Sudan Cybersecurity Authority

Sudan's national channel for bug bounty & vulnerability disclosure.

Report security issues in government services, critical infrastructure, telecoms, and major Sudanese companies through one trusted channel. Coordinated by SCA Sudan under a unified national safe-harbor framework.

0
Active programs
0
Registered organizations
0
Researchers
Why this platform exists

A single, accountable place to disclose security issues in Sudan.

Built and operated by SCA Sudan to give researchers a clear way to help, give organizations a way to receive help safely, and give the country a single source of truth on its cyber risk posture.

One national channel

No more guessing where to report. Every Sudanese government service, telecom, bank, and critical-infrastructure operator runs its program from the same trusted platform โ€” visible side by side at /programs.

Legal safe-harbor

Good-faith research that follows the program policy is shielded from prosecution under Sudan's coordinated disclosure framework. No surprise lawsuits, no chilling effect on legitimate testing.

Coordinated disclosure

Reports flow through a structured state machine: intake โ†’ triage โ†’ reproduction โ†’ fix validation โ†’ reward โ†’ public advisory. Both sides see the same status, with full audit history.

For researchers

Find issues. Earn recognition. Stay legal.

  • Clear scope, response SLAs, and disclosure timelines on every program.
  • Encrypted intake with attachment scanning and end-to-end audit trail.
  • Hall-of-Fame credit and optional rewards (bounty programs).
  • Multi-factor sign-in. Safe-harbor for good-faith research.
Create a researcher account
For organizations

Run a national-grade VDP or bug bounty.

  • Editable policy templates, in/out-of-scope assets, branded program page.
  • Triage workflow built around the global ISO/IEC 29147 disclosure norm.
  • VDP (no reward) or BBP (with reward bands in SDG, USD, EUR or USDT).
  • Per-tenant RBAC, full audit, optional invitation-only privacy.
Onboard your organization
For government & CNI

National visibility into cyber risk.

  • SCA Sudan staff get cross-tenant visibility, audit, and incident escalation.
  • Aggregate metrics by sector (telecom, banking, government, energy, transport).
  • Coordinated advisory publication for systemic issues.
  • Aligns with national cybersecurity strategy and CNI protection mandate.
About the operator
How it works

From submission to public advisory in four stages.

Every report carries an audit chain. Both researcher and organization see the same state at the same time. SCA Sudan oversees timelines and escalates where SLAs slip.

  1. 1

    Researcher submits

    Pick a program, review scope and policy, file a report with reproducible steps and impact statement.

  2. 2

    Triage & reproduce

    Organization confirms the vulnerability, sets the final severity, and assigns an engineer.

  3. 3

    Fix & validate

    Engineer ships the fix, validator confirms remediation, optional reward is decided per band.

  4. 4

    Coordinated disclosure

    After the fix, SCA Sudan and the program publish a public advisory crediting the researcher.

About the operator

Sudan Cybersecurity Authority

SCA Sudan is the federal body responsible for cybersecurity policy, critical-infrastructure protection, and national incident response. The Authority operates this platform as part of its mandate to provide a unified, accountable channel for coordinated vulnerability disclosure across the Republic.

Read more about SCA Sudan

Protect

Defend Sudan's critical national information infrastructure across telecom, energy, finance, government and transport.

Detect

Operate national threat-intelligence and incident-detection capabilities through SD-CERT and partner agencies.

Respond

Coordinate national-level incident response, including this CVD platform, alongside sectoral CSIRTs.

Build

Develop national cyber capability through workforce, research, and partnerships with OIC-CERT, AfricaCERT, and ITU.

Safe-harbor

Good-faith research is welcome and legally protected.

Authorised under each program's policy
Coordinated, non-public disclosure timeline
No civil or criminal action for compliant research
No DoS, no PII exfiltration, no third-party data
No social engineering of NCA or org staff
No public disclosure before agreed timeline ends
FAQ

Common questions

Who can submit a vulnerability report?โ–พ

Anyone โ€” a Sudanese national or an international researcher. You need to register a researcher account and verify your email. National ID is collected for Sudanese citizens to enable reward payouts; international researchers can submit reports without disclosing national ID.

Is there always a financial reward?โ–พ

Not always. Programs choose between a Vulnerability Disclosure Program (VDP) โ€” recognition and Hall of Fame credit only โ€” or a Bug Bounty Program (BBP) with monetary rewards. The badge on each program card tells you which is which.

Will I get in legal trouble for testing?โ–พ

Not if you follow the program policy and the national safe-harbor terms: stay in scope, don't exfiltrate sensitive data, don't cause downtime, don't share the bug publicly before coordinated disclosure. SCA Sudan recognises this platform as the lawful channel for good-faith research.

What if the organization ignores my report?โ–พ

Every report has SLAs visible to both sides. If an organization misses its acknowledgement or response window, SCA Sudan staff can escalate. After the agreed disclosure window โ€” typically 90 days โ€” researchers may request coordinated public disclosure even without the org's consent.

Can my organization run a private (invite-only) program?โ–พ

Yes. Programs can be Public (listed for all researchers) or Private (invite-only). Sensitive sectors โ€” banking, government IDs, defence-adjacent โ€” typically start private and graduate to public over time.

How is severity determined?โ–พ

Researchers provide their own estimate. The organization sets the final severity during triage, optionally with a CVSS v3.1 vector. The program's severity cap on each asset (if set) bounds the final score for that asset.

Report a vulnerability

Pick a program, read its policy, and file a report with reproducible steps. Your submission is encrypted in transit and at rest.

Run a program

Onboard your organization, define scope and policy, and start receiving coordinated reports from Sudan's researcher community.