CISA and Partners Publish Guidance to Help Software Manufacturers and Online Service Providers Work With Security Researchers
CISA and international partners released guidance to help software makers and online services collaborate with security researchers through structured vulnerability disclosure programs.
The Cybersecurity and Infrastructure Security Agency (CISA), along with the NSA, JPCERT/CC, NCSC-NL, and NCSC-UK, published a guide titled *Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers*. The document provides a framework for software manufacturers and online service providers to systematically engage with security researchers who identify vulnerabilities in their products or systems. The guidance emphasizes structured reporting processes to assess risks, improve vulnerability management, and enhance product security for customers.
Acting Executive Assistant Director for Cybersecurity Chris Butera stated that coordinated vulnerability disclosure is essential for a secure software ecosystem. The guidance aligns with CISA’s *Secure by Design* initiative, which promotes transparency and accountability in technology development and maintenance. CISA encourages suppliers to adopt these practices to foster constructive relationships with researchers and strengthen overall product security.
Security researchers play a critical role in identifying vulnerabilities before they can be exploited maliciously. However, they require a clear and safe process to report findings. The guidance outlines best practices for establishing a CVD program, including defining public policies that detail reporting procedures, permitted testing methods, and expected timelines for updates and resolutions. Transparency throughout the process is emphasized to build trust between researchers and organizations.
The document is part of CISA’s broader mission as the nation’s cyber defense agency, focusing on reducing risks to digital and physical infrastructure. Organizations are directed to CISA.gov for additional resources and implementation details. The guidance reflects a collaborative effort among international partners to promote safer and more secure technology ecosystems.