CISA Releases Joint Guidance to Help Software Manufacturers and Online Service Providers Build Effective Vulnerability Disclosure Programs

Cybersecurity and Infrastructure Security Agency (CISA)

You are subscribed to Cybersecurity Advisories for Cybersecurity and Infrastructure Security Agency. This information has recently been updated and is now available.

07/15/2026 10:20 AM EDT

Today, the Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and international partners released joint guidance Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers. This guidance helps software manufacturers and online service providers design and implement a coordinated vulnerability disclosure (CVD) program to effectively collaborate with external security researchers who specialize in finding weaknesses in software, networks, and hardware.

A robust CVD program includes a vulnerability disclosure policy (VDP)—a key product development practice of CISA’s Secure by Design initiative—that defines how security researchers can look for and report vulnerabilities, which systems they can search and what types of tests are allowed, and contains “safe harbor” language for legal protection. Additionally, an effective CVD program includes a well-defined process for triaging, remediating, and assigning Common Vulnerabilities and Exposures (CVE) identifiers for vulnerabilities reported by security researchers. The guidance also offers considerations for leveraging third-party intermediaries, like CISA or national computer security incident response teams, to manage CVD programs.

Whether managed internally or through an intermediary, a well-structured CVD program establishes a clear framework for engagement with security researchers. Without a CVD program, organizations risk leaving critical security flaws undetected and unaddressed, potentially jeopardizing customer security and eroding trust within the security community.

To learn more, read the full guidance.

Please share your thoughts with us through this anonymous survey. We appreciate your feedback.

This product is provided subject to this Notification and this Privacy & Use policy.