PUBLICATION

CVE Program: Establishing a Quality Era Framework

Publish Date

The Common Vulnerabilities and Exposures (CVE) Program is the global standard for identifying and cataloging publicly disclosed cybersecurity vulnerabilities. Through a collaborative, federated model and strong community engagement the program has grown to support the timely identification and documentation of vulnerabilities relied upon by organizations globally. 

CVE Program: Establishing a New Quality Era Framework describes how the program is advancing quality across four key dimensions: program governance, ecosystem participation, data infrastructure, and CVE record content, which builds upon the strategic priorities outlined in CISA’s Strategic Focus on CVE Quality for a Cyber Secure Future . Together, these efforts support CISA’s vision for a more resilient, transparent, and sustainable vulnerability management ecosystem while working to ensure CVE data remains accurate, actionable, and responsive to an evolving landscape. This framework reflects CISA’s continued commitment to community partnership, program modernization, transparency, and stewardship of the CVE Program.