CISA maps CVE program's Quality Era in new white paper
The framework names four dimensions of quality, but the most persistent complaint (missing machine-readable software identifiers in CVE records) didn't make the page.
TL;DR
CISA released a white paper Wednesday outlining how it plans to move the Common Vulnerabilities and Exposures program from a "Growth Era" into a "Quality Era." The paper (which follows a September 2025 strategy document) defines quality across four dimensions: program governance, ecosystem participation, data infrastructure, and CVE record content. Over 67,000 CVEs have been published so far in 2026, and NIST's National Vulnerability Database has seen a 263% increase in submissions since 2020. CISA is soliciting community feedback on the framework.
The white paper arrives roughly a year after the CVE program nearly lost its funding, an 11-month contract extension in April 2025 averted a shutdown, but the close call rattled defenders and opened a conversation about whether CISA should remain the program's steward. That question isn't settled, but this paper and its predecessor make clear that CISA intends to stay in the role.
The diagnosis is straightforward: the volume is breaking the process. CISA reports that CVEForecast.org projects 96,000 new CVEs by year-end. AI-enabled tooling is accelerating discovery and submission, but the same acceleration exposes gaps in triage, coordination, and accountability when the records coming in are incomplete or inconsistent. The four-dimension framework is CISA's answer, governance, participation, infrastructure, and content treated as interconnected rather than siloed problems.
Some vulnerability experts who spoke to CyberScoop were supportive in principle but unconvinced the paper goes far enough. Brian Fox, CTO of Sonatype, said he'd "believe we've entered a 'Quality Era' when we can see the improvement in the actual data." Tom Alrich, who leads the OWASP PURL Expansion Working Group, noted that the paper doesn't address what he called the CVE program's most important problem: "a huge and growing percentage of new CVE records don't contain a machine-readable software identifier." VulnCheck's Caitlin Condon observed that many of the potential success metrics in the document could be measured today but aren't shared publicly.
CISA has invited community feedback on the white paper. Whether the next step is an implementation plan, revised metrics, or another framing document will likely depend on what that feedback looks like.
Published ·Deep Fathom