# CISA and NSA Release Joint Guidance on Building Better Vulnerability Disclosure Programs
## The Threat
For decades, the traditional vulnerability disclosure process has operated as an adversarial dance between security researchers and software vendors. Researchers discover flaws; vendors dismiss them, delay fixes, or worse—threaten legal action. Meanwhile, threat actors harvest unpatched vulnerabilities for exploitation while customers remain exposed.
Coordinated Vulnerability Disclosure (CVD) flips this dynamic. Rather than dumping findings on the dark web or waiting for public exploit code to force vendor action, researchers report vulnerabilities through established channels, giving manufacturers time to develop and deploy patches before widespread attacks occur. The catch: CVD only works when vendors have clear policies, transparent processes, and demonstrate genuine commitment to fixing reported issues.
In a new joint advisory, the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and international partners have formalized what industry best practices should look like. This guidance isn't just another whitepaper gathering dust on a security blog—it's a roadmap for eliminating the chaos that turns every vulnerability into a potential crisis.
## Severity and Impact
| Aspect | Details |
|--------|---------|
| Guidance Type | Best practices for Coordinated Vulnerability Disclosure programs |
| Issuing Authorities | CISA, NSA, and international partners |
| Scope | All software manufacturers and online service providers |
| Key Focus | Policy design, triage processes, remediation workflows, CVE assignment, third-party coordination |
| Applicability | Critical infrastructure, commercial software, SaaS platforms, cloud providers |
| Risk of Non-Compliance | Delayed vulnerability patching, increased exploit prevalence, damaged researcher relationships, regulatory exposure |
## Affected Products
This guidance applies to organizations across all sectors:
## Mitigations
Organizations should immediately evaluate and strengthen their vulnerability disclosure programs using this guidance:
Policy and Process Design
Triage and Remediation
Researcher Relations
Third-Party Coordination
International Collaboration
## References
---
## HackWire Analysis
The timing of this guidance is no accident. Over the past three years, the security community has watched coordinated disclosure collapse into chaos. Major vendors have sued researchers for responsible reporting. Zero-day exploits have sold for millions on the dark market while patches languished. High-profile breaches have involved vulnerabilities that were disclosed months or years earlier but never actually fixed—not because patches were unavailable, but because vendors couldn't be bothered.
What CISA and NSA are signaling here is that the era of vendors treating researchers as nuisances is over. By codifying best practices at the federal level, they're creating accountability. Organizations that ignore this guidance risk regulatory scrutiny, reputational damage, and justified skepticism from the security research community that increasingly sees itself as having alternatives—public disclosure, exploit sales, or simply moving on to vendors who appreciate their work.
The guidance also addresses the intermediary problem. For years, researchers have struggled with vendors that don't respond, disappear after initial contact, or sit on patches indefinitely. By formalizing the role of CISA and international CERTs as mediators, the guidance creates an escalation path that doesn't require going public or selling to threat actors. This is critical infrastructure protection by other means.
The hard truth: most organizations will ignore this. Smaller vendors will claim they lack resources. Enterprise teams will deprioritize it. But the best-in-class organizations—the ones that actually care about security—will use this as their blueprint. And in a competitive market where security matters, that distinction will show.
For security teams, this is your playbook. For researchers, it's institutional backing for what you've been asking for. For vendors resisting transparency: the pressure just got official.
— HackWire Editorial
---
## Related Coverage