Security researchers question effectiveness of long-standing protocol for reporting software flaws to vendors.
ℹ️ Browser-based reading · AI studio voice coming soon
The technology industry is moving away from the 90-day vulnerability disclosure policy, a standard practice for reporting software security flaws to vendors before public release, according to discussion on Hacker News.
The 90-day window—established decades ago—has historically allowed companies time to develop patches while giving researchers a deadline to prevent indefinite delays. However, critics argue the timeframe no longer reflects modern software development cycles or threat landscapes.
European cybersecurity officials and enterprises monitor disclosure practices closely, as they affect incident response capabilities across the EU's expanding digital infrastructure. The shift signals potential changes to coordinated vulnerability management frameworks that organizations rely on for security planning.
No official regulatory body has announced policy changes, but the debate reflects growing pressure on disclosure standards. EU member states continue developing cybersecurity strategies that depend on predictable vulnerability reporting timelines. Industry consensus on revised disclosure protocols remains unclear.
The tech industry is moving away from the 90-day vulnerability disclosure standard, with security researchers arguing the decades-old window no longer fits modern software development or threat landscapes. No official regulatory changes have been announced, but the shift could reshape how organizations coordinate security patches and incident response.
If disclosure timelines become unpredictable, your organization's security planning could face delays—patch windows may extend or compress unpredictably, affecting when you need to deploy fixes. EU companies especially should watch this closely, as national cybersecurity strategies currently depend on these standardized timelines for compliance and risk management.