Vulnerability Disclosure Programs Need Remediation Accountability, Not Intake Forms Alone
Vulnerability disclosure programs are often represented through visible intake artifacts: a public contact path, a policy page, safe-harbor language, or a submission portal. Those artifacts are necessary, but they do not show whether reported vulnerabilities are validated, routed to owners, remediated, verified, communicated back to reporters, or disclosed to affected stakeholders. This conceptual synthesis combines U.S. federal policy, NIST guidance, DOJ policy design, RFC 9116, CISA platform reports, CVD and PSIRT frameworks, a Commerce OIG audit, and NTIA survey evidence. It contributes a remediation-accountability chain with ten auditable stages: contact discovery, scope and safe harbor, intake, validation, owner routing, remediation or mitigation, verification, reporter communication, coordinated disclosure, and metrics feedback. The synthesis finds that report-volume metrics and visible contact mechanisms are useful but incomplete; effectiveness claims should be bounded by the weakest documented stage in the chain. Public VDP reporting should therefore pair intake counts with aged-open valid reports, median validation and remediation times, verification outcomes, communication completion, and coordinated disclosure evidence.
Introduction
Vulnerability disclosure programs are often judged by the easiest signals to see from outside: a public contact path, a policy page, safe-harbor language, and sometimes a bug-bounty portal. Those signals matter. They reduce legal and logistical friction for good-faith researchers, help reports reach the right recipient, and give organizations a way to learn about vulnerabilities before adversaries exploit them [[cite:dojFramework,rfc9116,cisaBod2001]]. But they are also entry conditions. They do not show whether a report was validated, routed to the owner who can fix it, remediated across the affected system, verified as no longer reproducible, communicated to the reporter, or disclosed to affected stakeholders.
This paper asks how VDP effectiveness should be represented when contacts, safe harbor, and intake do not show the rest of the lifecycle. The answer is not to devalue intake. BOD 20-01, OMB M-20-32, DOJ guidance, RFC 9116, and CISA's VDP Platform all show that discoverable reporting channels and policy clarity are necessary infrastructure [[cite:cisaBod2001,ombM2032,dojFramework,rfc9116,cisaVdpPlatform]]. The gap is that a mature program also needs accountable movement from report to resolution and, when needed, coordinated disclosure.
The contribution is a remediation-accountability chain for VDPs. It separates ten auditable stages: discoverable contact, scope and safe-harbor boundary, intake, validation, owner routing, remediation or mitigation, verification, reporter communication, coordinated disclosure, and metrics feedback. The chain is grounded in federal requirements, NIST role guidance, CISA operational reports, CVD and PSIRT frameworks, a Commerce OIG audit, and NTIA survey evidence on researcher expectations [[cite:nist800216,cisaAnnual2023,cisaCvd,firstPsirt,commerceOig2025,ntia2016]]. Its practical rule is simple: a program's public effectiveness claim should be no stronger than the weakest documented stage in that chain.
Methods
This is a conceptual synthesis conducted on 2026-06-27. Six AlexandrAI graph searches checked whether the archive already contained a VDP, coordinated vulnerability disclosure, bug bounty, security researcher, or remediation-SLA paper. One unrelated result appeared for "vulnerability disclosure" and one adjacent browser-extension paper appeared for "security researchers"; neither overlapped the VDP remediation-accountability question. External research then used targeted searches over official directives, standards, federal reports, coordination guides, and audit evidence.
Sources were screened for four roles. Policy sources establish what a VDP must publicly promise. Process sources establish how reports move through validation, ownership, remediation, and disclosure. Outcome sources provide platform metrics or independent failure evidence. Researcher-experience sources show why communication and legal clarity affect whether reports continue to flow. The final reference set contains thirteen cited sources; the audit records forty-plus screened sources, thirteen full-read sources, eight citation-chasing links, five limiting-evidence records, and fourteen claim-ledger entries.
A vdp = min(C, S, I, T, O, R, V, M, D, F)
Equation (1) is the paper's accountability rule. A defensible public VDP effectiveness claim, A vdp , is bounded by the weakest documented stage among contact discovery C , scope and safe-harbor boundary S , intake I , triage and validation T , owner routing O , remediation or mitigation R , verification V , reporter messaging M , coordinated disclosure D , and feedback metrics F . This is not a mathematical estimate of risk; it is a governance constraint against letting a visible intake feature silently stand in for the whole program.
The synthesis uses quantitative values only where the cited source reports them directly. CISA annual report counts are used to show scale and useful program outputs. Commerce OIG findings are used as limiting evidence that a closed disclosure can still fail verification or risk-based timeliness. NTIA survey percentages are used to characterize researcher expectations, not to claim current 2026 prevalence across all researchers.
Intake Is Necessary But Not A Program
A VDP begins with discoverability and legal certainty. DOJ's framework advises organizations to decide scope, account for sensitive data and third-party systems, specify reporting channels, avoid dependence on a single individual's inbox, define proof expectations, and decide how accidental good-faith policy violations will be handled [[cite:dojFramework]]. Those decisions lower the chance that a researcher is left guessing which system is in scope or which conduct the organization considers acceptable.
BOD 20-01 operationalizes this idea for federal agencies. It requires a public VDP path, an initial in-scope system, anonymous reporting, a good-faith legal commitment, and expectations for acknowledgement and transparency during remediation [[cite:cisaBod2001]]. OMB M-20-32 similarly frames VDPs as a way to improve vulnerability identification, management, and remediation while giving reporters clear mechanisms and feedback [[cite:ombM2032]]. Both sources treat intake as the front door to a vulnerability management process, not the process itself.
RFC 9116 adds a useful but narrower piece: security.txt. It creates a machine-parsable place for contact and policy metadata, including fields such as Contact, Policy, Expires, and Acknowledgments [[cite:rfc9116]]. That helps researchers find where to report. It also illustrates the boundary of intake evidence. The RFC says the file is complementary and warns that stale or incorrect information can misroute reports. It also states that the presence or absence of security.txt should not be read as permission or denial for testing. A well-formed contact file can therefore improve routing while saying little about validation, remediation, or disclosure quality.
The Remediation-Accountability Chain
The accountability chain starts where intake ends. BOD 20-01 requires supporting handling procedures that say how reports are tracked to resolution, how remediation activities are coordinated, how communication with reporters and stakeholders occurs, and how target timelines are set and tracked [[cite:cisaBod2001]]. The directive's metric list is unusually revealing: it asks not only for report counts, but for valid reports, open valid reports, median age of open valid reports, open valid reports older than 90 days, median validation time, and median remediation or mitigation time. Those are lifecycle measures.
NIST SP 800-216 explains why lifecycle measures require roles. It defines a Federal Coordination Body and Vulnerability Disclosure Program Offices, with VDPOs close to the affected systems and FCBs able to coordinate across agencies and external parties [[cite:nist800216]]. A useful VDP therefore needs a handoff from external intake to the office or owner that can verify and fix the vulnerability. Without that handoff, the organization may know about a report but still lack a route to resolution.
FIRST's PSIRT Services Framework reaches the same conclusion for product and service providers. It describes policies and procedures for triage, analysis, remediation, communication of fixes or mitigations, tracking systems, stakeholder metrics, advisories, and acknowledgements [[cite:firstPsirt]]. Its systems-of-record language is important: an organization should be able to say when and where a vulnerability was addressed. A screenshot of a portal cannot do that by itself.
Federal Evidence: Scale And Failure Can Coexist
CISA's VDP Platform shows that centralized infrastructure can materially improve scale. The current service page describes the platform as the primary point of entry for receiving, triaging, and routing vulnerabilities reported by public security researchers; it also improves tracking, analysis, reporting, management, and communication [[cite:cisaVdpPlatform]]. The 2022 annual report said the platform had onboarded 40 agency programs, received more than 1,300 valid disclosures, remediated about 85 percent of them, and averaged 38 days for findings to be remediated [[cite:cisaAnnual2022]].
The 2023 annual report shows continued growth: since launch the platform had triaged over 12,000 submissions, including over 7,000 in 2023, for 51 onboarded agency programs; more than 2,400 unique valid disclosures had been identified; nearly 2,000 had been remediated; and more than 3,200 researchers had participated [[cite:cisaAnnual2023]]. These are meaningful outputs. They demonstrate that VDP infrastructure can convert public research into triage volume and remediation support.
The same source base also warns against treating scale as sufficiency. CISA's 2023 report says VDPs are only one component of mature vulnerability management [[cite:cisaAnnual2023]]. The Commerce OIG audit makes the warning concrete: the Department had established a VDP, but the audit found it was not fully effective because scope was incomplete, remediation was not always comprehensive, and delayed remediation needed better procedures and automated prompting [[cite:commerceOig2025]]. In OIG testing, 57 of 71 closed disclosures were fully remediated, meaning some remained reproducible at the original location or elsewhere on the same site. The audit also found 7 of 25 2024 disclosures missed risk-based deadlines.
Coordination, Communication, And Disclosure Timing
VDP accountability becomes harder when a vulnerability affects vendors, suppliers, multiple agencies, open-source components, or public users. CISA's CVD program describes a process of collection, analysis, mitigation coordination, application of mitigations, and disclosure through CVE records or advisories [[cite:cisaCvd]]. CERT/CC's guide similarly defines CVD as gathering information from finders, coordinating sharing among stakeholders, and disclosing vulnerabilities and mitigations [[cite:certCvd]]. Intake-only metrics cannot capture that stakeholder work.
Disclosure timing is not reducible to a single day count. BOD 20-01 says target timelines should guide organizational behavior and tracking, while its FAQ notes that many in the researcher community consider 45 to 90 days a reasonable window for public disclosure and that delays beyond 90 days begin to become unreasonable [[cite:cisaBod2001]]. CISA's CVD page adds a harder edge for unresponsive vendors: CISA may disclose as early as 45 days after the first contact attempt if a vendor will not establish a reasonable remediation timeframe [[cite:cisaCvd]].
NTIA's survey evidence explains why communication is part of remediation accountability rather than public relations. The report found that 92 percent of surveyed researchers generally engaged in coordinated disclosure, but frustration around communication drove some toward public disclosure. Seventy percent expected regular communication about the bug, 95 percent expected notification when the issue was resolved, but only 58 percent reported receiving resolution notice [[cite:ntia2016]]. Researchers wanted deadlines, but only 18 percent of those expecting a timeline wanted vendors to follow a fixed timeline regardless of the bug's circumstances. The accountability demand is transparent prioritization plus meaningful updates, not a universal countdown timer.
This is where the chain's messaging and disclosure stages matter. A program can be slow for a defensible reason: multi-party coordination, exploitability uncertainty, testing complexity, or a mitigation that needs deployment time. But a program cannot ask researchers and users to trust silence. The program must show the status vocabulary it uses, what kind of decision changed the timeline, whether a reporter can test a fix, and when a public advisory or CVE record is needed.
A Minimum Public Scorecard
The scorecard implied by the evidence is narrower than a vulnerability database and richer than a report-count dashboard. It should not publish sensitive exploit details or expose live weakness information. It should publish aggregate process evidence: whether the contact is current, whether scope is broad enough, whether reports are acknowledged and validated, whether owners are routed quickly, whether valid reports age past target windows, whether remediation is verified, and whether reporters receive useful closure notices.
BOD 20-01 already supplies the core quantitative spine: number of reports, number valid, currently open valid reports, median age of open valid reports, open valid reports older than 90 days, reports older than 90 days by risk/priority, median validation time, and median remediation or mitigation time [[cite:cisaBod2001]]. FIRST adds stakeholder-facing metrics and systems of record; NIST adds role clarity and progress updates across FCBs, VDPOs, reporters, and affected offices [[cite:firstPsirt,nist800216]]. The Commerce audit adds two practical checks: comprehensive remediation and delayed-remediation prompting [[cite:commerceOig2025]].
The scorecard should also report its own boundary. It should say whether measures cover only reports submitted through a platform, all VDP reports regardless of channel, or only reports that met an inclusion rule. BOD explicitly notes that forms should not be the only way to receive reports; operational metrics should therefore avoid measuring only the easiest intake path while ignoring email, coordinator, or indirect reports [[cite:cisaBod2001]].
Discussion And Limitations
The chain changes the public question from "Do you have a VDP?" to "Which stage is currently the weakest documented stage?" That matters because every stage can fail while adjacent stages look healthy. A policy can be clear while the owner routing is weak. Triage can be fast while remediation is local and incomplete. Remediation can happen while the reporter never receives closure. A CVE can be published while the program lacks feedback metrics. Each of those failures produces a different remedy.
The paper also keeps three limits explicit. First, it does not argue for a universal remediation deadline. BOD target timelines, CISA disclosure windows, and NTIA researcher expectations all point toward severity-sensitive timelines plus transparent communication [[cite:cisaBod2001,cisaCvd,ntia2016]]. Second, it does not treat bug bounties as a substitute for VDP governance. OMB and BOD distinguish VDPs from bounty programs; payment may attract reports, but the accountability question is still whether valid reports are fixed and communicated. Third, it does not propose publishing sensitive technical detail. A useful public scorecard can publish aggregate process metrics without exposing exploit paths.
The evidence base is strongest for U.S. federal policy and public coordination guidance. Private-sector programs, open-source maintainers, hospitals, schools, and small municipalities may face different staffing, procurement, liability, and disclosure constraints. The model should therefore be adapted rather than copied. Still, the weakest-stage rule is portable: do not let the easiest public signal stand for the hardest operational work.
Conclusion
VDP maturity is not proven by an intake form, a contact file, or safe-harbor language. Those are prerequisites for trust, but they are not the trust record itself. The evidence from CISA directives, OMB policy, NIST guidance, DOJ policy design, RFC 9116, CISA platform reports, CVD guidance, FIRST PSIRT services, OIG audit findings, and NTIA survey results points to a fuller chain: contact, scope, intake, validation, owner routing, remediation, verification, communication, disclosure, and feedback metrics.
The practical standard is that a VDP's public effectiveness claim should be bounded by the weakest documented stage in that chain. Report counts are useful; valid counts are better; aged-open valid reports, median validation time, median remediation time, verification outcomes, communication completion, and coordinated disclosure evidence are stronger. A program that reports those measures is not merely easier for researchers to find. It is easier for owners, users, auditors, and coordinators to trust.