“CISA remains committed to leading, growing and sustaining the CVE Program into the foreseeable future, just as we’ve done for more than 25 years without fail,” said Chris Butera, acting executive assistant director for cybersecurity.
CISA’s “Quality Era” and why it matters
The Cybersecurity and Infrastructure Security Agency published a white paper outlining a move from what it calls a “Growth Era” into a planned “Quality Era” for the Common Vulnerabilities and Exposures (CVE) program. The paper sets out steps intended to raise the accuracy, consistency and usefulness of CVE records — the canonical catalog many organizations rely on to identify software and product vulnerabilities.
CISA framed the white paper as part of a program-wide maturation effort informed by feedback from the CVE community, and the agency invited further comment on the plan. The document is presented as a follow-on to an earlier strategy paper on the program’s future.
Scale, pressure and sources of error
The white paper places the move toward quality against a backdrop of rapidly rising volume. Over 67,000 new CVEs had been published in 2026 as of last week, and the National Institute of Standards and Technology National Vulnerability Database program recorded a 263% increase in CVE submissions between 2020 and 2025. The paper explicitly names artificial intelligence as a factor that has “furthered the rise.”
CISA warned that while faster discovery and reporting can improve the value of vulnerability information when records are complete and actionable, the same acceleration “can expose gaps in processes, tooling, coordination, and accountability — especially when the quality of the submissions is uneven.”

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadFour dimensions of data quality
To address those gaps, the white paper proposes improving CVE data quality across four key dimensions: transparent and effective program governance; broad and active participation across the global software community; data infrastructure that supports CVE operational functions; and reliable CVE record content. The agency presents those dimensions as interconnected levers to make records more usable for downstream consumers.
Expert reactions: cautious support and pointed criticisms
Reactions from vulnerability experts quoted in CyberScoop were mixed: some praised the goals while expressing skepticism about elements of the plan and the pace of change.
- Brian Fox, Sonatype’s co-founder and chief technology officer, welcomed the candid recognition of long-standing problems. He said incomplete or inconsistent records “create real downstream work for the security tools, developers, and organizations trying to determine whether they’re actually affected and what to do next.” He added, “I’ll believe we’ve entered a ‘Quality Era’ when we can see the improvement in the actual data and in the decisions that data enables.”
- Tom Alrich, who leads the OWASP PURL Expansion Working Group, argued the white paper overlooks a core operational problem: “that a huge and growing percentage of new CVE records don’t contain a machine-readable software identifier.” He said he supported the paper’s items but warned they would not address that central shortfall.
- Caitlin Condon, VulnCheck’s vice president of security research, said CISA and the CVE program are well-positioned to define and enforce standards that make “quality” explicit. However, she framed the white paper as a foundation rather than a complete framework, noting many of the proposed success metrics “can be measured today, but simply aren’t shared publicly.” She urged more transparency on current metrics and clearer reasoning for why chosen measures are the right ones.
What this means for technologists, policymakers, and enterprises
- Technologists and security teams: expect continued operational friction until record content becomes more consistent. As Brian Fox noted, incomplete records create downstream work for tools and developers trying to determine exposure and remediation steps.
- Policymakers and program stewards: the white paper arrives amid questions about stewardship and resources. Some experts have asked whether other organizations should assume responsibility for the CVE program given reported budget cuts at CISA; the agency has instead invited community feedback and offered the white paper as a path to stronger governance.
- Enterprises and procurement leaders: the surge in published CVEs — more than 67,000 so far in 2026 — and the rise in submissions to the NVD highlight a growing data-management challenge. The proposed focus on machine-readable identifiers, infrastructure, and shared metrics would directly affect how organizations automate vulnerability assessments and prioritize fixes.
The white paper frames quality as an ecosystem problem — governance, participation, infrastructure and record content must all improve for CVE data to be reliably actionable. CISA has opened the proposal to community input, and experts say success will be judged not by the paper itself but by measurable improvements in record accuracy, completeness and usability — and by whether the program publishes the metrics needed to demonstrate that progress.
Source: CyberScoop — CISA outlines improvement plan for CVE program



