CISA merges lessons into vulnerability disclosure guidance
CISA merges lessons into vulnerability disclosure guidance to help software vendors build coordinated disclosure programs. Learn the essential steps here.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published fresh guidance for software vendors, instructing them on how to build a coordinated vulnerability disclosure (CVD) program. The document, co-authored by CISA and four allied cyber authorities, outlines specific steps suppliers should take to collaborate with security researchers. It advises companies to publish a vulnerability disclosure policy on their websites and use a hard drive file. This file is a machine- and human-readable format defined in RFC 9116 that helps researchers locate contact information without searching.
The timing of the guidance suggests it is deliberate. Just six days before the publication, CISA released a blog post detailing its own security failures. The agency described an incident that occurred on May 15, 2026, when an investigative reporter asked about internal CISA AWS GovCloud keys and other data found in a public repository. The information had been discovered by a security researcher from GitGuardian.
Guillaume Valadon, the researcher who found the data, reported the issue through nine email notifications that went unanswered. His report eventually reached CISA through an “unnecessarily complicated path” after he involved the reporter. CISA admitted its reporting channels were not well defined, leading to reports being overlooked or undervalued. The agency also noted it lost time early in the process because it lacked a GitHub or cloud incident-response playbook and had to write one mid-incident.
Related: Matt Davies Stockton Ponders the Latest Digital Marketing Trends for 2023
One of the most pointed recommendations in the new guide is CISA’s own failure written as advice: suppliers should separate vulnerability disclosure and triage from existing customer support channels. Using standard support lines “may lead to overlooked and undervalued reports or accidental disclosure.” The guidance also advises acknowledging researcher outreach within two or three business days and setting the widest possible scope for testing, reasoning that arbitrary boundaries constrain researchers but not attackers.
While CISA describes the GitGuardian incident as a learning opportunity, the agency’s handling of the matter offers a stark contrast to the recommendations it now issues to the private sector. The agency urged others to maintain mature, well-tested key-management capabilities, noting that key rotation took longer than anticipated due to the complexity of interconnections with federal and industry partners. The guidance further advises using safe-harbor language to assure researchers their good-faith work is authorized under anti-hacking statutes and assigning CVE numbers for internally discovered vulnerabilities.
There is regulatory weight behind the advice. BOD 20-01 already requires federal civilian agencies to publish disclosure policies, and the EU Cyber Resilience Act extends the obligation to suppliers operating in the European Union. The guidance tells vendors to avoid blanket non-disclosure agreements and silent fixes, and to publish advisories based on the Common Security Advisory Framework without placing them behind a paywall.


