Skip to content

Security1 publisher2 min readPublished

CISA moves vulnerability coordination off CERT/CC's VINCE onto its own platform

Since September 17, 2026, reports to CISA go through VINCE-NT, a platform the agency owns and manages itself, and anyone with an open case will be told individually when it moves across.

The Watch · Security desk

Illustration accompanying CISA moves vulnerability coordination off CERT/CC's VINCE onto its own platform

What happened

  • CISA switched its vulnerability reporting and coordination intake to VINCE-NT on September 17, 2026, replacing the platform it had used for filings and case handling.
  • Active cases transition over the coming weeks rather than in one cutover, and inactive cases are not migrated and remain accessible only on the old VINCE instance.
  • The terminology changed with the platform: vendor or maintainer is now supplier, product is now component, and researcher or finder is now reporter.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint Case history is now split across two systems, so anyone reconstructing a closed multi-party coordination has to search the retired platform as well as the new one.
  • decision Every organization with a documented CISA escalation path has to decide whether to rewrite its disclosure policy and intake automation now or discover the renamed fields during a live case.
  • exposure Reporters and suppliers filing with CISA are now handing case data to a platform the agency itself owns and hosts, with the coordination metrics flowing to its CVD team.
  • capability Direct integration with CISA's internal tooling makes it easier for the agency to feed disclosure cases into its other programs without a hand-off from a university-run center.

The practical change for a reporter is which login holds the case file. VINCE was built in 2020 by CERT/CC, a unit of Carnegie Mellon University's Software Engineering Institute, and CISA has used it since that year [2]. VINCE-NT is CISA-managed, and the agency says the change moves ownership, sponsorship and management of the platform to its Coordinated Vulnerability Disclosure team and lets the platform integrate with CISA's internal tools and processes [4][5].

"VINCE-NT is a modernized, CISA-managed platform for vulnerability reporting and coordination. It improves how vulnerability reporters, product suppliers and CISA case managers collaborate throughout the disclosure process," CISA said in an announcement posted on social media on September 17 [6].

Active cases move over the coming weeks, and a case coordinator contacts each stakeholder with the transition date, so the migration is per-case [7][8]. Inactive cases do not move at all; they stay on VINCE [9]. Anyone who needs the history of a closed multi-party case therefore has two systems to search. The announcement does not say how long the old one stays reachable.

The vocabulary changed too. "Vendors/developer/maintainer" is now "supplier," "product" is now "component," and "researcher/finder" is now "reporter" [10]. That matters for anyone whose intake automation, ticket templates or disclosure policy references the old field names. CISA said organizations should update internal reporting procedures so submissions go through VINCE-NT [11].

On the platform itself, CISA lists a simpler submission interface, better triage prioritization, automated advisory publication workflows, built-in collaboration tools that protect sensitive data, more case metrics for the CVD team, and stronger support for multi-party coordination [3]. Those are the agency's own descriptions of its own build. The announcement includes no third-party assessment of them, and says nothing about how case data was moved or what access CERT/CC retains to material that stays on VINCE.

Nothing here is being attacked, and no CVE turns on it. The change is custody: a coordination workflow that a US federal agency rented from a university-run center for six years is now built and managed by the agency, with the case metrics flowing to CISA's CVD team [4][5]. For a reporter filing to CISA, the requirement is a new account and a corrected internal runbook. For a supplier receiving multi-party notifications, the harder question is whether embargo handling and participant lists behave the same way on a platform whose operator also runs the US federal disclosure program.

What to watch

  • Whether CISA publishes a retirement date for VINCE, since inactive cases remain only there.
  • Whether CERT/CC states what access it keeps to case data left on VINCE, and whether it continues to run its own coordination intake.
  • Whether multi-party embargo handling and participant visibility on VINCE-NT match what suppliers saw on VINCE.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories