Spider on keyboard showing CVE program

CISA Outlines Future Vision for CVE Program With Plans for Funding and Improved Vulnerability Prioritization

A new strategic roadmap from CISA may calm some nerves as regards the future of its widely-used CVE program, as the organization has indicated it has plans for funding beyond the program’s current 2026 deadline. The plan also outlines enhancements to the program, such as better identification and prioritization of the most immediate software threats and additional participation by an assortment of security researchers and open-source experts from around the globe.

CISA signals confidence about not just continued existence of CVE program, but ability to expand

The future of the CVE program has been in question since the election of the Trump administration, which went on to slash CISA funding and put the program in immediate jeopardy. MITRE Corp. was able to exercise a contractual clause in April of this year that guaranteed it 11 more months of funding, but with no commitments or known alternative sources beyond March 2026. The agency had said that at minimum the existing database would continue to be available via GitHub, but without funding there would cease to be further entries.

Though CISA points out plans for growth, it also frames its strategy as a transition from its “Growth Era” to its “Quality Era.” The contrast is framed as the prior era being the agency’s collection of 460 CVE Numbering Authorities (CNAs) worldwide, and the upcoming era focusing on modernization, data quality improvements and improved communications and transparency to include a greater deal of community feedback.

That does not rule out future expansion, of course. The program’s future growth will focus on better representation of “international organizations and governments, academia, vulnerability tool providers, data consumers, security researchers, operational technology, and open-source communities.” And though “diversified funding” sources have been discussed for months, the program is also seeking new sources of government sponsorship.

CVE program declares privatization is not the path forward

The CVE program plan is thin on details about alternate funding sources at this point, other than indicating some confidence about them being available and noting that new government relationships are being pursued. That does not necessarily remove the possibility of renewed US funding, though Trump has had a frosty relationship with CISA as of late. But the roadmap does declare that privatization of the program is “not the answer” and reaffirms that CVE data must remain free and openly accessible as a public good.

The change in CISA focus also comes with the appointment of new executive assistant director Nick Andersen, who was formerly in charge of the Energy Department’s cybersecurity during the first Trump administration. Andersen made comments at the recent Billington Cyber Conference that signaled intent to get new US funding in place for the program, calling the present near-lapse a “workflow issue” with contract paperwork and adding that there was never any “demonstrated intent” to not continue funding the CVE program.

MITRE and its CVE board have already made moves toward greater independence from the US, however, founding the CVE Foundation to transform the CVE program into a separate entity with non-profit status opening it up to a mix of public and private funding sources going forward. Andersen’s comments seemed to indicate that CISA’s future plans are at odds with this direction, with the agency concerned about the national security implications of looping in private funding partners. MITRE Corp. has issued some comments expressing a preference for the prior US funding model (under the US Department of Homeland Security through CISA’s National Cyber Security Division) to be restored.

Though it was far from the only reason for creating the project, CISA’s “Vulnrichment” program was initiated in mid-2024 during rumblings of the prospect of the CVE program being defunded under a future Trump administration. The program was formed as an attempt to bolster NIST’s efforts, which was already struggling with funding and being swamped in a backlog of cataloging work at the time. The primary focus of Vulnrichment is better prioritization of the most dangerous vulnerabilities by assigning them to one of four categories that suggests the immediacy with which they should be acted upon. The project is hosted on GitHub and loops in members of the public to assist in more quickly making these determinations so that very serious vulnerabilities can be identified and remediated faster.

Though Trump has had poor personal relations with CISA in recent years, the recent comments by the agency and its heads indicate that the administration at minimum at least views its defense functions as vital and that it seems likely that new funding for the CVE program will be figured out ahead of the early 2026 deadline.

Patrick Garrity, Security Researcher at VulnCheck, offers some insight from an insider position and sees this as a greatly increased likelihood that CISA will take over the program going forward: “The CVE program roadmap is a good starting point and underscores the need for reform across the program. There are plenty of opportunities for improvement across areas that have presented persistent challenges, such as transparency, communication, responsiveness, timely execution and collaboration. CISA directly acknowledges the transparency and communication issues long cited by participants, and the commitment to milestone reporting, regular dialogue and expanding engagement beyond traditional software suppliers is critical to bridging trust gaps within the community. The emphasis to include security researchers, academia, open-source communities and international partners helps address the need for better responsiveness, data enrichment across CVE records and reinforces the importance of accountability.”

“CISA’s admission that it must take a more active role in the long-term stewardship of the program also indicates the organization may assume the secretariat role in administering the program, and governance could shift to direct government oversight. This further illustrates the value of expanding public-private partnerships and forging strong community relationships. This includes Vulnrichment, which has been critical in filling gaps left by NIST NVD,” added Garrity.