Last updated
    CERT Coordination Center
    Cybersecurity

    CERT Coordination Center

    United States flagUnited States

    "Coordinating responses to computer security incidents since 1988"

    Founded 1988 Pittsburgh, Pennsylvania, United States
    Community

    About

    The CERT Coordination Center, commonly known as CERT/CC, was established in 1988 at the Software Engineering Institute (SEI) at Carnegie Mellon University, following the Morris Worm incident that infected roughly 6,000 computers. That event made clear the need for a centralized capability to handle computer security emergencies. What began as a small team has grown into a research organization of more than 200 professionals, focused on discovering, analyzing, and coordinating responses to software vulnerabilities, with particular attention to those affecting multiple vendors or safety-critical systems.

    CERT/CC operates as a federally funded research and development center, with primary funding from U.S. government contracts, notably from the Department of Defense and the Department of Homeland Security. Its role is coordination rather than commercial competition. It acts as a neutral intermediary between businesses, government agencies, and other Computer Emergency Response Teams worldwide, facilitating information sharing and joint responses to cyber threats. The center's public vulnerability notes database serves as a repository of coordinated disclosures, and its open-source tools, such as the CERT UEFI Parser, are used by security researchers internationally.

    The organization maintains a close partnership with the Department of Homeland Security, formalized to enhance national cybersecurity capabilities. In recent years, CERT/CC has issued advisories on significant vulnerabilities, including a hidden backdoor in Tenda routers (CVE-2026-11405) affecting millions of devices, and flaws in Xiaomi earbuds. Its work is regularly covered by major technology outlets, reinforcing its authority in the field. For those tracking the safety of the digital world, CERT/CC remains a cornerstone institution.

    Products & Sub-brands

    Vulnerability Coordination and DisclosureIncident Response CoordinationCERT UEFI ParserOpen-Source Security ToolsTraining and Education

    Frequently Asked Questions

    Who owns the CERT Coordination Center?
    The CERT Coordination Center is owned and operated by the Software Engineering Institute (SEI), a federally funded research and development center at Carnegie Mellon University. It receives its primary funding from U.S. government contracts, particularly from the Department of Defense and Department of Homeland Security.
    Who is the CEO of CERT Coordination Center?
    CERT/CC does not have a CEO in the traditional corporate sense. It is led by the director of the CERT Division at the Software Engineering Institute, who reports to SEI's leadership at Carnegie Mellon University.
    Is CERT/CC still in business?
    Yes, CERT/CC remains fully operational and highly active. As of 2026, it continues to issue critical vulnerability advisories, including the Tenda router backdoor disclosure (CVE-2026-11405) affecting millions of devices and Xiaomi earbud vulnerability warnings, and it released the new CERT UEFI Parser open-source tool in January 2026.
    What is the difference between CERT/CC and US-CERT (CISA)?
    CERT/CC is an academic, federally funded research center at Carnegie Mellon University focused on coordinating vulnerability disclosures across multiple vendors and sectors. US-CERT, now part of the Cybersecurity and Infrastructure Security Agency (CISA), is a U.S. government operational agency focused on protecting federal civilian networks and coordinating national incident response. The two organizations collaborate closely but serve different roles.
    How do I report a vulnerability to CERT/CC?
    Vulnerabilities can be reported through the CERT/CC website (cert.org) using their online vulnerability reporting form. The center also maintains a documented response policy through platforms like HackerOne, which outlines expected timelines and coordination procedures for researchers. CERT/CC prioritizes vulnerabilities affecting multiple vendors or critical infrastructure.

    Keywords

    CERT/CCcomputer emergency response teamvulnerability coordinationincident responsecybersecuritySoftware Engineering InstituteCarnegie MellonCVEopen-source security toolsUEFI parser

    Sources

    Company Info

    Founded
    1988
    Founder
    Software Engineering Institute at Carnegie Mellon University
    Headquarters
    Pittsburgh, Pennsylvania, United States
    Industry
    Cybersecurity
    Parent Company
    Software Engineering Institute, Carnegie Mellon University
    Employees
    200+
    Parent Organization
    Software Engineering Institute, Carnegie Mellon University
    Funding
    U.S. federal government contracts (DoD, DHS)
    Number of Employees
    200+
    Key Initiative
    Vulnerability Notes Database

    Official Website

    www.kb.cert.org/

    Join the community

    fans discussing