logo

CVE, Congress, and the NDAA: A merge story

ID: 717a12c3-35c8-521f-91be-d16cf67279b5

STIX ID: report--717a12c3-35c8-521f-91be-d16cf67279b5

Feed Name: runZero Blog

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: todb

...
...

This article explains Amendment 812 to the FY2027 NDAA that would formally place the CVE program under CISA, create a capped CVE Board with appointed rotating and permanent members, authorize multi-year funding, and require a joint 10-year modernization plan for CVE and the NVD; it outlines benefits (improved governance and data quality) and risks (U.S. control may prompt international fragmentation) and urges technical stakeholders to engage with Congress while the language is still being negotiated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.