Planned NDAA amendment would codify CISA’s role in cyber vulnerability program
Sanu biswas/Getty Images
ByDavid DiMolfetta,
Cybersecurity Reporter, Nextgov/FCW
June 18, 2026 03:52 PM ET
The measure, expected as a proposed add-on to the government’s 2027 defense package, targets a bedrock cybersecurity vulnerability-tracking system after a contracting fiasco last year.
A contracting scare that briefly cast uncertainty over a key cyber vulnerability-tracking program is prompting lawmakers to add a measure to the annual defense authorization bill that would establish the program within the Cybersecurity and Infrastructure Security Agency.
The proposal would formally house the Common Vulnerabilities and Exposures program under CISA, require a joint modernization plan with the National Institute of Standards and Technology and push officials to improve the public vulnerability data used by agencies, companies and security researchers to assess cyber risk, according to the text of the planned amendment viewed by Nextgov/FCW.
CVE provides a standardized methodology for logging publicly known...
Copyright of this story solely belongs to nextgov.com. To see the full text click HERE