The U.S. Cybersecurity and Infrastructure Security Agency (CISA) published on Wednesday a framework for establishing the ‘Quality Era’ of the Common Vulnerabilities and Exposures (CVE) Program. The framework sets out an approach for advancing the program through four areas, including transparent and effective governance, broad and active global participation, robust data infrastructure that supports core CVE operations, and high-quality CVE record content.
Titled ‘CVE Program: Establishing a Quality Era Framework,’ the document describes the Quality Era as the next stage in the CVE Program’s development and focuses on improving the quality of vulnerability information produced by the program. CISA’s framework addresses the program’s governance, participation, infrastructure and record content as interconnected elements needed to support the CVE Program’s continued development.
CISA believes the CVE Program remains an essential public good and that it must work collaboratively across its many global partners to help ensure that the identifier system, validation pathways, and coordination models remain resilient and reliable in a high-volume, AI-accelerated environment.
The nation’s lead cybersecurity agency recognizes emerging challenges of this new era, as automated and artificial intelligence (AI) enabled technologies introduce new pressures across the software lifecycle from development and testing to vulnerability discovery, reporting, coordination, and response. Rising vulnerability volumes further strain triage timelines, coordinated disclosure processes, remediation workflows, and CVE assignment activities.
“As of September 18, over 67,000 new CVEs have been published in 2026 and CVEForecast.org projects that a total of 96,000 new CVEs will be published by the end of the year,” the document detailed. “Additionally, the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) program reported a 263% increase in CVE submissions between 2020 and 2025, with submissions in the first three months of 2026 one third higher than during the same period in 2025.”
The CVE Quality Era framework identifies four dimensions and corresponding potential success metrics. Program governance focuses on transparent and effective CVE Program governance through clear stewardship, structural maturation, representative ecosystem participation and collaborative decision-making. Potential success metrics include the timeliness of governance decisions, the frequency of published governance materials such as policies and updates, the number of conflicts of interest identified and resolved, and external satisfaction or trust indicators such as partner surveys.
Ecosystem participation focuses on broad and active participation across the global software development community. This includes CVE Numbering Authorities (CNAs), Roots, CNAs of Last Resort (CNAs-LR), product suppliers, tool vendors, researchers and governments. Potential success metrics include the number and diversity of active CNAs, Roots and CNAs-LR; participation rates in working groups or community events; the volume and quality of community-submitted feedback; and growth rate of participating organizations across sectors and regions.
Data infrastructure focuses on the systems supporting core CVE operational functions, including CVE ID reservation and CVE Record publication. The framework says these systems should enable quality at scale through robust application programming interfaces (APIs), schemas, validation libraries and cve.org. Potential success metrics include system uptime and reliability, API performance and throughput, validation error frequency, and the time required to deploy schema or platform updates.
CVE Record content focuses on ensuring that CVE Records are complete, accurate, timely and actionable so that cyber defenders and downstream users can rely on them with confidence. Potential success metrics include the percentage of CVE Records meeting defined quality criteria and the rate of corrections or updates required after publication.
CISA’s Strategic Focus on CVE Quality for a Cyber Secure Future identifies six lines of effort for advancing the Quality Era. The workstreams map across four Quality Era dimensions: Program Governance, Data Infrastructure, Ecosystem Participation and CVE Record Content. The framework states that meaningful progress requires coordinated action across the entire CVE ecosystem.
Community Partnerships addresses Program Governance, Ecosystem Participation, and CVE Record Content by fostering collaborative relationships among CVE Numbering Authorities, researchers, and industry stakeholders. Government Sponsorship addresses Program Governance and Data Infrastructure by providing institutional authority and resources to maintain and evolve the CVE infrastructure.
Modernization addresses Program Governance, Data Infrastructure, and CVE Record Content by updating the technical systems and data standards that underpin the CVE ecosystem. Transparency and Communication addresses Program Governance and Ecosystem Participation by establishing clear visibility into CVE program operations and decision-making processes.
Data Quality Improvements address Ecosystem Participation and CVE Record Content by implementing validation workflows and feedback mechanisms that enable systematic refinement of vulnerability records. Improvements in CNA of Last Resort (LR) address Data Infrastructure, Ecosystem Participation, and CVE Record Content by expanding the capacity of the designated backup CNA to ensure comprehensive CVE coverage when original vendors or researchers are unavailable.
The Quality Era requires coordinated progress across CVE Program governance, ecosystem participation, data infrastructure, and CVE Record content. Improvements to CVE Record content rely on clear data requirements, effective tooling, and active CNA participation. Improvements to data infrastructure depend on sustained investment, secure and scalable systems, and feedback from downstream users.
Improvements to ecosystem participation depend on broad representation across the technologies, sectors, regions, and communities the CVE Program serves. Program governance improvements depend on transparent stewardship, structural maturation, collaborative participation, efficiency, and responsiveness to the global vulnerability management community.
These dimensions reinforce one another through interconnected dependencies. Technical modernization can strengthen consistency and scalability, but it cannot replace community engagement, governance maturation, or shared expectations for vulnerability data. Similarly, stronger participation and governance create the foundation for organizations across the ecosystem to adopt technical improvements effectively. The Quality Era is therefore a program-wide maturation effort rather than a single initiative or technology upgrade.
This CVE Quality Era framework broadly explains how CISA’s lines of effort align with the CVE Program’s major quality dimensions. Future CVE Quality Era publications will provide additional details on specific areas of work within this framework.
In the coming months, CISA, in coordination with the CVE Program working groups, plans to publish a blog series on cve.org that will focus on the technology, infrastructure, and data modernization efforts that support quality at scale. The blog series will describe current and planned improvements to the core pieces of infrastructure that support CVE Program operations. These efforts are essential for strengthening consistency, responsiveness, and downstream usability, but they represent only one part of the broader Quality Era portfolio.
The CVE Program working groups have been instrumental to the success of this effort, sustaining the momentum for advancing Quality Era improvements. CISA will continue to engage the CVE community as these efforts advance, including CNAs, Roots, CNAs-LR, researchers, suppliers, governments, vulnerability management vendors, standards bodies, open source communities, and downstream data consumers. Ongoing feedback will help ensure CVE Quality Era efforts continue to align with the needs of the global cybersecurity community.


