Skip to content

Security1 publisher2 min readPublished

CISA moves the CVE program's stated priority from volume to data quality

CISA's white paper for a "Quality Era" in the CVE program is open for community feedback. The vulnerability researchers CyberScoop asked about it support the aim and say it leaves out the identifiers and the published metrics that would prove it.

The Watch · Security desk

Illustration accompanying CISA moves the CVE program's stated priority from volume to data quality

What happened

  • CISA published a white paper on Wednesday setting out how it intends to improve the CVE program, the clearinghouse the industry treats as definitive for vulnerability data.
  • The plan names four dimensions of data quality: program governance, participation across the global software community, data infrastructure for CVE operational functions, and reliable record content.
  • More than 67,000 new CVEs had been published in 2026 as of last week, the volume CISA says its existing processes are now absorbing.
  • The program reached the point last year where a contract for it nearly ended before a last-minute reprieve.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint On Condon's reading the document is not yet a framework, so nothing about it changes what a CNA must file, and triage teams have no new required fields and no compliance date to plan for.
  • decision Teams that match CVE records to installed software keep paying for their own product identifier mapping, because Alrich says the plan leaves the missing machine-readable identifier untouched.
  • exposure Budget cuts keep CISA's stewardship in play, and every scanner, SBOM workflow and advisory pipeline that treats CVE IDs as stable infrastructure inherits that funding risk.

Tom Alrich, who leads the OWASP PURL Expansion Working Group on Product URLs for commercial software, was blunt about how much of the document he agrees with [15]. "I support everything mentioned. I also support the flag, motherhood and apple pie," he said [16]. His objection is narrow and operational: "However, nothing in there is going to affect the CVE program's most important problem: that a huge and growing percentage of new CVE records don't contain a machine-readable software identifier" [17].

The paper itself acknowledges the load. "These pressures intensify quality challenges across the CVE ecosystem," it states [11]. NIST's National Vulnerability Database saw a 263% increase in CVE submissions between 2020 and 2025 [5], which is roughly 3.6 times the 2020 count [23]. CISA says artificial intelligence has furthered the rise [6].

Brian Fox, Sonatype's co-founder and chief technology officer, described the cost of a thin record to CyberScoop: "Incomplete or inconsistent records create real downstream work for the security tools, developers, and organizations trying to determine whether they're actually affected and what to do next" [13]. He is waiting on evidence. "I'll believe we've entered a 'Quality Era' when we can see the improvement in the actual data and in the decisions that data enables," Fox said [14].

The governance question behind this has a recent history. Some vulnerability experts have asked whether other organizations should take over CISA's stewardship of the program, given budget cuts at the agency [21]. Chris Butera, CISA's acting executive assistant director for cybersecurity, said the agency "remains committed to leading, growing and sustaining the CVE Program into the foreseeable future, just as we've done for more than 25 years without fail" [8]. He invited further feedback on the paper, which follows an earlier strategy document on the program's future [10].

Caitlin Condon, VulnCheck's vice president of security research, said CISA and the program are "well-positioned to both observe challenges in this space and to create (and enforce) standards that explicitly state what 'quality' means in CVE records" [18]. She also said the document is the basis for a future framework and not yet a full-fledged one [19]. "Many of the potential success metrics suggested in the document can be measured today, but simply aren't shared publicly," Condon said [20].

What to watch

  • Whether the next iteration publishes current CVE quality metrics and the reasoning behind them, which Condon asked for.
  • Whether a machine-readable software identifier becomes a required field for CNA submissions rather than a recommendation.
  • Whether the stewardship argument moves from commentary to a formal proposal to move the program out of CISA.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories