays per valid finding, and attracts many testers with different skills. It needs a mature vulnerability handling process behind it and does not deliver the systematic coverage or the written evidence of a penetration test. Most companies start with a disclosure policy and a pentest, then add a bounty.
What is a bug bounty?
A bug bounty is a program in which an organisation invites security researchers to find vulnerabilities in a defined scope and pays them for valid reports. The program publishes the scope (which domains, apps or products), the rules (what is allowed, what is out of bounds, how to report), the severity scale and the reward table. Researchers test on their own initiative and time; the organisation triages the reports, pays for the ones that are new and valid, fixes them and usually allows publication after the fix.
Programs are public (anyone may participate) or private (invited researchers only), run on platforms such as HackerOne, Bugcrowd, Intigriti or YesWeHack or self-managed, and can be time-boxed as a “live hacking event” or continuous.
Where is it defined?
Bug bounties are a market practice, not a standard. The processes around them are standardised: ISO/IEC 29147 describes vulnerability disclosure, meaning how an organisation receives reports from outside and communicates about them, and ISO/IEC 30111 describes the internal handling process from receipt to remediation. RFC 9116 defines security.txt, the file at /.well-known/security.txt that tells researchers where to report. In the EU, the Cyber Resilience Act requires manufacturers of products with digital elements to have a coordinated vulnerability disclosure policy and handling process (Annex I Part II) and to report actively exploited vulnerabilities (Article 14). None of these require rewards. In Germany, the legal position of researchers depends on the program’s permission, which is why clear rules matter: testing without authorisation can fall under section 202a and following of the Criminal Code.
What it means in practice
A bounty is only as good as the team behind it. Before the first payout you need people who triage reports within days, a way to reproduce and rate them, developers who fix them, and a policy on duplicates, out-of-scope reports and researchers who go too far. Companies that launch a public program without this drown in low-quality reports and burn goodwill with the good researchers.
For product and device makers the scope question is harder than for web companies. Researchers need a device to test, test devices cost money, and findings in firmware often need the vendor’s own tooling to reproduce. Hardware bounties exist, but they are rarer and usually invitation-only. A penetration test with authorised firmware extraction and debug access gets to the same places faster.
We do not run bounty programs and do not participate in them for customers; our tests are commissioned, authorised and scoped. We do help with the two things a bounty needs first: the vulnerability handling process (triage criteria, severity rating with CVSS, fix and disclosure timelines, CRA reporting) and the disclosure policy with its security.txt.
Common misunderstandings
A bug bounty is not free testing. It costs rewards, platform fees and, above all, staff time, and the cost is unpredictable. It is also not a measure of security: a program with few reports can mean a secure target or an unattractive one. And it is not a substitute for a disclosure policy. The policy comes first; the bounty is an optional incentive on top.
FAQ
Frequently asked questions
What does a bug bounty cost?
The payouts depend on severity and on what the program promises. Public programs on the large platforms typically pay from a few hundred euros for low-severity findings to five-figure sums for critical ones in high-value targets, plus the platform fee. The larger cost is internal: triage, duplicates, communication with researchers and fixing what comes in. Budget staff time before budgeting rewards.
Can a bug bounty replace a penetration test?
No. A bounty gives you many eyes over time on externally reachable systems, but no guarantee that anyone looked at a specific component, no report you can hand to an auditor or a customer, and nothing for systems researchers cannot reach: internal networks, ECUs, devices without public interfaces. A pentest gives systematic coverage with written evidence. Companies with both use the pentest for depth and the bounty for the long tail.
Is a bug bounty needed for the Cyber Resilience Act?
No. The CRA requires manufacturers to have a coordinated vulnerability disclosure policy and a vulnerability handling process (Annex I Part II), to provide a contact address for reports and to handle and remediate what comes in. That can be met with a published policy and a security.txt without paying rewards. A bounty is one way to encourage reports, not a legal requirement.
Sources
- ISO/IEC 29147:2018 Information technology, Security techniques, Vulnerability disclosure
- ISO/IEC 30111:2019 Information technology, Security techniques, Vulnerability handling processes
- EUR-Lex: Regulation (EU) 2024/2847 (Cyber Resilience Act), Annex I Part II vulnerability handling
- IETF RFC 9116: A File Format to Aid in Security Vulnerability Disclosure (security.txt)
Related pages
- GlossaryResponsible DisclosureResponsible or coordinated vulnerability disclosure (CVD): reporting a vulnerability to the vendor and fixing it before publication. Rules, deadlines and the law.
- GlossaryPenetration testA penetration test is an authorised, mostly manual attack on a system to find and prove exploitable vulnerabilities. Definition, types, process and the report.
- ComparisonsPenetration Test vs Bug Bounty: Paid Days or Paid Findings?A pentest buys tester time with a fixed scope and a full report. A bug bounty pays independent researchers per valid finding, with no end date. When each pays off.
- InsightsIs a Penetration Test Legal in Germany? § 202c ExplainedPenetration testing is legal in Germany with written authorisation. What the Hackerparagraf (§ 202c StGB) says, why permission matters, and the planned reform.
- ServicesWe break in. You get the proof and the fix.Hands-on penetration testing by OSCP-certified engineers: IoT devices, ECUs, industrial systems, web, cloud and networks. Fixed-price offer after a 15-min call.
