Department of Justice Announces New Policy for Charging Cases under the Computer Fraud and Abuse Act
- Document
- 19 May 2022
- Event
- 19 May 2022
- Retrieved
- 16 September 2026
What the document says
On 19 May 2022, the Department of Justice announced a revised policy for charging cases under the Computer Fraud and Abuse Act, the main federal computer-hacking statute. For the first time, the policy directs federal prosecutors not to charge good-faith security research. It defines that term narrowly: accessing a computer solely to test, investigate or correct a security flaw, carried out in a way designed to avoid harm to individuals or the public, with findings used primarily to promote the security of the affected systems or their users. The policy also lists conduct it says should never have been charged in the first place, such as violating a website's terms of service by using a pseudonym, checking sports scores at work, or embellishing an online dating profile. The Justice Manual section on computer fraud now incorporates this standard, directing that a prosecutor should decline a case where the evidence shows good-faith research and the defendant intended it as such.
Confidence and limits
This is a Justice Department policy statement about how it will exercise prosecutorial discretion, not a change to the statute itself and not a court ruling. Congress did not amend the CFAA, and the policy states plainly that it does not bind future administrations or protect anyone from state computer-crime laws, which can differ from the federal standard. Reporting at the time noted the policy followed a Supreme Court decision the year before that had already narrowed what counts as exceeding authorized access; this article does not evaluate that ruling itself, only the department's stated response to it.
Why it mattered
Security researchers had long argued that the CFAA's broad, decades-old language left them exposed to federal charges for work that ultimately improved security, since the statute does not distinguish a researcher probing a system to report a flaw from someone probing it to exploit one. The policy does not resolve that ambiguity in the law, but it commits the department that decides which CFAA cases to bring to a specific, written test before doing so, and it puts researchers on notice that authorization still matters: the policy explicitly says claiming to do research is not a defense for someone acting in bad faith, such as extorting a system's owner over a discovered flaw.
Defensive takeaway
If your organization commissions or receives unsolicited security research, put a written authorization or safe-harbor scope in place before testing begins, since the department's good-faith standard turns on intent and manner, not on the researcher's after-the-fact explanation.
- Does your vulnerability disclosure policy state clearly what testing is authorized, matching what a researcher would reasonably expect from good-faith conduct?
- Would your organization treat an unsolicited report the same way regardless of the policy discussed here?
- Have you checked whether your state's own computer-crime law tracks the federal standard, given the policy does not bind state prosecutors?
The policy narrows one source of legal risk for researchers acting in good faith without removing it entirely, and it leaves the underlying statute exactly as Congress wrote it in 1986, available to a future administration to interpret differently.
Put a written authorization or safe-harbor scope in place before any security testing begins, since the policy's protection turns on documented good-faith intent, not on an after-the-fact explanation.
The DOJ press release and Justice Manual language are the department's own statements of policy; they do not change the underlying statute, do not bind future administrations, and do not affect state computer-crime laws.
Sources & reading trail
The DOJ's own announcement and definition of good-faith security research, and examples of conduct it says should not be charged.
government-primary · Source published: 19 May 2022 · Retrieved: 16 September 2026
The current Justice Manual language directing prosecutors to decline charging good-faith security research and defining the term.
government-primary · Source published: Not established · Retrieved: 16 September 2026
Corroborates the announcement date, quotes the Deputy Attorney General, and notes the policy's non-binding, administration-dependent status.
reputable-original-reporting · Source published: 19 May 2022 · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.