The most compelling evidence in a cybersecurity career is usually the evidence that cannot be taken out of the building. A zero-day discovery held under wraps. An intrusion discovered without it getting into the news. Detection code running inside the security operations center of a bank, unattributed to anyone.
Such work does exist and is often unpublished, which is why EB-1A petitions of cybersecurity experts fail just like academic EB-1A petitions fail. The officer is not asking for any doubts about the work being carried out; rather, the officer is asking for something that the applicant cannot provide. How does one resolve this dilemma?
The middle ground between the two ends of the statement “USCIS has shut EB-1A down” on the one hand, and “anyone with a LinkedIn badge can get one” on the other, is where the truth is hidden by the numbers. With EB1A Experts passing 330 in terms of number of approved extraordinary ability petitions at the same time there is a rise in USCIS approval numbers up to the year 2026, the truth has become clear.
Thus, the goal posts haven’t moved; the burden of proof has. Here’s how that plays out if you are planning to submit your application this year.
Why Cybersecurity Evidence Breaks the Template
The basic narrative depends on a literature base that is self-referential. Aggressive scientists will sign NDAs, incident responders will work by client-confidentiality guidelines, and cleared individuals will find out that their best research will never be documented.
Two ways of failing to do the job properly exist. The first one refers to the way in which, in petitions, it is not the artifact, but the assertion that substitutes for the “critical breach response” in question, while the engagement is not mentioned at all. The second one refers to the fact that, in petitions, petitioners use the company’s reputation instead of their own contribution, since it provides the lion’s share of Requests for Evidence.
Cyber Evidence by USCIS Criterion
The petitioners must meet three out of ten regulatory requirements or have an internationally renowned award. Meeting the requirements does not make one eligible because USCIS evaluates the entire record.
| Criterion | Verifiable Cybersecurity Evidence |
| Original contributions | CVE assignments with CVSS severity, documented vendor patching, MITRE ATT&CK contributions, adopted Sigma or YARA rules |
| Judging others’ work | CFP review boards (USENIX Security, ACM CCS, Black Hat), CVE Numbering Authority roles, peer review |
| Scholarly authorship | Peer-reviewed papers at IEEE S&P, ACM CCS or NDSS, with citations |
| Awards | Pwnie Awards, Pwn2Own placements, CERT commendations, bug bounty standing |
| Membership | IEEE Senior or Fellow grade, ACM Distinguished Member, standing program committees |
| Published material about you | Named trade press coverage about the researcher, not only the vulnerability |
| Leading or critical role | CISO, principal architect, or incident commander, with the organization’s distinction independently evidenced |
| High salary | BLS wage percentiles for SOC 15-1212, Information Security Analysts |
CISSP, OSCP, and CEH are all exam-based certifications and not memberships based on superior performance. Listing them under this standard is asking for trouble.
The Milestone By The Numbers
| Metric | Data Point |
| EB1A Experts approvals | 330+ |
| E11 approval rate, Q1 FY2026 | 47.5% |
| E11 approvals / denials, Q1 FY2026 | 2,180 / 2,414 |
| E11 approval rate, Q4 FY2025 | 53.4% |
| E11 approval rate, FY2025 | 66.9% |
| I-140 premium processing fee | $2,965, effective March 1, 2026 |
| Premium processing window | 15 business days |
| Governing framework | Two-step Kazarian analysis, still in effect |
The approval rates pertain to the cases that have been finalised, not the ones that have yet to be heard, so it’s not a success rate in the total number of filings. Verify the fees using the USCIS Fee Schedule before submitting the application.
What the 2026 Data Actually Shows
Approvals declined from 66.9% during fiscal year 2025 to 53.4% in Q4 of fiscal year 2025 and then to 47.5% in Q1 of fiscal year 2026. More denials than approvals are seen amongst decided cases; therefore, the claim about upward trend in EB-1A approvals is baseless.
It is the change from number to verifiable support. The eight verifiable pieces of evidence about a petitioner’s contribution will beat eighty that will repeat the same unsupported claim. The RFEs are increasingly focusing on composition of the panel and the criticality of the role.
Where Mukherji v. Miller Stands
On January 28, 2026, Mukherji v. Miller ruled from the District of Nebraska that the two-step final merits test was never properly adopted and granted the petition for approval. USCIS filed an appeal, but withdrew it on June 10. On June 16, the Administrative Appeals Office ruled against the Mukherji argument in another case.
The decision is binding on one party, there is no appellate precedent, and USCIS continues to use the final merits test. Any 2026 plan relying on the idea that the test has been abolished rests on a misunderstanding.
What Sits Behind a 330+ Track Record
It is four or five, not three. When a hurdle is overcome using margin, it minimises the impact on the case if the decision-maker ignores one of the categories, and this is the reason why marginal cases fail.
Independent confirmation. The supervisors verify the accomplishment; third parties with no financial interest verify the importance. It is far more important for an independent party to verify the fact that a disclosure resulted in an out-of-cycle patch.
Ongoing rather than historic recognition. USCIS often dismisses accomplishments that are older than five years unless there has been an ongoing impact via deployment, citation, or licensing.
Implementation. Implementation turns an accomplishment into an achievement of major significance, i.e., lower incident costs, improved audit posture, better user protection.
Does Your Profession Affect Your Odds?
No, not directly. The USCIS does not release any list of approved professions in ranking order, nor is there any evidence anywhere that researchers do better than founders and engineers do better than athletes.
| Profession | Strongest Evidence Types |
| Researchers | Citations, publications, peer review, patents |
| Founders and creators | Media coverage, audience metrics, commercial outcomes |
| Athletes | Rankings, awards, competition records |
| Technology professionals | Patents, open-source adoption, licensing deals |
| Cybersecurity professionals | CVE records, committee service, adopted tooling, incident and audit data |
Depending on the position you hold within the realm of security, the evidence keeps shifting from researcher to CVE, cloud architect to scale of deployment, and GRC professional to standards development. Your position is what dictates your evidence and not your success.
EB1A Experts has helped secure over 330 EB-1A petitions approved in the fields of research, technology, cybersecurity, entrepreneurship, and the arts. All satisfied the criteria outlined in 8 CFR 204.5(h)(3) and the Kazarian merits analysis test. There are no statistics available from USCIS on firm level, hence this figure is firm-reported and cannot be compared with the USCIS approval rate. The firm still continues to track the trends post-Mukherji and adjusts the Evidence Strategy based on field.
The year 2026 does not punish the EB-1A petitions. It punishes those petitions that require an adjudicator to take the applicant’s word for granted, which is exactly what an NDA will leave a security expert.
The solution does not lie in a detailed dossier. The solution lies in that part of your dossier which never knew anything about confidentiality – the CVE attached to your name, the program committee that invited you, the advisory that recognised your discovery, the out-of-cycle patch from the vendor that came because of your efforts. The problem does not lie in there being a hole in the wall; the problem lies in whether you fit through it or not.





