Mandate
SCA Sudan exists to safeguard the digital integrity of the Sudanese state and its citizens. The Authority sets national cybersecurity policy, supervises critical-information-infrastructure protection, runs the national CERT (SD-CERT), and represents Sudan in international cyber forums.
This bug-bounty & vulnerability-disclosure platform is one of the Authority's operational instruments — it gives the country a single accountable place where security researchers can report issues and organizations can receive them under a shared legal and procedural framework.
Legal basis
The Authority operates under national cybersecurity legislation. Within that framework, the platform provides a national safe-harbor for researchers performing good-faith security testing in line with each program's published policy, the global ISO/IEC 29147 coordinated disclosure norm, and the terms summarised on the policy page.
Reports filed through this platform are treated as a privileged communication channel. Researchers acting in good faith and within scope are not pursued civilly or criminally for activities that this framework authorises.
The four pillars
Protect
Defend Sudan's critical national information infrastructure across telecom, banking, energy, government, defence-adjacent, transport and health sectors.
Detect
Operate national threat-intelligence and incident-detection capabilities through SD-CERT and partner sectoral CSIRTs.
Respond
Coordinate national-level incident response, run this CVD platform, manage public advisories, and convene cross-sector incident coordination.
Build
Develop national cyber capability through workforce training, research partnerships, and international cooperation with OIC-CERT, AfricaCERT, ITU and ITU-D.
Structure
The platform sits within SCA Sudan's Operations Directorate, in coordination with SD-CERT (national CERT) and the Legal Affairs office. Day-to-day operations are handled by a small SCA staff team — visible inside the platform as the NCArealm — which has cross-tenant visibility into queues, SLAs, registrations and audit trails. SCA staff never see the contents of in-flight reports between a researcher and an organization unless explicitly escalated.
Participating organizations
Public-facing programs come from Sudanese government agencies, state-owned enterprises, banks, telecom operators, energy utilities, and major private companies. Each onboarded organization is reviewed by SCA Sudan staff before its program goes live.
See the live list at /programs.
Public advisories
When a vulnerability affects multiple Sudanese organizations or carries systemic risk, SCA Sudan publishes a coordinated advisory crediting the original reporting researcher (with their consent) and describing the fix. Advisories are linked from the platform at /advisories.