Vulnerability Disclosure Program (VDP)
A Vulnerability Disclosure Program (VDP) is a formal, published process that lets outside security researchers and members of the public safely report security flaws they find in an organization's systems or software. It gives researchers a clear, sanctioned way to notify the organization so problems can be fixed rather than exploited. In the federal context, agencies may use a shared platform to receive and act on this information.
A Vulnerability Disclosure Program (VDP) is a formal mechanism through which an organization enables external security researchers to test in-scope systems and report discovered vulnerabilities responsibly, generally including a published policy that defines authorized scope, reporting channels, handling expectations, and researcher protections. For U.S. federal civilian agencies, CISA offers a VDP Platform that enables agencies to receive actionable vulnerability information and collaborate with the public. A VDP should be distinguished from a bug bounty program: a VDP generally provides a coordinated intake and disclosure process without necessarily offering monetary rewards, whereas bug bounty programs typically incentivize submissions with payment. The evidence provided does not establish the specific binding authority, applicable directive, or scope boundaries (for example, applicability to CUI, defense, or national security systems) for any given VDP, and readers should verify the governing policy and any agency-specific requirements against current official sources.
Why it matters
A Vulnerability Disclosure Program addresses a persistent reality: security researchers and members of the public regularly discover flaws in an organization's systems whether or not the organization invites them to. Without a published, sanctioned channel for reporting, well-intentioned finders may have no safe way to notify the organization, and the organization may lose the opportunity to remediate a flaw before it is exploited. A VDP formalizes this intake so that vulnerabilities can be surfaced and fixed rather than left unreported or, worse, quietly traded or exploited.
Who it's relevant to
Inside VDP
Common questions
Answers to the questions practitioners most commonly ask about VDP.