# CISA and NSA Release Joint Guidance on Building Better Vulnerability Disclosure Programs


## The Threat


For decades, the traditional vulnerability disclosure process has operated as an adversarial dance between security researchers and software vendors. Researchers discover flaws; vendors dismiss them, delay fixes, or worse—threaten legal action. Meanwhile, threat actors harvest unpatched vulnerabilities for exploitation while customers remain exposed.


Coordinated Vulnerability Disclosure (CVD) flips this dynamic. Rather than dumping findings on the dark web or waiting for public exploit code to force vendor action, researchers report vulnerabilities through established channels, giving manufacturers time to develop and deploy patches before widespread attacks occur. The catch: CVD only works when vendors have clear policies, transparent processes, and demonstrate genuine commitment to fixing reported issues.


In a new joint advisory, the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and international partners have formalized what industry best practices should look like. This guidance isn't just another whitepaper gathering dust on a security blog—it's a roadmap for eliminating the chaos that turns every vulnerability into a potential crisis.


## Severity and Impact


| Aspect | Details |

|--------|---------|

| Guidance Type | Best practices for Coordinated Vulnerability Disclosure programs |

| Issuing Authorities | CISA, NSA, and international partners |

| Scope | All software manufacturers and online service providers |

| Key Focus | Policy design, triage processes, remediation workflows, CVE assignment, third-party coordination |

| Applicability | Critical infrastructure, commercial software, SaaS platforms, cloud providers |

| Risk of Non-Compliance | Delayed vulnerability patching, increased exploit prevalence, damaged researcher relationships, regulatory exposure |


## Affected Products


This guidance applies to organizations across all sectors:


  • Software manufacturers — including operating system vendors, enterprise applications, security tools, and productivity suites
  • Online service providers — SaaS platforms, cloud infrastructure providers, content delivery networks, hosting services
  • Critical infrastructure operators — energy, water, transportation, healthcare, and communications sectors
  • Government and defense contractors — agencies and vendors handling sensitive systems
  • IoT and embedded device manufacturers — firmware vendors and device security teams
  • Open-source projects — maintainers of widely-used libraries and frameworks

  • ## Mitigations


    Organizations should immediately evaluate and strengthen their vulnerability disclosure programs using this guidance:


    Policy and Process Design

  • Publish a clear, findable vulnerability disclosure policy that explains how researchers should report issues
  • Define specific communication channels (security.txt, dedicated email addresses, bug bounty platforms)
  • Establish clear timelines for acknowledgment, triage, and status updates
  • Document the process for assigning CVE identifiers for reported vulnerabilities

  • Triage and Remediation

  • Create a cross-functional triage team that evaluates reported vulnerabilities within days, not weeks
  • Prioritize fixes based on actual severity and exploitation likelihood, not reporter persistence
  • Provide transparent status updates at regular intervals, even if the vulnerability is still under investigation
  • Develop realistic patch timelines that account for the complexity of affected systems

  • Researcher Relations

  • Treat security researchers as partners in improving security, not adversaries or threats
  • Avoid retaliatory actions, legal threats, or intimidation tactics that discourage reporting
  • Consider implementing bug bounty programs that compensate researchers for valid findings
  • Recognize the work of researchers in security advisories and patch release notes

  • Third-Party Coordination

  • Leverage intermediaries like CISA or national incident response teams (CERTs) to facilitate disclosure when direct communication fails
  • Use these channels to coordinate multi-vendor disclosures and manage embargo periods
  • Establish relationships with industry-specific ISACs (Information Sharing and Analysis Centers)

  • International Collaboration

  • Recognize that vulnerabilities in global products require coordination across borders
  • Work with international partners to align disclosure practices and timelines
  • Follow established norms for handling vulnerabilities reported across different jurisdictions

  • ## References


  • CISA Guidance: [Coordinated Vulnerability Disclosure Best Practices](https://www.cisa.gov/) (CISA official advisory)
  • NSA Cybersecurity Collaboration Center: [NSA Cybersecurity Resources](https://www.nsa.gov/cybersecurity/) (U.S. National Security Agency resources)
  • Original Announcement: Coordinated Vulnerability Disclosure Program guidance from CISA, NSA, and international partners
  • CVE Program Details: [Common Vulnerabilities and Exposures (CVE)](https://www.cve.org/) (CVE identifier system)

  • ---


    ## HackWire Analysis


    The timing of this guidance is no accident. Over the past three years, the security community has watched coordinated disclosure collapse into chaos. Major vendors have sued researchers for responsible reporting. Zero-day exploits have sold for millions on the dark market while patches languished. High-profile breaches have involved vulnerabilities that were disclosed months or years earlier but never actually fixed—not because patches were unavailable, but because vendors couldn't be bothered.


    What CISA and NSA are signaling here is that the era of vendors treating researchers as nuisances is over. By codifying best practices at the federal level, they're creating accountability. Organizations that ignore this guidance risk regulatory scrutiny, reputational damage, and justified skepticism from the security research community that increasingly sees itself as having alternatives—public disclosure, exploit sales, or simply moving on to vendors who appreciate their work.


    The guidance also addresses the intermediary problem. For years, researchers have struggled with vendors that don't respond, disappear after initial contact, or sit on patches indefinitely. By formalizing the role of CISA and international CERTs as mediators, the guidance creates an escalation path that doesn't require going public or selling to threat actors. This is critical infrastructure protection by other means.


    The hard truth: most organizations will ignore this. Smaller vendors will claim they lack resources. Enterprise teams will deprioritize it. But the best-in-class organizations—the ones that actually care about security—will use this as their blueprint. And in a competitive market where security matters, that distinction will show.


    For security teams, this is your playbook. For researchers, it's institutional backing for what you've been asking for. For vendors resisting transparency: the pressure just got official.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)