# CISA Vendor-Researcher Collaboration Framework

> CISA releases a vendor-researcher collaboration framework establishing operational standards for coordinated vulnerability disclosure, including safe harbor provisions and response timelines.

**URL:** https://www.ciptadusa.com/blog/cisa-vendor-researcher-disclosure-guide-20260716  
**Type:** blog  
**Author:** PT Cipta Dua Saudara  
**Category:** Application Security  
**Published:** 2026-07-16  
**Cover:** https://cdn-uagents.enitip.com/uploads/blog/2026-07/daily-appsec-20260716-015009.jpg  

## Article

CISA and its international partners have published new guidance that explicitly defines how software vendors and online service providers should collaborate with security researchers. This isn't another advisory—it's an operational blueprint for coordinated vulnerability disclosure that addresses the grey zones organizations have navigated for decades.

## Summary

CISA releases a vendor-researcher collaboration framework establishing operational standards for coordinated vulnerability disclosure, including safe harbor provisions and response timelines.

## The Challenge

The relationship between security researchers and software vendors has historically been fraught with friction. A researcher discovers a vulnerability, reports it to the vendor, then waits—sometimes weeks, sometimes months—without clarity on whether their report was read, prioritized, or ignored.

On the vendor side, vulnerability reports arrive in inconsistent formats, through undefined channels, with varying timeline expectations. Without a clear framework, both parties operate on assumptions—and divergent assumptions produce conflict.

The result: premature full disclosure, silent patching without credit, legal threats against researchers, and vulnerabilities that remain open because no one wants to coordinate.

## Approach

The CISA guidance establishes three operational pillars:

**Explicit safe harbor.** Vendors are asked to publish written policies protecting researchers from legal action as long as they operate within defined scope. This is no longer goodwill—it's an auditable commitment.

**Defined channels and timelines.** Every vendor should maintain a security.txt, a dedicated intake email, and timeline commitments for acknowledgment (48 hours), triage (7 days), and remediation (90 days). These numbers aren't arbitrary—they follow ISO 29147 standards and battle-tested practices.

**Collaboration, not confrontation.** The guidance promotes a model where researchers are involved in the patching process—from fix validation to coordinated disclosure timing. This transforms the dynamic from adversarial to cooperative.

For application security teams, the implication is direct: audit whether your organization already has a vulnerability disclosure policy meeting these standards. If not, the CISA guidance provides a ready-to-adapt template.

## References

- [CISA and Partners Publish Guidance to Help Software Manufacturers](https://www.cisa.gov/news-events/news/cisa-and-partners-publish-guidance-help-software-manufacturers-and-online-service-providers-work) — CISA
- [ISO/IEC 29147:2018 Vulnerability Disclosure](https://www.iso.org/standard/72311.html) — ISO
- [The CERT Guide to Coordinated Vulnerability Disclosure](https://vuls.cert.org/confluence/display/CVD) — CERT/CC

---

*Markdown version of https://www.ciptadusa.com/blog/cisa-vendor-researcher-disclosure-guide-20260716 — generated for AI agents and LLM crawlers.*
