# Disclosure Timing Cannot Serve as a Proxy for Exploitation Onset

- **Artifact ID:** CHQ-ASC-2026-005
- **Version:** v1.0
- **Status:** Canonical
- **Public record:** https://record.cybersecurityhq.com/constraints/chq-asc-2026-005
- **Machine-record SHA-256:** `5332b74f4ede5893393d00fb4b1d88a5ff292025c251fb0034a1a9fc3f55513c`

## Complete structured record

```json
{
  "id": "CHQ-ASC-2026-005",
  "legacy_ids": [
    "CHQ-ACJ-2026-005"
  ],
  "title": "Disclosure Timing Cannot Serve as a Proxy for Exploitation Onset",
  "version": "v1.0",
  "issued": "2026-04-07",
  "status": "Canonical",
  "doctrine_class": "Anticipatory Structural Constraint",
  "precedent": [
    "CHQ-ASC-2026-001",
    "CHQ-ASC-2026-002"
  ],
  "purpose": "This Anticipatory Structural Constraint establishes the governing principle for evaluating governance claims, remediation programs, and risk reporting that treat vulnerability disclosure as the boundary condition for exploitation exposure.\n\nSecurity programs that use CVE publication, KEV catalog addition, or vendor advisory issuance as the event that initiates the defender response window are making a structural assumption that the available evidence does not support. This constraint defines the interpretive boundary for all CHQ governance artifacts that address remediation timing, exploitation onset, and pre-disclosure exposure.",
  "core_judgment": "Remediation scheduling, risk prioritization, and governance reporting that treat vulnerability disclosure as the start of the exploitation window are operating on an assumption the evidence does not consistently support. In a material fraction of confirmed exploitation events, exploitation precedes public disclosure by days to weeks. The exposure window is defined by the gap between attacker exploitation onset and public defender awareness, not by CVE publication, KEV catalog addition, or vendor advisory issuance.\n\nThe disclosure event does not create the risk. It reveals risk that may already exist in the environment. Security programs without a documented response model for pre-disclosure exploitation windows are operating with an unaddressed structural gap regardless of patch velocity.\n\nPrompt patching is necessary. It is not sufficient when exploitation precedes the availability of the patch. These are different conditions with different governance implications.",
  "derivation_intro": "This constraint derives from prior canonical constraints and observed structural conditions:",
  "derivation": [
    "From CHQ-ASC-2026-001: Threat model scope is determined by attacker capability, not defender awareness. Exploitation that precedes disclosure is within attacker capability scope regardless of institutional signal availability.",
    "From CHQ-ASC-2026-002: Contemporaneous evidence is the basis of knowledge. Absence of disclosure is not evidence of non-exploitation. It is evidence only of non-disclosure.",
    "VulnCheck 2025 exploitation data: 28.96% of Known Exploited Vulnerabilities showed evidence of exploitation on or before the day their CVE was published, an increase from 23.6% in 2024.",
    "Mandiant M-Trends 2026: Mean time to exploit reached negative seven days within the engaged breach response caseload, indicating exploitation before patch availability is a statistical norm in confirmed breach cases, not an exception.",
    "Cisco FMC CVE-2026-20131: Amazon MadPot sensor infrastructure confirmed Interlock ransomware exploitation beginning January 26, 2026, 36 days before Cisco public disclosure on March 4, 2026.",
    "FortiClient EMS CVE-2026-35616: watchTowr honeypot infrastructure recorded exploitation from March 31, 2026, approximately 7 days before Fortinet public disclosure and CISA KEV addition on April 6, 2026."
  ],
  "scope_governs": [
    "Governance assertions about the adequacy of patch-based remediation programs for internet-facing infrastructure",
    "Risk reporting that uses CVE publication date as the boundary condition for exposure window calculation",
    "Prioritization frameworks that treat KEV catalog absence as evidence of non-exploitation",
    "Any CHQ Position, analysis, or assessment evaluating remediation timing relative to exploitation onset",
    "Board and regulatory reporting claims that reference disclosure-based timelines as evidence of remediation discipline"
  ],
  "scope_does_not_govern": [
    "The design of specific vulnerability management or patch management programs",
    "Vendor disclosure practices or coordinated vulnerability disclosure program design",
    "CVE publication processes or KEV catalog methodology",
    "Whether any specific organization's patching velocity is adequate given its environment"
  ],
  "relationship_to_derived": "CHQ Positions applying this constraint to specific architectures, technologies, or deployment contexts inherit its authority but do not inherit its permanence. Position-specific conclusions may change as exploitation evidence evolves. This constraint does not.\n\nCHQ-SM-2026-013 (Exploitation Timing Is Structurally Independent of Disclosure Timing) derives directly from this constraint and documents the evidential basis in detail. CHQ-SC-2026-006 (Exploitation Timing Precedes Defender Awareness) is the structural condition this constraint governs.",
  "irreversibility_statement": "This constraint contains no retirement triggers.\n\nIt may be superseded only by a successor Anticipatory Structural Constraint demonstrating that exploitation timing has become reliably posterior to disclosure across the confirmed KEV population, sustained over a minimum of three consecutive annual measurement periods. A reduction in the pre-disclosure exploitation fraction does not supersede this constraint if the fraction remains material. Regulatory improvement in disclosure timelines, vendor commitment to earlier disclosure, or changes in vendor disclosure practices are not grounds for supersession.",
  "boundary_of_application": [
    "Assign liability for governance failures in organizations with disclosure-based programs",
    "Prescribe specific pre-disclosure detection or response architectures",
    "Replace regulatory or legal compliance requirements governing disclosure timelines",
    "Address the accuracy, completeness, or timeliness of any specific threat intelligence source",
    "Establish that any specific vulnerability was exploited before disclosure in any specific environment"
  ],
  "attestation": "This constraint reflects CHQ's position that vulnerability disclosure is not a reliable proxy for exploitation onset, and that governance assertions about remediation adequacy based on disclosure-aligned timelines cannot be structurally substantiated. Security governance must treat the pre-disclosure exploitation window as an operating condition requiring a documented response model, not an edge case requiring no response until public confirmation.",
  "pdf_hash": "45c4ec200c2b366339332f007c4d24888ebf843507c39fdea90a761e81c9ffb0",
  "unresolved_conflicts": [
    {
      "date": "2026-09-22",
      "description": "The canonical constraint records Cisco FMC disclosure as March 4, 2026, while ED-2026-013 records March 3, 2026; the 36-day interval from January 26 supports March 3. The source date remains unverified.",
      "sources": [
        "CHQ-ASC-2026-005",
        "CHQ-ED-2026-013"
      ],
      "status": "UNRESOLVED"
    }
  ],
  "derived_artifacts": [
    "CHQ-SM-2026-013",
    "CHQ-SC-2026-006",
    "SC-2026-006 criterion v2.0",
    "CHQ-SM-2026-017",
    "CHQ-SM-2026-018"
  ],
  "classification_scope": "EXTERNAL_INTERPRETIVE",
  "classification_resolution": "This constraint governs interpretation of an external structural condition.",
  "lifecycle_governance": {
    "error_correction": "A clerical, citation, date, identifier, or transcription error may be corrected only by a dated erratum that identifies the prior text, corrected text, evidence for the correction, affected hash, and whether meaning changed. Meaning-changing corrections are amendments, not errata.",
    "amendment": "A constraint may be amended only by a ratified, versioned amendment that preserves the prior version, states the changed proposition and rationale, recomputes the canonical hash, and notifies registered reliance. An amendment may clarify or narrow a constraint but may not silently replace its core judgment.",
    "successor": "A constraint may be superseded only by a separately identified successor that cites the predecessor, satisfies the predecessor's stated supersession test, states the exact proposition displaced, and records the effective transition. Prior versions remain historical and ineligible for new reliance after supersession.",
    "permanence": "Permanent means no automatic expiry or retirement trigger. It does not mean immune from demonstrated error, transparent amendment, or a successor that satisfies the canonical supersession test."
  },
  "governance_amendments": [
    {
      "date": "2026-09-22",
      "effective_version": "v1.0",
      "amendment_id": "CHQ-ASC-TEMPLATE-2026-001",
      "description": "Successor and reassessment language normalized as explicit artifact-governance metadata; individual canonical supersession tests remain controlling.",
      "canonical_hash_effect": "UNCHANGED"
    },
    {
      "date": "2026-09-22",
      "effective_version": "v1.0",
      "amendment_id": "CHQ-PRS-2026-001-AMD-003",
      "description": "Class-wide error-correction, amendment, successor, and permanence semantics ratified as non-canonical governance metadata. ASC-006's internal-adjudication classification is formally resolved without changing its canonical constraint text.",
      "canonical_hash_effect": "UNCHANGED"
    }
  ]
}
```
