CISA Rolls Out Upgraded Vulnerability Reporting Platform: VINCE-NT
The US Cybersecurity and Infrastructure Security Agency (CISA) has launched an upgraded version of its vulnerability reporting and coordination platform, moving from the Carnegie Mellon University-developed VINCE system to a new CISA-managed platform called VINCE-NT. The change, effective from September 17, 2026, brings more automation, built-in tools for researchers, and better integration with CISA's internal processes.
As part of the transition, CISA has also updated some of its terminology. What was previously called a 'vendor/developer/maintainer' is now a 'supplier,' 'product' becomes 'component,' and 'researcher/finder' is now referred to as a 'reporter.' Ownership and management of the platform has shifted to CISA's Coordinated Vulnerability Disclosure (CVD) team.
Organisations with active cases on the old VINCE platform will be contacted by a case coordinator about their transition date, while inactive cases will remain on the legacy system rather than being migrated. CISA has advised all organisations to update their internal reporting procedures so future vulnerability submissions are made through VINCE-NT rather than the old platform.