cisatrade-pressNewsThe Broadside3 min read

CISA to Congress: don’t lock the CVE program in statute

The vulnerability-tracking backbone that 530 CNAs depend on needs formal recognition, but rigid legislative design rules could break what AI and international partners are already reshaping.


TL;DR

CISA’s vulnerability response branch chief told Black Hat that statutory recognition for the CVE Program is welcome, but legislation that dictates how the program operates could cripple its ability to adapt. The caution follows a June amendment from Reps. Ramirez and Whitesides that would codify CVE in DHS, establish a 15-member board, and require a NIST-CISA modernization plan. The amendment died in the House Rules Committee. CISA hasn’t opposed it, but Cerkovnik warned that overly prescriptive rules would collide with a program already absorbing AI-driven vulnerability discovery and pressure to bring international partners (ENISA among them) into formal governance roles.

CISA wants the CVE Program in statute. It doesn't want Congress to tell it how to run the thing.

Lindsey Cerkovnik, branch chief for vulnerability response and coordination at CISA, told Black Hat on Thursday that "defining the importance of the program in legislation in general seems like a very helpful thing." The remark was directed at a proposal from Reps. Delia Ramirez (D-Ill.) and George Whitesides (D-Calif.) that would codify the Common Vulnerabilities and Exposures Program within DHS and hand CISA a formal statutory mandate as its federal steward.

That's the piece CISA can live with. The other piece (prescribing how the program must operate) is where Cerkovnik drew a line.

"When you overdefine how to execute the thing, it can make it very restrictive and difficult," she said. The program runs on a federated model: CISA sponsors it, MITRE operates the infrastructure under contract, and more than 530 CVE Numbering Authorities (software vendors, national cybersecurity agencies, research groups) assign identifiers and publish records within their scopes. That structure has absorbed decades of growth. It isn't obvious that a legislative operating manual would make it better.

The Ramirez-Whitesides amendment, reported by Nextgov/FCW in June, would establish a 15-member CVE board with permanent seats for CISA, NIST, and top-level CVE authorities, plus rotating industry, academic, researcher, and foreign-government members. It would also require a modernization plan from CISA and NIST. The House Rules Committee didn't select it for floor consideration, so it never got a vote.

What changed since the contracting scare

The legislative push traces back to April 2025, when MITRE warned that federal funding for CVE was about to lapse. CISA extended the contract within hours and later called it a "contract administration issue," not a funding gap. The episode still rattled the community. It exposed how much of the world's vulnerability-tracking infrastructure depended on a single U.S. government contract, a fragility the EU's cybersecurity agency, ENISA, has since signaled it wants to help address.

CISA has been publicly working the international angle since at least September 2025, when Nick Andersen, then executive assistant director for cybersecurity, said the agency wanted ENISA and other partners to have "ownership" and a "seat at the table." That's the direction the program is moving. Cerkovnik's Black Hat remarks suggest CISA doesn't want Congress to preempt that evolution by writing the 2025 org chart into law.

AI is coming for the pipeline

The other variable is AI-driven vulnerability discovery. Cerkovnik pointed to a recently announced AI research effort (the details are still emerging) as a signal that the volume and nature of incoming CVEs may change faster than the program's current processes were designed to handle. A modernization plan makes sense. A modernization plan written by Congress in 2026 and baked into statute might not.

None of this means CISA opposes the amendment. Cerkovnik's framing was careful: formal recognition good, operational straitjacket bad. But the amendment is dead for now, and the program's trajectory (toward international co-governance and AI-era throughput) is already in motion regardless.

For practitioners, nothing changes Monday. The CVE Program continues operating as it has for 26 years: MITRE under a CISA contract, CNAs assigning IDs, defenders reading the feed. The legislative fight is about what happens when that 26-year run of no-lapse operations hits a stressor that a contract extension can't fix.


Published ·Deep Fathom

CISA to Congress: don’t lock the CVE program in statute — The Broadside