Generalizability of telemetry-based internal-knowledge regulation to vendors
Determine whether the telemetry-based regulatory mechanism established by CISA Binding Operational Directive 26-04 for federal operators can be generalized to software vendors so that regulatory duties attach to independently recorded internal vulnerability findings rather than only to externally observed exploitation.
References
Whether that generalises from federal operators to vendors is the open question.
— After Cheap Discovery: From unknown to known-and-unfixed
(2609.03266 - Sistany, 3 Sep 2026) in Section 9, “What follows for measurement and effort”