“VINCE-NT is a modernized, CISA-managed platform for vulnerability reporting and coordination. It improves how vulnerability reporters, product suppliers and CISA case managers collaborate throughout the disclosure process,” CISA said in an announcement published on social media on September 17.
From VINCE to VINCE‑NT: a formal handoff
Since 2020 the agency has used Carnegie Mellon University’s Vulnerability Information and Coordination Environment (VINCE), a platform developed that year by the Computer Emergency and Response Team Coordination Center (CERT/CC), a unit of the university’s Software Engineering Institute (SEI). On September 17, 2026, CISA said it is now using VINCE‑New Technology (VINCE‑NT) and that the change “shifts ownership, sponsorship and management of the platform to its Coordinated Vulnerability Disclosure (CVD) team.”
VINCE‑NT's built‑in collaboration and automation tools
CISA outlined a set of enhancements built into VINCE‑NT intended to reduce friction and improve coordination. The agency listed the following capabilities:
- A user-friendly interface that makes submitting vulnerability reports easier, safer and reduces friction
- Enhanced triage effectiveness enabling teams to better prioritize the most critical vulnerabilities
- Simplified advisory publication workflows through automation
- Built-in tools enabling transparent collaboration among all parties while protecting sensitive data
- Enhanced reporting case metrics, giving CISA’s CVD team actionable insights to improve coordination
- Stronger support for multi-party coordination and developing advisories

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleEnhanced triage, reporting metrics, and automated advisory workflows
CISA emphasized that VINCE‑NT not only modernizes the user interface but also automates parts of the disclosure lifecycle. The agency said automation will simplify advisory publication workflows and provide enhanced reporting case metrics that supply the CVD team with “actionable insights” to improve coordination. CISA also signaled the platform is designed to support multi‑party coordination while protecting sensitive data during collaboration.
Terminology changes: supplier, component, reporter
Alongside technical and process upgrades, VINCE‑NT introduces standardized vocabulary for participants and artifacts. CISA said the labels it previously used will be revised: the “vendors/developer/maintainer” entry becomes “supplier,” “product” is replaced by “component,” and “researcher/finder” is now “reporter.”
What this means for vulnerability reporters, product suppliers, and CISA case coordinators
- Vulnerability reporters: CISA said vulnerability submissions should now be made through VINCE‑NT; the platform’s user interface and built‑in collaboration tools are intended to make reporting “easier, safer and reduce friction.”
- Product suppliers: Organizations that previously engaged on VINCE should update internal reporting procedures to reflect that submissions to CISA flow through VINCE‑NT going forward.
- CISA case coordinators and active‑case stakeholders: CISA said active VINCE cases will be transitioned to VINCE‑NT “over the coming weeks.” For stakeholders with active cases, a case coordinator will reach out and convey the transition date; CISA also said inactive cases will not be moved but will remain available on VINCE.
By formally moving VINCE into a CISA‑managed VINCE‑NT and updating both tooling and terminology, the agency has set a concrete operational step: organizations should update internal reporting procedures so that future vulnerability submissions to CISA are made through VINCE‑NT. Active cases will be migrated in the coming weeks, inactive cases will stay on the original VINCE, and case coordinators will notify stakeholders of specific transition dates.




