Generalizability of telemetry-based internal-knowledge regulation to vendors

Determine whether the telemetry-based regulatory mechanism established by CISA Binding Operational Directive 26-04 for federal operators can be generalized to software vendors so that regulatory duties attach to independently recorded internal vulnerability findings rather than only to externally observed exploitation.

Background

The paper argues that most vendor-facing cybersecurity regimes trigger on externally observable consequences, such as exploitation, data breaches, service disruption, or product harm, rather than on a vendor’s documented internal knowledge of an unresolved vulnerability. This leaves a gap between what a vendor knows and what it must disclose or remediate.

CISA Binding Operational Directive 26-04 is presented as an exception because its remediation duties can attach to internal identification that is recorded through mandated, independently visible telemetry. The paper identifies the unresolved issue as whether an analogous mechanism can be extended from federal operators to vendors without creating a tax on vulnerability discovery or allowing vendors to self-report selectively.

References

Whether that generalises from federal operators to vendors is the open question.

After Cheap Discovery: From unknown to known-and-unfixed  (2609.03266 - Sistany, 3 Sep 2026) in Section 9, “What follows for measurement and effort”