Coordinated Disclosure
Coordinated disclosure is a process in which someone who finds a security vulnerability reports it privately to the vendor or affected party and gives them time to fix it before the details are made public. This approach is intended to protect users by reducing the window during which a flaw is known but unremediated. It requires cooperation between the person who discovers the vulnerability and the organization responsible for addressing it.
Coordinated Vulnerability Disclosure (CVD) is a vulnerability disclosure model in which finders (such as security researchers) and the relevant stakeholders (typically the affected vendor, and in some cases a coordinating body such as CISA or a national CSIRT) work together to share information about a vulnerability, allowing time for remediation before the vulnerability is publicly disclosed. It is sometimes referred to as responsible disclosure, though the coordinated framing emphasizes multi-party cooperation rather than obligation. CVD governs the timing and communication of disclosure between the parties; it does not by itself guarantee that a fix is developed, deployed, or effective, and the specifics, such as disclosure timelines and coordinator roles, vary by policy, program, and jurisdiction. In the third-party and supply chain context, coordinated disclosure is a mechanism affecting how vulnerabilities in a supplier's products or services become known, but it is distinct from a supplier's internal patching, ongoing monitoring, or contractual notification obligations. Regulatory and policy expectations around CVD differ across regions (for example, EU-level guidance discussed by ENISA versus U.S. programs run by CISA).
Why it matters
For third-party and supply chain risk professionals, coordinated disclosure shapes how and when an organization learns that a vulnerability exists in a supplier's product or service. Because most organizations have limited visibility into the internal development and security practices of their vendors, the disclosure process is often one of the few structured channels through which flaws in externally sourced software or services become known. A well-functioning CVD process can shorten the window during which a vulnerability is known but unremediated, but it does not by itself confirm that a supplier has developed, deployed, or verified an effective fix. Those remain distinct from the disclosure event itself.
CVD is also important because the timing of public disclosure directly affects downstream exposure. When a vulnerability in a widely used supplier component becomes public before affected organizations have applied remediation, the disclosure can accelerate exploitation attempts across every organization that depends on that component. This is particularly relevant where a single supplier or component is embedded across many products, so a coordination breakdown at one vendor can propagate risk through multiple tiers of a supply chain. Coordinated disclosure governs communication and timing, but it does not substitute for a supplier's internal patching, ongoing monitoring, or contractual notification obligations, and gaps in any of these can leave residual exposure even when disclosure is handled well.
Because expectations around disclosure differ by policy, program, and jurisdiction, professionals should not assume a uniform standard. Programs such as CISA's Coordinated Vulnerability Disclosure Program in the United States and EU-level guidance discussed by ENISA reflect different regional approaches, and a supplier operating across regions may be subject to more than one set of expectations. Understanding whether and how a critical supplier participates in coordinated disclosure, and how it commits to notify customers, can be a meaningful input into vendor assessment, though it should be treated as one signal among several rather than a guarantee of security.
Who it's relevant to
Inside CVD
Common questions
Answers to the questions practitioners most commonly ask about CVD.
