CISA Outlines Future of CVE Program with Focus on Quality
CISA has published a whitepaper detailing four 'dimensions of quality' to enhance the CVE program, aiming to improve vulnerability cataloging and characterization amidst growing volume.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released a whitepaper outlining a strategic vision for the future of the Common Vulnerabilities and Exposures (CVE) program. Titled "Dimensions of Quality," the document details four key areas CISA will focus on to improve the program, which is crucial for cataloging and characterizing newly discovered software vulnerabilities.
The initiative comes at a critical juncture for the CVE program, which has faced uncertainty regarding its long-term funding and operational stability since the Trump administration nearly ended its contract with Mitre. The increasing volume of disclosed vulnerabilities, exacerbated by the rise of AI-driven vulnerability discovery, known as the 'vulnpocalypse,' has intensified the need for program enhancements. Forecasts predict a significant surge in CVEs recognized this year, potentially accounting for nearly a quarter of all CVEs reported since the program's inception.
CISA's whitepaper emphasizes four core "dimensions of quality": Program governance, ecosystem participation, data infrastructure, and CVE record content. This framework aims to ensure the reliability, responsiveness, and overall quality of vulnerability data disseminated through the CVE system. The agency is stepping up to address the escalating volume challenge, seeking to maintain the program's status as a trusted global public good for cybersecurity defenders.
While the whitepaper does not explicitly mention resource allocation, experts like Katie Moussouris, CEO of Luta Security, expressed optimism, stating that CISA is focused on maintaining the program and that internal cases for necessary resources have likely been made. She believes that Congress will act to ensure CISA has adequate funding to manage its responsibilities.
However, some industry observers have expressed concerns about the whitepaper's specificity. Adrian Sanabria, founder of the Defenders Initiative, noted that the document lacks concrete details on how CISA will fundamentally change its approach. He argued that simply doing "more of what we're already doing" is insufficient given the backlog of unenriched CVEs and the challenges in managing them effectively.
A key area of concern for Sanabria is the enrichment of CVE data, which includes providing Common Vulnerability Severity Scores (CVSS). Currently, only about one in five vulnerabilities receive this enrichment, a process vital for most vulnerability management platforms. The lack of consistent enrichment and varying severity scores from different organizations, including emerging efforts in Europe, presents a significant challenge for accurate vulnerability prioritization.
CISA's move towards a "quality era" for CVE signifies a commitment to improving the program's robustness and utility. The focus on governance and ecosystem participation aims to foster better collaboration among the numerous organizations involved in allocating and enriching CVEs. Enhancements to data infrastructure and record content are expected to improve the consistency and reliability of vulnerability information, addressing issues like differing CVSS scores for the same vulnerability.
The "Dimensions of Quality" whitepaper represents CISA's latest effort to adapt the CVE program to the evolving threat landscape. By focusing on these four dimensions, CISA aims to ensure that the CVE system remains a cornerstone of global cybersecurity efforts, providing timely and accurate information to help organizations defend against increasingly sophisticated threats.
While CISA's white paper outlines a commitment to a "Quality Era" for the CVE program, some experts express skepticism about its tangible impact. Specifically, concerns remain regarding the program's ability to address the critical issue of machine-readable identifiers and whether the proposed improvements will translate into genuinely actionable data for downstream security efforts. Experts like Brian Fox of Sonatype noted that they will only believe in the "Quality Era" when improvements in the actual data and the decisions it enables are evident.