supply-chaintrade-pressNewsThe Broadside1 min read

Zero-knowledge proofs could crack the SCRI-sharing liability deadlock

The math works (FDD just proved it across three live environments) but no agency has even begun writing zero-knowledge proofs into a reporting rule.


TL;DR

A cryptographic technique called zero-knowledge proofs could let critical-infrastructure operators prove they're exposed to a specific vulnerability without disclosing software inventories, network diagrams, or scan data. FDD's Center on Cyber and Technology Innovation recently validated the approach in a proof-of-concept that tested 38 known vulnerabilities across three operational environments, only the proofs and yes/no answers left the premises. The math works. What doesn't exist yet is the regulatory infrastructure to make a zero-knowledge proof satisfy a CIRCIA reporting obligation or a compliance finding.

The core problem isn't new. CISA's ICT Supply Chain Risk Management Task Force spent years documenting it: companies won't share supply chain risk information because doing so exposes them to defamation claims, trade-secret misappropriation suits, and breach-of-contract actions, among other liability vectors. The Task Force's 2021 report on liability protections acknowledged that the most actionable SCRI (vulnerability data, software inventories, configuration details) is the data companies are least willing to hand over.

Zero-knowledge proofs offer a technical path around the liability problem rather than through it. Instead of asking Congress to expand Safe Harbor protections (again), the approach lets a company prove the answer to a specific question ("is CVE-2025-XXXX present in your operational environment?") without ever transmitting the underlying scan data. The math is real, not aspirational. FDD's Center on Cyber and Technology Innovation ran a proof-of-concept across three operational environments, testing yes-or-no queries against 38 known vulnerabilities. Only the proofs and answers left the premises. The test confirmed the approach works and surfaced how widespread each vulnerability was.

What it doesn't do, yet, is answer the question compliance directors actually need answered: can a regulator accept a zero-knowledge proof as satisfying a reporting obligation? That requires standards bodies to define acceptable proof schemas, agencies to write them into rules, and auditors to be trained on verification, none of which has started. The gap between "this math works" and "this satisfies CISA's CIRCIA reporting requirements" is measured in years, not months. Structured pilots are the right next step, but the history of cryptographic adoption in federal compliance programs suggests cautious timelines are warranted.


Published ·Deep Fathom