Article · July 23, 2026

CISA's Coordinated Vulnerability Disclosure Guidance: A Look at What's New

CISA's new joint guidance on coordinated vulnerability disclosure updates the playbook in welcome ways. What's new, what it leaves out for safety-critical systems, and what medical device makers should draw from.

CISA has published new guidance on how to build a coordinated vulnerability disclosure (CVD) program: Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers. It’s a joint publication with the NSA, Japan’s JPCERT/CC, the Netherlands’ NCSC-NL, and the UK’s NCSC. Reading it alongside the 2016 NTIA guidance is a useful exercise: there’s a lot to like, some genuinely helpful updates, and a couple of areas where the earlier work still has something to offer.

A quick note on that earlier work, since it doesn’t come up in the new document. The NTIA multistakeholder process, led by Allan Friedman, PhD, produced resources that remain excellent references — I still turn to them regularly, particularly the early-stage template, which lays out how to stand up a program and mature it over time. A large group of people put real effort into it, including Joshua Corman, Amanda Craig Deckard, Bruce Lowenthal, Tara Hairston, Graham Watson, Jessica Wilkerson, Steve Christey Coley, Penny Chase, Art Manion, Katie Moussouris, Chris Wysopal, Kymberlee Price, Jennings Aske, Jen Ellis, Jim Jacobson, and many others. It’s worth knowing that history exists, since it offers additional resources and perspectives that didn’t fit into the new document.

What the new guidance gets right

The core of the CISA document looks solid and familiar. The sections and criteria for what belongs in a program are broadly consistent with the earlier work and remain aligned with the CERT Guide to Coordinated Vulnerability Disclosure and the ISO/IEC playbooks. The safe harbor language carries forward from the NTIA work, as well as the work of those like Casey John Ellis through disclose.io.

There are also sensible updates for practices that either didn’t exist or weren’t well established in 2016:

  • CVE assignment. Recommending that companies assign CVEs should help strengthen the CVE program overall, which in turn makes efforts like the Known Exploited Vulnerabilities list and SBOM more useful.
  • security.txt. This makes programs clearer and easier for researchers to find.
  • SSVC prioritization. Pointing to SSVC for prioritization is a good step.

What the earlier work still offers

Two areas from the earlier NTIA work seem worth revisiting.

The first is safety-critical systems. The 2016 effort included a working group focused specifically on safety-critical disclosure, because these systems carry additional and adapted considerations. The FDA, medical device makers, and healthcare providers all participated, and that work helped inform the FDA’s premarket and postmarket guidance on medical device cybersecurity. The 6 Differences in IoT and Cyber Safety framework from I Am The Cavalry — a grassroots initiative I help lead — distills why: consequences can include direct physical harm, the adversaries and their motivations differ, device composition and economics constrain what defenders can do, the operational context is unusual, and timescales stretch across decades. Given the range of organizations behind the new guidance, this feels like material that could add value if folded in, especially as vulnerabilities in supply chains for safety-critical sectors are increasingly prevalent.

The second area is multi-party disclosure, which the new guidance touches on only briefly. It does reference FIRST’s Guidelines and Practices for Multi-Party Vulnerability Coordination and Disclosure, which is the right pointer, but there’s room to say more about how to actually build these situations into a program as supply chain complexity grows and as vulnerability research becomes accessible to more researchers through large language models (LLMs) like Mythos, ChatGPT 4.6 Sol, and others.

Building for the future, preserving what we’ve learned

This exercise highlights how easily our field loses its own institutional memory. A great deal of the reasoning behind past decisions gets overwritten or simply forgotten because we don’t consistently prioritize continuity.

A concrete example: when the FDA was drafting its postmarket guidance in 2016, there was extensive debate about whether the proposed disclosure timelines were too short (because updates need to be rigorously tested) or too long (because the consequences to patients and the public health system may be so severe). Decisions were made and written into the guidance, but as far as I’m aware the reasoning behind them wasn’t preserved. That kind of context is exactly what the next generation of practitioners could benefit from, and it’s what Seth Carmody of MedCrypt and I tried to capture in our recent live stream, Behind the FDA Cybersecurity Guidance (LinkedIn or YouTube).

The new guidance is a real contribution and updates the older material in meaningful ways. There are also some great resources in the older work from the original NTIA page and disclose.io that are worth drawing from when developing or revisiting your coordinated vulnerability disclosure program.

Get in touch

Working through the same questions on your device or program?