The organization must verify that the manufacturer has an established and enforced policy for Coordinated Vulnerability Disclosure (CVD).
This policy is essential as it provides a clear and structured process for security researchers and others to report potential vulnerabilities they discover in the manufacturer's products.
To confirm compliance, the organization should request the manufacturer's CVD policy document and check for evidence that it is actively used, such as a public-facing webpage (e.g., a '/security' page) with instructions for reporting vulnerabilities.