SCAP support for SSVC metrics in vulnerability reporting and management

15 views
Skip to first unread message

Vijay S Sarvepalli

unread,
Jul 16, 2026, 3:57:47 PMJul 16
to scap...@list.nist.gov, sc...@nist.gov
Hello SCAP Community,
I would like to start a discussion about adding support for Stakeholder-Specific Vulnerability Categorization (SSVC) as a recognized metric within SCAP.
With the recent publication of CISA Binding Operational Directive (BOD) 26-04, vulnerability prioritization is moving beyond severity alone and toward risk-informed decision making. The directive explicitly prioritizes remediation using factors such as known exploitation, public exposure, automatability, and technical impact—concepts that are naturally represented by the SSVC decision model.
At the same time, SCAP 1.4 currently includes support for metrics such as CVSS and CCSS, but not SSVC. As SCAP continues to evolve as the standard for machine-readable security automation and vulnerability information, it seems like an appropriate time to consider whether SSVC should become part of the ecosystem.
SSVC has seen growing adoption within the CVE ecosystem and by organizations that need actionable prioritization rather than severity scoring alone. It complements CVSS by helping organizations answer "What should I do next?" instead of only "How severe is this vulnerability?"
Some potential benefits of adding SSVC support to SCAP include:
  • Standardized machine-readable exchange of SSVC decision points and outcomes.
  • Better alignment between SCAP content and modern vulnerability management practices.
  • Support for organizations implementing BOD 26-04-style prioritization and similar risk-based remediation processes.
  • Improved interoperability between vulnerability management tools that already consume SCAP content and those beginning to use SSVC.
The SSVC project already provides well-defined decision models, schemas, and tooling that could serve as a starting point:
If an XML representation or SCAP-specific schema extensions are needed, I believe the SSVC community would be interested in collaborating on reference schemas, tooling, and validation support to help integrate SSVC cleanly into the SCAP ecosystem.
I'd be interested in hearing the community's thoughts on whether this would be a worthwhile direction for a future revision or extension of SCAP. If there is interest, I'd also be happy to participate in discussions around requirements, schema design, and interoperability considerations.
Thank you for your consideration, and I look forward to the discussion. I have opened an issue in SSVC GitHub where SCAP community that is interested can add relevant content too - https://github.com/CERTCC/SSVC/issues/1209 
Best regards,
Vijay Sarvepalli
Principal Engineer
CERT/CC Software Engineering Institute 
Carnegie Mellon University 

Prisaca, Dragos (Fed)

unread,
Jul 20, 2026, 1:00:06 PM (11 days ago) Jul 20
to Vijay S Sarvepalli, SCAP-DEV, SCAP

Hi Vijay,

 

Thanks for raising this. CVSS and CISA-SSVC do answer different questions - "how bad is it" vs "what do I do about it" - and exchanging that second one in a machine-readable way is worth a look.

 

A few things to consider before treating it as a SCAP metric:

- Where does the decision belong? A CISA-SSVC outcome is tied to a stakeholder and a moment in time, while a CVSS base vector on a CVE is more general but carries no context. As an aside, getting to a final CISA-SSVC outcome requires answering the "Mission Prevalence" input for each affected asset.

- Which SSVC? SSVC has multiple possible instantiations, the most well-known likely being CISA-SSVC.

- How do we reuse? If it does move forward, prefer starting from SSVC's existing models and schemas rather than rebuilding them.

 

We put CVSS, SSVC, and EPSS side by side on a severity panel at our recent CPE workshop (Jono Spring covered SSVC), so there's some shared ground here already. Glad to join the requirements and interoperability discussion, and I'll look at the GitHub issue.

 

Thanks,

//Dragos.

 

Best regards,

Dragos Prisaca

Computer Scientist | NIST Technical Lead, CPE specifications

National Institute of Standards and Technology

dragos....@nist.gov

 

From: Vijay S Sarvepalli <vssarv...@cert.org>
Sent: Thursday, July 16, 2026 3:58 PM
To: SCAP-DEV <scap...@list.nist.gov>; SCAP <sc...@nist.gov>
Subject: [EXTERNAL] SCAP support for SSVC metrics in vulnerability reporting and management

 

Some people who received this message don't often get email from vssarv...@cert.org. Learn why this is important

Vijay S Sarvepalli

unread,
Jul 20, 2026, 3:58:55 PM (11 days ago) Jul 20
to Prisaca, Dragos (Fed), SCAP-DEV, SCAP
Hello Dragos,

For your questions:

1. Where does the decision belong? A CISA-SSVC outcome is tied to a stakeholder and a moment in time, while a CVSS base vector on a CVE is more general but carries no context. As an aside, getting to a final CISA-SSVC outcome requires answering the "Mission Prevalence" input for each affected asset.

2. Which SSVC? SSVC has multiple possible instantiations, the most well-known likely being CISA-SSVC.


  • I would say CISA's specifically BOD-26-04 is the most relevant in SCAP scenarios. If the BOD focused decision points have been evaluated with best available information of the asset, they can be further narrowed down if needed to more specificity for information that may be missing when doing the SCAP scans.

3. How do we reuse? If it does move forward, prefer starting from SSVC's existing models and schemas rather than rebuilding them.




Let me know how we can support adoption or inclusion of such metrics. If you have already supported CVSS, this should hopefully be even easier. 


Vijay Sarvepalli
Principal Engineer
CERT/CC Software Engineering Institute 
Carnegie Mellon University 


From: Prisaca, Dragos (Fed) <dragos....@nist.gov>
Sent: Monday, July 20, 2026 12:59 PM
To: Vijay S Sarvepalli <vssarv...@cert.org>; SCAP-DEV <scap...@list.nist.gov>; SCAP <sc...@nist.gov>
Subject: RE: [EXTERNAL] SCAP support for SSVC metrics in vulnerability reporting and management
 
Warning: External Sender - do not click links or open attachments unless you recognize the sender and know the content is safe.

Prisaca, Dragos (Fed)

unread,
Jul 21, 2026, 5:41:47 PM (10 days ago) Jul 21
to Vijay S Sarvepalli, SCAP-DEV, SCAP

Hi Vijay,

 

Thanks for the detailed follow-up - the BOD 26-04 framing and the schema links are helpful.

A good part of our team is out over the next couple of weeks, so rather than give you a rushed answer I'd like to wait until everyone's back before we respond properly. Figure early August.

Appreciate your patience.

 

Thanks,

//Dragos.

 

Best regards,

Dragos Prisaca

Computer Scientist | NIST Technical Lead, CPE specifications

National Institute of Standards and Technology

dragos....@nist.gov

 

From: Vijay S Sarvepalli <vssarv...@cert.org>
Sent: Monday, July 20, 2026 3:59 PM
To: Prisaca, Dragos (Fed) <dragos....@nist.gov>; SCAP-DEV <scap...@list.nist.gov>; SCAP <sc...@nist.gov>
Subject: Re: [EXTERNAL] SCAP support for SSVC metrics in vulnerability reporting and management

 

You don't often get email from vssarv...@cert.org. Learn why this is important

Reply all
Reply to author
Forward
0 new messages