-
Notifications
You must be signed in to change notification settings - Fork 0
Frequently Asked Questions
The Coordinated Vulnerability Disclosure (CVD) process relies on a common platform that enables researchers and suppliers (IT and OT/ICS) to report, communicate, and coordinate the mitigation of cybersecurity vulnerabilities. From 2020 – September 17, 2026, that platform was the Vulnerability Information and Coordination Environment (VINCE), a secure coordination tool sponsored by CISA and hosted by Carnegie Mellon University’s Software Engineering Institute (SEI).
The Vulnerability Information and Coordination Environment New Technology (VINCE-NT) now replaces the legacy VINCE system and serves as the modern platform supporting the CVD process. Sponsored, hosted, and managed by CISA, VINCE-NT introduces updated technology, improved security, and enhanced workflows to strengthen collaboration across the cybersecurity community. This modernization effort advances CISA’s mission to provide secure, efficient tools for handling vulnerability information. For additional details, please refer to CISA's CVE Vision Paper.
VINCE-NT is the upgraded version of the VINCE platform. Sponsored, hosted, and managed by CISA, VINCE-NT builds on the foundation of VINCE, introducing modernized technologies, enhanced security features, and improved functionality to better support CISA’s mission of securing critical infrastructure and fostering collaboration among researchers, suppliers, and other stakeholders. The platform streamlines the process of identifying and resolving cybersecurity vulnerabilities, ensuring that vulnerabilities are disclosed, remediated, and communicated in a timely and secure manner. VINCE-NT is part of CISA’s broader effort to lead the cybersecurity community in reducing risk and strengthening the security of critical systems and infrastructure.
The transition to VINCE-NT primarily impacts teams and individuals who have been using the VINCE platform. These users include members of CISA's CVD team, cybersecurity researchers, product suppliers, and other stakeholders involved in the CVD process. These groups rely on the platform to report, coordinate, and remediate vulnerabilities in a secure manner, ensuring that risks to critical infrastructure and systems are mitigated effectively. Other CISA personnel who do not directly use VINCE or participate in vulnerability coordination will experience minimal or no impact.
The intended users of VINCE-NT are vulnerability researchers, suppliers, and others involved in the CVD process.
Active VINCE cases will be transitioned over the coming weeks following VINCE-NT go-live on September 17, 2026. Your case coordinator will reach out and convey the transition date within the VINCE case.
Historical case data will be available for the foreseeable future within VINCE.
VINCE-NT offers enhanced coordination workflows, improved integration with CISA’s internal tools and processes, and an updated user experience, advancing our ability to reduce cybersecurity risk in critical infrastructure and IT systems. Additionally, this change shifts ownership, sponsorship, and management of the platform to CISA.
CISA will process all new vulnerability reports and coordination activities in VINCE-NT. Enhancements include:
- Streamlined Report Submission: VINCE-NT introduces a user-friendly interface that makes submitting vulnerability reports easier, safer, and reduces friction.
- Enhanced Triage Effectiveness: Teams can quickly prioritize the most critical vulnerabilities, prompting a quicker response time.
- Improved Publication Workflow: VINCE-NT simplifies advisory publication through automation, delivering timely and accurate information to stakeholders.
- Secure Communication & File Sharing: Built-in tools enable transparent collaboration among all parties while protecting sensitive data.
- Robust Case Metrics: Advanced reporting tracks progress and performance, giving CISA’s CVD team actionable insights to improve coordination.
- Multi-party Coordination: VINCE-NT supports seamless collaboration among researchers, suppliers, and defenders, accelerating resolution and reducing risk.
VINCE-NT uses slightly different terms than VINCE and other common jargon.
| VINCE-NT | VINCE (and other) |
|---|---|
| Supplier | vendor, developer, maintainer |
| Component | product (CVE, CSAF) |
| Reporter | researcher, finder |
A more significant difference is that VINCE-NT supports more specific and formal vulnerability status information than Vendor Information provided in VINCE-generated Vulnerability Notes. This aligns more closely with CSAF and the CVE Record Format.
No, VINCE-NT and the Vulnerability Disclosure Policy (VDP) Platform serve different purposes. The VDP platform is a CISA-managed service that enables Federal Civilian Executive branch agencies to intake, triage, and route vulnerabilities reported by public security researchers for issues found in the agencies own internet-accessible systems. VINCE-NT is a tool designed to support the CVD process by facilitating collaboration and communication between industry stakeholders involved in addressing vulnerabilities which may receive a CVE ID. The CVD process focuses on working with researchers, suppliers, and other stakeholders to coordinate the responsible disclosure and remediation of novel vulnerabilities.
Anyone is eligible to report a vulnerability, and you do not need an account. See Reporters: Report a Vulnerability . That’s it. Your report will be sent to the CVD team for review and follow-up.
If you have additional questions, please contact the CVD team at cvd@cisa.dhs.gov or visit CISA's CVD Program page for more information on CVD.