Skip to content

Frequently Asked Questions

amanion-cisa edited this page Sep 17, 2026 · 7 revisions

The Coordinated Vulnerability Disclosure (CVD) process relies on a common platform that enables researchers and suppliers (IT and OT/ICS) to report, communicate, and coordinate the mitigation of cybersecurity vulnerabilities. From 2020 – September 17, 2026, that platform was the Vulnerability Information and Coordination Environment (VINCE), a secure coordination tool sponsored by CISA and hosted by Carnegie Mellon University’s Software Engineering Institute (SEI).

The Vulnerability Information and Coordination Environment New Technology (VINCE-NT) now replaces the legacy VINCE system and serves as the modern platform supporting the CVD process. Sponsored, hosted, and managed by CISA, VINCE-NT introduces updated technology, improved security, and enhanced workflows to strengthen collaboration across the cybersecurity community. This modernization effort advances CISA’s mission to provide secure, efficient tools for handling vulnerability information. For additional details, please refer to CISA's CVE Vision Paper.

What is VINCE-NT?

VINCE-NT is the upgraded version of the VINCE platform. Sponsored, hosted, and managed by CISA, VINCE-NT builds on the foundation of VINCE, introducing modernized technologies, enhanced security features, and improved functionality to better support CISA’s mission of securing critical infrastructure and fostering collaboration among researchers, suppliers, and other stakeholders. The platform streamlines the process of identifying and resolving cybersecurity vulnerabilities, ensuring that vulnerabilities are disclosed, remediated, and communicated in a timely and secure manner. VINCE-NT is part of CISA’s broader effort to lead the cybersecurity community in reducing risk and strengthening the security of critical systems and infrastructure.

Who will be impacted by the transition from VINCE to VINCE-NT?

The transition to VINCE-NT primarily impacts teams and individuals who have been using the VINCE platform. These users include members of CISA's CVD team, cybersecurity researchers, product suppliers, and other stakeholders involved in the CVD process. These groups rely on the platform to report, coordinate, and remediate vulnerabilities in a secure manner, ensuring that risks to critical infrastructure and systems are mitigated effectively. Other CISA personnel who do not directly use VINCE or participate in vulnerability coordination will experience minimal or no impact.

Who are the intended users of VINCE-NT?

The intended users of VINCE-NT are vulnerability researchers, suppliers, and others involved in the CVD process.

What will happen to active VINCE cases?

Active VINCE cases will be transitioned over the coming weeks following VINCE-NT go-live on September 17, 2026. Your case coordinator will reach out and convey the transition date within the VINCE case.

What will happen to inactive VINCE cases?

Historical case data will be available for the foreseeable future within VINCE.

Why is VINCE being upgraded to VINCE-NT?

VINCE-NT offers enhanced coordination workflows, improved integration with CISA’s internal tools and processes, and an updated user experience, advancing our ability to reduce cybersecurity risk in critical infrastructure and IT systems. Additionally, this change shifts ownership, sponsorship, and management of the platform to CISA.

CISA will process all new vulnerability reports and coordination activities in VINCE-NT. Enhancements include:

  • Streamlined Report Submission: VINCE-NT introduces a user-friendly interface that makes submitting vulnerability reports easier, safer, and reduces friction.
  • Enhanced Triage Effectiveness: Teams can quickly prioritize the most critical vulnerabilities, prompting a quicker response time.
  • Improved Publication Workflow: VINCE-NT simplifies advisory publication through automation, delivering timely and accurate information to stakeholders.
  • Secure Communication & File Sharing: Built-in tools enable transparent collaboration among all parties while protecting sensitive data.
  • Robust Case Metrics: Advanced reporting tracks progress and performance, giving CISA’s CVD team actionable insights to improve coordination.
  • Multi-party Coordination: VINCE-NT supports seamless collaboration among researchers, suppliers, and defenders, accelerating resolution and reducing risk.

What are some differences between VINCE-NT and VINCE?

VINCE-NT uses slightly different terms than VINCE and other common jargon.

VINCE-NT VINCE (and other)
Supplier vendor, developer, maintainer
Component product (CVE, CSAF)
Reporter researcher, finder

A more significant difference is that VINCE-NT supports more specific and formal vulnerability status information than Vendor Information provided in VINCE-generated Vulnerability Notes. This aligns more closely with CSAF and the CVE Record Format.

Is VINCE-NT related to CISA VDP?

No, VINCE-NT and the Vulnerability Disclosure Policy (VDP) Platform serve different purposes. The VDP platform is a CISA-managed service that enables Federal Civilian Executive branch agencies to intake, triage, and route vulnerabilities reported by public security researchers for issues found in the agencies own internet-accessible systems. VINCE-NT is a tool designed to support the CVD process by facilitating collaboration and communication between industry stakeholders involved in addressing vulnerabilities which may receive a CVE ID. The CVD process focuses on working with researchers, suppliers, and other stakeholders to coordinate the responsible disclosure and remediation of novel vulnerabilities.

How do I report a Vulnerability?

Anyone is eligible to report a vulnerability, and you do not need an account. See Reporters: Report a Vulnerability . That’s it. Your report will be sent to the CVD team for review and follow-up.

What should I do if I have questions about VINCE-NT or CVD?

If you have additional questions, please contact the CVD team at cvd@cisa.dhs.gov or visit CISA's CVD Program page for more information on CVD.