Skip to content

All Users

amanion-cisa edited this page Sep 17, 2026 · 17 revisions

This page documents general tasks for all users, primarily account creation and management.

1. Terms and Conditions

Use of VINCE-NT is subject to Terms and Conditions. Your authentication provider may enforce additional Terms of Use.

2. Access VINCE-NT

To access VINCE-NT visit https://vulnerabilities.cisa.gov/.

3. Register a New Account

It is possible to submit a vulnerability report without creating an account or logging in. To submit a report as a registered user or for all other purposes, you will need to create an account. There are two options to create an account.

  1. Most users should follow the instructions for Self-service.

  2. If you are a U.S. government employee or partner with a CAC or PIV card, see CAC or PIV card holder.

3.1 Self-service

Create an account through the CISA Registration Portal (which uses Okta as the authentication provider).

  1. Visit https://vulnerabilities.cisa.gov/.

  2. Select [Log in or sign up]

  3. Do not enter a [Username], do not select [Next], do not select [Sign in with PIV / CAC card].

  4. Select [New user registration] at the bottom of the screen. You may need to scroll down.

  5. If you are notified about the Privacy Policy, select [I Agree].

  6. Enter an [Email] address and select [Continue].

  7. You should receive a verification code via email. Enter the Verification Code and select [Verify Code].

  8. Select [VINCE-NT] from the [Application] drop-down menu then select [Next].

  9. Optionally enter [Organization] and [Sub-organization] then select [Continue]. These fields are informational and do not, for example, specify Supplier Group names.

  10. Enter [First Name], [Last Name], and [VINCE-NT screen name]. This information will be used to identify you in VINCE-NT. You are not required to use your real names. Select [Submit request].

  11. You should see a screen noting [Request Received] and that your request for VINCE-NT access has been granted.

  12. You should receive email (from noreply_acess@cisa.dhs.gov) with instructions to activate your account. Select [Activate Okta Account] from the email message, or copy the link and paste it into a web browser.

  13. You should see a screen requiring you [Set up security methods]. Under [Required now] select [Set up] to choose a [Password] for your account.

  14. Noting the password length and complexity requirements, enter a password in the [Enter password] and [Re-enter password] fields. Then select [Next].

  15. You must select at least one additional security method. Select [Set up] for one of:

  16. [Google Authenticator]

    1. Scan the QR code with Google Authenticator then select [Next].

    2. [Enter code] and select [Verify].

  17. [Okta Verify]

    1. Scan the QR code with your mobile device (using either your camera app or Okta Verify). Follow the instruction in Okta Verify.
  18. [Security Key or Biometric Authenticator]

    1. Follow the instructions to set up this security method.
  19. You may optionally [Set up] additional security methods. When you are done setting up additional security methods, select [Continue].

  20. You should see the CISA ICAM screen including a [VINCE-NT] icon under [My Apps]. Select the [VINCE-NT] icon.

    1. Alternatively, access https://vulnerabilities.cisa.gov/ in a web browser.
  21. Select [Log in or sign up].

  22. You should now be logged in to VINCE-NT. If your previous session timed out, you will need to [Log in to VINCE-NT].

  23. When you first log in, you will be presented with the VINCE-NT Terms and Conditions. Scroll through the text and select [I Accept] to continue to use VINCE-NT.

  24. You will be presented with VINCE-NT Terms and Conditions again when they change.

  25. [Dashboard] is selected. You may see one or more Groups you can [Request to join].

3.2 CAC or PIV Card Holder

If you are a U.S. government employee or partner with a CAC or PIV card:

  1. Visit https://vulnerabilities.cisa.gov/.

  2. Select [Log in or sign up].

  3. Do not enter a [Username], do not select [Next], do not select [Sign in with PIV / CAC card].

  4. Select [New user registration] at the bottom of the screen. You may need to scroll down.

  5. If you are notified about the Privacy Policy, select [I Agree].

  6. Enter the email address associated with your PIV or CAC card and select [Continue].

  7. On the CISA ICAM Login [Sign In] screen, you should see the email address you previously entered in the [Username] field. Select [Sign in with PIV / CAC card].

  8. If prompted, select a certificate.

  9. If prompted, enter your PIN.

  10. Select [VINCE-NT] from the [Application] drop-down menu then select [Next].

  11. On the CISA Registration Portal page, Select [Continue >].

  12. Your [Organization] and [Sub-organization] are filled in based on your certificate. Select [Continue >].

  13. Enter a [VINCE-NT screen name] and select [Submit request].

  14. You should see a screen noting [Request Received] and that your request for VINCE-NT access has been granted. Select [Sign in to your CISA Application >].

  15. You should see the CISA ICAM screen including a [VINCE-NT] icon under [My Apps]. Select the [VINCE-NT] icon.

    1. Alternatively, access https://vulnerabilities.cisa.gov/ in a web browser.
  16. Select [Log in or sign up].

  17. You should now be logged in to VINCE-NT. If your previous session timed out, you will need to [Log in to VINCE-NT].

  18. When you first log in, you will be presented with the VINCE-NT Terms and Conditions. Scroll through the text and select [I Accept] to continue to use VINCE-NT.

  19. You will be presented with VINCE-NT Terms and Conditions again when they change.

  20. [Dashboard] is selected. You may see one or more Groups you can [Request to join].

4. Log in to VINCE-NT

After creating an account you can log in to VINCE-NT.

4.1 Self-service

  1. Visit https://vulnerabilities.cisa.gov/.

  2. If you have a current valid authentication provider session, you will be logged in automatically.

  3. If you are not logged in automatically, select [Log in or sign up].

  4. You may need to enter your email address and select [Next].

  5. You may also need to select either an MFA method, password, or both, and follow the prompts.

  6. You should now be logged in to VINCE-NT.

4.2 CAC or PIV Card Holder

  1. Visit https://vulnerabilities.cisa.gov/.

  2. Select [Log in or sign up].

  3. Select [Sign in with PIV / CAC card].

  4. You should now be logged in to VINCE-NT.

4.3 Now What?

  1. As a Reporter, you might want to report a vulnerability or view Cases you have previously reported.

  2. If you are a Supplier, you might want to create or join an existing Supplier Group or view your Cases.

5. Log out of VINCE-NT

  1. Select your profile icon in the upper right corner.

  2. Select [Log Out].

  3. Select [Sign Out] on the confirmation screen. This will log you out of VINCE-NT but not your authentication provider.

    1. If you log in to VINCE-NT while your authentication provider session is still valid, you will not need to provide credentials.

6. Log out of Authentication Provider (CISA ICAM, Okta)

  1. On the VINCE-NT log out screen, select [Log out of the authentication provider.].

    1. Alternatively, visit https://login.access.cisa.gov/
  2. In the CISA ICAM screen, select your name and [CISA ICAM Login] in the upper right corner.

  3. Select [Sign out].

  4. You will be returned to the CISA ICAM login screen. If you authenticate again from this screen, you will be taken to the CISA ICAM screen. You should see a VINCE-NT App icon, select this to return to the VINCE-NT login screen. Select [Log in or sign up] and you will be automatically logged in to VINCE-NT.

7. Reset Password (for self-service only)

  1. Visit https://vulnerabilities.cisa.gov/.

  2. Click [Log in or sign up].

  3. Enter your email address and select [Next].

  4. If prompted with the password screen, proceed to step 5.

    1. If prompted with a non-password authentication option, select [Verify with something else] then select [Password]
  5. Select [Forgot Password?].

  6. Select [Send me an email].

    1. A reset email will be sent to your email address.
  7. Select the [Reset Password] button in the password reset email.

    1. If you have Okta set up as a form of authentication, you may also use the code provided in the email instead.
  8. Enter and re-enter a new password and confirm it.

  9. Select [Reset Password]. You may be logged in directly after this step.

  10. If not logged in already, select [Login] or return to the original login window and enter your new credentials.

8. Manage MFA Methods (for self-service only)

  1. Visit https://login.access.cisa.gov/.

  2. If necessary, log in.

  3. Select the dropdown under your profile name in the top right, select [Account settings].

  4. Scroll down to Security Methods.

  5. Edit, Set up, or Remove authentication methods as desired.

9. Get Help

9.1 Logging In

For issues related to logging in, including multi-factor security method and password resets:

  1. Visit https://access.cisa.gov/faq.

  2. Send mail to the CISA Technical Operations Center.

9.2 Report a Bug or Request a Feature

  1. Visit the CISA VINCE-NT GitHub repository and review existing issues. If you do not find a relevant existing issue, file a new issue.

  2. Alternatively, send mail to the CISA CVD team.

9.3 Report a Security Vulnerability in VINCE-NT

  1. Report the vulnerability within VINCE-NT.

  2. File a private report through GitHub.

  3. Send mail to the CISA CVD team.

9.4 Report a Code of Conduct Issue

  1. Send mail to the CISA CVD team.

  2. If the issue involves the CISA CVD team, send mail to central@cisa.dhs.gov.

10. Manage Your Account

  1. Select the user icon in the upper right corner of most screens.

  2. Select [Profile].

10.1 Change Profile Details

  1. Select the [Account] tab.

  2. Make any desired changes.

    1. You can change the color of your user icon, upload or remove ([Reset]) a profile photo, change your name, organization, and title, and change your time zone.
  3. Select [Save changes] at the bottom of the screen.

10.2 Generate an API Key

  1. Select the [MFA/API] tab.

  2. Select [Generate API Key].

  3. Save the API key somewhere securely. Anyone with the valid API key can perform actions as you in VINCE-NT.

  4. Select [Ok].

  5. To generate a new API key select [Refresh API Key].

    1. If you are concerned that your API key was exposed, generate a new API key. This invalidates the previous API key.

10.3 Configure Email Preferences

  1. Select the [Email Preferences] tab.

  2. Make any desired changes.

  3. Select [Save Changes] at the bottom of the screen.