# GSA Defines Vulnerability Disclosure Rules

GSA’s vulnerability disclosure policy sets authorized testing boundaries and reporting procedures for security researchers using systems listed on its VDP Platform. Contractors supporting in-scope GSA systems should account for the policy’s 90-day remediation and disclosure framework, report vulnerabilities found in vendors’ non-federal systems directly to those vendors, and follow restrictions on handling sensitive information.

- Contractors should confirm which GSA systems are listed on the VDP Platform and ensure security testing and vulnerability-reporting processes follow the stated scope and procedures.
- The 90-day framework makes timely coordination between contractors and GSA important for remediation and disclosure of reported vulnerabilities.
- Vulnerability reports concerning vendors’ non-federal systems should go directly to those vendors; reports to GSA can be submitted at gsa-vulnerability-reports@gsa.gov, including to ask whether a system is in scope.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity
**Published:** October 01, 2026

### Government Entities
- U.S. General Services Administration (GSA)
- Cybersecurity and Infrastructure Security Agency (CISA)

### Sources
- [Vulnerability disclosure policy | GSA](https://www.gsa.gov/website-information/vulnerability-disclosure-policy) - GSA