
Review your policy
A new multi-agency cybersecurity information sheet urges organizations to establish accessible, inclusive and well-governed coordinated vulnerability disclosure programs.
At a glance
- The guidance was developed by NSA, CISA, JPCERT/CC, the Netherlands' NCSC and other partners.
- Organizations are encouraged to publish a vulnerability disclosure policy and provide a clear public reporting channel.
- The recommendations support broad security-testing scope and the use of trusted intermediaries where appropriate.
- Disclosure programs should be maintained and updated rather than treated as a one-time policy document.
Why this matters
Researchers often find weaknesses before defenders do. A clear reporting path helps organizations receive that signal early, reduces uncertainty for good-faith researchers and improves the chance of coordinated remediation.
A policy without operational ownership can still fail. Intake, triage, legal coordination, engineering response and researcher communication need defined service levels.
Who should act
- Product security and vulnerability disclosure teams
- Legal and risk leaders responsible for researcher engagement
- Public-sector and critical-infrastructure organizations
- Software and service providers without a published reporting route
SecurityTalent action checklist
- Publish a human-readable vulnerability disclosure policy and a monitored reporting channel.
- Define safe-harbor language, eligible systems, testing expectations and prohibited activity with legal review.
- Create triage severity, acknowledgment and status-update targets.
- Connect the intake process to engineering ownership, incident response and customer communication.
- Test the program with a tabletop exercise and review it after material product or organizational changes.
Source and attribution
Primary source: Establishing a Coordinated Vulnerability Disclosure Process
- Publisher
- National Security Agency and partner agencies
- Author / authority
- NSA, CISA, JPCERT/CC, NCSC-NL and partners
- Published
- July 15, 2026
- SecurityTalent review
- July 18, 2026
This is an original SecurityTalent summary and analysis based on the linked primary source. It is not a republication. The source controls if facts, versions or deadlines change after our review.