generated: '2026-09-04' method: searched probe: false source: https://www.bd.com/en-us/about-bd/cybersecurity?active-tab=4 url: https://www.bd.com/en-us/about-bd/cybersecurity description: >- BD runs a published Coordinated Vulnerability Disclosure (CVD) program out of the BD Cybersecurity Trust Center. BD states it accepts reports of potential cybersecurity concerns from security researchers, customers, third-party component vendors and other external groups, and describes a three-stage process — Report, Evaluate, Disclose. BD is authorized as a CVE Numbering Authority (CNA) by the CVE Program, and prepares coordinated disclosures in tandem with CISA; the resulting advisories are published to the BD Cybersecurity Trust Center and to CISA's ICS medical advisories, and shared with the Health Information Sharing and Analysis Center (H-ISAC). BD serves no /.well-known/security.txt (see well-known/becton-dickinson-well-known.yml) — the intake channel is a web form ("Report an issue" / cybersecurity issue report form) on the Trust Center page rather than an RFC 9116 document. No bug bounty program, no PGP key, no published response-time SLA and no explicit safe-harbor language were found on the provider's own pages. program: published: true type: coordinated-vulnerability-disclosure cna: true cna_note: >- BD is authorized as a CVE Numbering Authority by the CVE Program and assigns CVE IDs for its own products. bug_bounty: false safe_harbor: unstated pgp_key: none-found sla: unstated security_txt: false policy: - https://www.bd.com/en-us/about-bd/cybersecurity?active-tab=4 contact: - kind: web-form label: Cybersecurity issue report form ("Report an issue") url: https://www.bd.com/en-us/about-bd/cybersecurity note: >- Form-based intake linked from the Trust Center; BD does not expose a direct form URL or a dedicated security mailbox on the public page. General support intake is https://www.bd.com/en-us/support/contact-us. disclosure_channels: - name: BD Cybersecurity Trust Center — Bulletins and Patches url: https://www.bd.com/en-us/about-bd/cybersecurity?active-tab=3 note: BD-published security bulletins and patch guidance for its products. - name: CISA ICS medical advisories url: https://www.cisa.gov/news-events/ics-medical-advisories note: >- BD coordinates public disclosures with CISA; e.g. ICSMA-24-352-01 (BD Diagnostic Solutions products) was published there in coordination with BD. - name: Health Information Sharing and Analysis Center (H-ISAC) note: BD states it shares coordinated vulnerability disclosures with H-ISAC for reach. - name: BD Product Security Annual Report url: https://www.bd.com/content/dam/bd-assets/bd-com/en-us/document/cybersecurity/report-guide-and-templates/BD-2023-Product-Security-Annual-Report_EN.pdf note: Annual public report on BD's product security methodology and disclosure practice. evidence: - source: https://www.bd.com/en-us/about-bd/cybersecurity?active-tab=4 http_status: 200 fetched: '2026-09-04' keywords: [coordinated vulnerability disclosure, report, evaluate, disclose, CVE Numbering Authority, CISA] - source: https://www.bd.com/en-us/about-bd/cybersecurity http_status: 200 fetched: '2026-09-04' keywords: [report an issue, cybersecurity issue report form, trust center] - source: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-352-01 fetched: '2026-09-04' note: Example of a BD-coordinated public advisory. maintainers: - FN: Kin Lane email: kin@apievangelist.com