What is SSVC?
Stakeholder-Specific Vulnerability Categorization: a decision-tree method that turns a few facts about a vulnerability into an action, such as Track, Attend or Act.
Instead of one number, SSVC asks questions with a small set of answers: is it being exploited (none, proof of concept, active), can exploitation be automated (yes, no), what is the technical impact (partial, total), and how much it matters to the mission and to public well-being. CISA's version maps the answers to four outcomes: Track, Track*, Attend and Act.
CISA's Vulnrichment programme adds exploitation, automatable and technical-impact values to many CVE records, and BOD 26-04 uses those values to set federal deadlines.
Sources
Related terms
- BOD 26-04CISA Binding Operational Directive 26-04, "Prioritizing Security Updates Based on Risk" (10 June 2026), which replaced BOD 22-01's flat KEV deadlines with risk-based timelines.
- EPSSExploit Prediction Scoring System: FIRST's daily estimate of the probability (0 to 1) that a CVE will see exploitation activity in the next 30 days.
- CVSSCommon Vulnerability Scoring System: FIRST's standard 0.0–10.0 score for how severe a vulnerability is, based on how it can be exploited and what it affects.