Developer docs
API playgroundTry for free, no card

Search company profiles

CVE Foundation

Full company profile

uuid0036lu5

Namestring
CVE Foundation
Legal namestring
CVE Foundation
Company typeenum
Private
Founded yearint
2025
Descriptiontext

The CVE Foundation is a 501(c)(3) nonprofit incorporated in Washington State on April 16, 2025, established by a coalition of longtime CVE Board members to ensure the long-term sustainability, independence, and global governance of the Common Vulnerabilities and Exposures (CVE) Program. The Foundation does not own the CVE Program outright but serves as a supporting entity working alongside CISA and MITRE to transition the program from a single US-government-funded model to a diversified, multi-stakeholder nonprofit model. It serves the global cybersecurity ecosystem including technology vendors, security product companies, governmental CERTs, security researchers, operational defenders, and 453 CVE Numbering Authorities (CNAs) across 40 countries.

The Foundation's core technical product is the modernized CVE.org platform and its surrounding infrastructure: a cloud-native CNA Directory with REST APIs and webhooks, an Issue Management System for CNA-to-CNA coordination, a planned NVD-like microservices API (REST, GraphQL, Model Context Protocol), a CSAF v2.1 export pipeline, a Federated CPE Dictionary System, and VEX integration. AI features in development include a RAG-enabled LLM chatbot for CNA identification, AI-assisted CVSS/CWE scoring within Vulnogram, and AI-driven CPE entity recognition. These products collectively target improvements in data quality, CNA productivity, scalability, and alignment with the EU Cyber Resilience Act.

The Foundation's business model is that of a nonprofit funded through philanthropic contributions, grants from foundations and government entities, corporate sponsorships, individual/organizational donations, and a planned long-term endowment fund. The CVE Program itself is distributed as a free global public good with no commercial pricing. Distribution is entirely digital and self-serve via CVE.org and APIs. Customer concentration is therefore not a traditional revenue risk; rather, the strategic risk is funding concentration, which the Foundation is explicitly working to diversify following the April 2025 funding crisis that prompted its formation.

Short descriptiontext

CVE Foundation is a 501(c)(3) nonprofit established in April 2025 to support the sustainability, independence, and global governance of the Common Vulnerabilities and Exposures (CVE) Program. It serves technology vendors, security product companies, governmental CERTs, researchers, defenders, and 453 CNAs across 40 countries by modernizing CVE.org infrastructure and diversifying program funding.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
11–50
akta.pro rankint
HeadquartersWashington, United States
HQ citystring
Washington
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Offices6 records

Each record includes

City, Country, Type, Description, Source

Keyword5 values
vulnerability identification, cybersecurity standards, vulnerability management, nonprofit foundation, CVE program
Industry1 code
1Bug Bounty, Vulnerability Disclosure & Security Services
CodeFSAPAJALPrimaryYes
NAICS code3 codes
  • Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services5182
  • Computer Systems Design and Related Services54151
  • Custom Computer Programming Services541511
SIC code3 codes
  • Services-Prepackaged Software7372
  • Services-Computer Integrated Systems Design7373
  • Services-Computer Programming, Data Processing, Etc.7370
Product category
Cybersecurity Vulnerability Identification Standards
GTM motion1 record

Each record includes

Type, Description, Source

Revenue model4 records
1Philanthropic Contributions and Grants
TypeLicensing Royalties
Description

Seeking contributions from foundations that support technological advancement and cybersecurity initiatives. Grants from foundations and government entities to support program operations and development.

2Corporate Sponsorships
TypeLicensing Royalties
Description

Sponsorships from commercial entities that benefit from CVE data for their operations, contributing financially to the Program's sustainability.

3Donations
TypeLicensing Royalties
Description

Individual and organizational donations to support the nonprofit mission of ensuring CVE stability and independence.

4Endowment Fund
TypeManaged Services
Description

Long-term endowment fund providing financial bedrock to ensure operations continue regardless of external economic fluctuations.

Marketing channels7 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels3 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Personnel, Technology or R&D, Infrastructure, Operations, Marketing or Sales
Pricing details1 tier
1Free public access to CVE identifiers and records
ModelOtherBilling cadenceMonthly
Notes

CVE Program provides free, publicly available vulnerability identifiers and records. No pricing for the core service as it is a nonprofit public good.

GTM typeB2B
B2B
Offering typeSoftware
Software
Core offering1 text field

The CVE Foundation supports the sustainability and independence of the CVE Program—a globally recognized system for identifying and describing publicly disclosed cybersecurity vulnerabilities—through diversified funding and community engagement. It develops and operates infrastructure services including a CNA Directory with REST APIs, an Issue Management System, a RAG-enabled LLM CNA Identification Chatbot, an NVD-Like API for CVE.org, AI-enhanced Vulnogram tooling, a CSAF export pipeline, a Federated CPE Dictionary, and VEX integration capabilities. All CVE identifiers and records are provided free of charge to the global cybersecurity community.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 3 values shown
  • Enables organizations to reliably assess which vulnerabilities affect them and how well their tools cover those risks
+2 more records
Product overview1 text field

The CVE Foundation is developing a platform of infrastructure services to modernize and sustain the CVE Program. The core offerings include: the CNA Directory (cloud-native repository with REST APIs and webhooks for CNA information management), an Issue Management System (ticketing system for CNA coordination), a LLM-based CNA Identification Chatbot (RAG-enabled AI for product-to-CNA matching), and an NVD-Like API for CVE.org (microservices-based API with REST/GraphQL/MCP interfaces). Supporting tools include enhanced Vulnogram (AI-assisted CVE record creation), CSAF Export Pipeline (automated CSAF v2.1 conversion), Federated CPE Dictionary System (decentralized CPE maintenance with AI), and VEX Integration (real-time vulnerability status updates). These products collectively address CVE enrichment, scalability, data quality, and international coordination challenges while aligning with EU Cyber Resilience Act requirements.

Product and service8 records
1CNA Directory
CategoryPlatform
Description

Cloud-native repository of CVE Numbering Authority (CNA) details including scope definitions and contact information, exposing scalable REST APIs that support creation, updating, and removal of CNAs and Roots, plus webhooks for event-driven notifications of CNA changes. Built for global CVE program participants and integrators.

2Issue Management System
CategoryPlatform
Description

Ticketing system supporting CNA-to-CNA and CVE stakeholder-to-CNA coordination for resolving post-disclosure disputed CVEs and duplicate assignments with greater transparency and integration into third-party workflows such as GitHub.

3CNA Identification Chatbot
CategoryAI Product
Description

RAG-enabled LLM-based chatbot that identifies CNAs scoped for given products based on natural language product name queries, providing relevant scope details to assist security researchers in routing vulnerability assignments.

4NVD-Like API for CVE.org
CategoryAPI Product
Description

Microservices-based API for CVE.org with standardized query interfaces including REST, GraphQL, and Model Context Protocol, exposing CVE data as a data lake for cloud service consumption with legacy API backward compatibility planned.

5Vulnogram Enhancement with LLM Technology
CategoryTool
Description

AI integration into the Vulnogram tool enabling CNAs to create higher-quality enriched CVE records through automated vulnerability scoring (CVSS), CWE assignment, and affected product associations (CPE) with interactive feedback mechanisms.

6CSAF Export Pipeline
CategoryAPI Product
Description

Automated continuous export pipeline that converts CVE.org data into Common Security Advisory Framework (CSAF) v2.1 format with structured JSON-based formatting for seamless integration with third-party security platforms.

7Federated CPE Dictionary System
CategoryPlatform
Description

Decentralized mechanism for maintaining the Common Platform Enumeration (CPE) dictionary through federated contributions from CNAs and designated cybersecurity organizations, augmented by AI-driven entity recognition for standardized CPE definitions.

8VEX Integration on CVE.org
CategoryPlatform
Description

Vulnerability Applicability and Status (VEX) capability inline on CVE.org that allows CNAs to contribute real-time vulnerability status updates for open-source CVEs through the VEX framework.

Scale indicator3 records

Each record includes

Type, Value, Description, Source

Partnership8 partners
Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2025-04-25
Description

MITRE operates the CVE Program under contract with the US government. Following the April 2025 funding crisis, MITRE has been in discussions with the CVE Foundation about program continuity and future collaboration. The Foundation is committed to building strong, transparent relationships with MITRE.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2025-04-23
Description

CISA is the primary US government sponsor of the CVE Program. The CVE Foundation is working to maintain a strong partnership with CISA to support the CISA ICS Root and the MITRE-run CNA of last resort functions while helping expand the program globally. CISA has expressed commitment to actively seeking community feedback and fostering inclusivity in CVE stewardship.

Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2024-01-01
Description

ENISA operates the European Union Vulnerability Database (EUVD) as a CNA since January 2024. ENISA issues both EU-specific IDs and CVE IDs, extending and complementing the global CVE ecosystem with regionally relevant intelligence. The CVE Foundation intends to continue and expand partnerships with EU organizations.

4CVE Numbering Authorities (CNAs)
Strategic tierCoreTypeOthers
Description

The CVE Program includes 453 CNAs from 40 countries that assign CVE IDs and add CVE records. CNAs are the lifeblood of CVE and the Foundation is deepening engagement with CNAs, Roots, and community contributors to elevate their voices and increase their role in shaping the program.

Strategic tierMajorTypeStrategic or Co-development Partner
Description

NIST manages the National Vulnerability Database (NVD) which enriches CVE records with CVSS scores, CWE taxonomy, and CPE product coverage. The CVE Foundation is collaborating with NVD to become an Authorized Data Provider (ADP) and integrate historical vulnerability data into CVE.org.

Strategic tierMajorTypeStrategic or Co-development Partner
Description

FIRST provides interoperable scoring standards including CVSS and EPSS that work with CVE data. The CVE Foundation works with FIRST to enable security professionals to communicate clearly, assess risk consistently, and act swiftly based on CVE data.

Strategic tierMajorTypeStrategic or Co-development Partner
Description

The Center for Cybersecurity Policy and Law created a CVE primer whitepaper to raise awareness about challenges facing the CVE Program including governance, transparency, and funding. Kent Landfield serves as a Fellow for the Center, and the Foundation works closely on policy discourse.

8The CVE Board
Strategic tierCoreTypeStrategic or Co-development Partner
Description

The CVE Board provides governance oversight of the CVE Program. Multiple CVE Board members formed the CVE Foundation to transition CVE to a nonprofit model with diversified funding. The Foundation aims to evolve the Board into a more inclusive, globally coordinated governance structure.

Recent move7 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeOthers
Description

Largest nonprofit stewarding open-source infrastructure, including hosting OpenSSF. Comparable as a mature nonprofit model for funding and governing critical technology infrastructure used globally.

TypeOthers
Description

Nonprofit that supports open-source software projects and infrastructure through community-driven governance. Comparable as a nonprofit stewarding critical technology infrastructure with a sponsorship-driven funding model.

TypeDirect peer
Description

Operates the EU Vulnerability Database (EUVD) and became a CVE Numbering Authority in January 2024. Directly comparable as a regional vulnerability database operator and CNA extending the CVE ecosystem across Europe.

TypeOthers
Description

Nonprofit organization providing cybersecurity best practices, certifications, and standards. Comparable as a nonprofit cybersecurity standards body with a similar membership and corporate sponsorship funding model.

TypeEmerging player
Description

Nonprofit that supports open-source cybersecurity resources including vulnerability catalogs and tooling. Comparable as a nonprofit stewarding critical cybersecurity infrastructure with a similar community-led, donation-and-sponsorship-driven funding model.

TypeEmerging player
Description

Cross-industry initiative hosted by the Linux Foundation focused on improving open source software security. Comparable as a nonprofit consortium coordinating cybersecurity tooling, standards, and funding across vendors and foundations.

TypeDirect peer
Description

Manages the NVD, the primary enrichment layer for CVE records with CVSS, CWE, and CPE data. Directly comparable as a major CVE ecosystem participant that the Foundation is collaborating with to integrate historical vulnerability data.

TypeDirect peer
Description

Operates the CVE Program under US government contract and is the current program operator whose relationship with the Foundation determines the Foundation's role. Directly comparable as the operational backbone for global vulnerability identification that the Foundation was created to support.

TypeBroad incumbent
Description

Global standards body for incident response that maintains CVSS and EPSS scoring frameworks used alongside CVE. Comparable as a related cybersecurity standards organization with an overlapping stakeholder community and Peter Allor as a leader in FIRST PSIRT SIG.

TypeOthers
Description

Nonprofit that operates Let's Encrypt and Prossimo, providing free internet security infrastructure as a public good. Comparable as a nonprofit operating critical security infrastructure on a free, donor-funded model.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat6 records

Each record includes

Type, Details

Key risks6 records

Each record includes

Headline, Details, Source

Key highlights6 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers4 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment6 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile4 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
Yes

Docs URL, Description

Integration2 records

Each record includes

Title, Type, Description, Source

AI capability6 records

Each record includes

Type, Description, Source

AI maturity
App detail

Has app

Feature5 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles5 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
No data
Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

CVE Foundation

Cybersecurity Vulnerability Identification Standardsthecvefoundation.org

CVE Foundation is a 501(c)(3) nonprofit established in April 2025 to support the sustainability, independence, and global governance of the Common Vulnerabilities and Exposures (CVE) Program. It serves technology vendors, security product companies, governmental CERTs, researchers, defenders, and 453 CNAs across 40 countries by modernizing CVE.org infrastructure and diversifying program funding.

What CVE Foundation does

The CVE Foundation is a 501(c)(3) nonprofit incorporated in Washington State on April 16, 2025, established by a coalition of longtime CVE Board members to ensure the long-term sustainability, independence, and global governance of the Common Vulnerabilities and Exposures (CVE) Program. The Foundation does not own the CVE Program outright but serves as a supporting entity working alongside CISA and MITRE to transition the program from a single US-government-funded model to a diversified, multi-stakeholder nonprofit model. It serves the global cybersecurity ecosystem including technology vendors, security product companies, governmental CERTs, security researchers, operational defenders, and 453 CVE Numbering Authorities (CNAs) across 40 countries.

The Foundation's core technical product is the modernized CVE.org platform and its surrounding infrastructure: a cloud-native CNA Directory with REST APIs and webhooks, an Issue Management System for CNA-to-CNA coordination, a planned NVD-like microservices API (REST, GraphQL, Model Context Protocol), a CSAF v2.1 export pipeline, a Federated CPE Dictionary System, and VEX integration. AI features in development include a RAG-enabled LLM chatbot for CNA identification, AI-assisted CVSS/CWE scoring within Vulnogram, and AI-driven CPE entity recognition. These products collectively target improvements in data quality, CNA productivity, scalability, and alignment with the EU Cyber Resilience Act.

The Foundation's business model is that of a nonprofit funded through philanthropic contributions, grants from foundations and government entities, corporate sponsorships, individual/organizational donations, and a planned long-term endowment fund. The CVE Program itself is distributed as a free global public good with no commercial pricing. Distribution is entirely digital and self-serve via CVE.org and APIs. Customer concentration is therefore not a traditional revenue risk; rather, the strategic risk is funding concentration, which the Foundation is explicitly working to diversify following the April 2025 funding crisis that prompted its formation.

CVE Foundation firmographics

Firmographics
Name
CVE Foundation
Legal name
CVE Foundation
Website
https://thecvefoundation.org
Company type
Private
Founded year
2025
Operating status
Operating
Headcount range
11–50 employees
Short description
CVE Foundation is a 501(c)(3) nonprofit established in April 2025 to support the sustainability, independence, and global governance of the Common Vulnerabilities and Exposures (CVE) Program. It serves technology vendors, security product companies, governmental CERTs, researchers, defenders, and 453 CNAs across 40 countries by modernizing CVE.org infrastructure and diversifying program funding.
Ownership category
akta.pro rank

CVE Foundation industry classification

Industry
Product category
Cybersecurity Vulnerability Identification Standards
NAICS
Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (5182), Computer Systems Design and Related Services (54151), Custom Computer Programming Services (541511)
SIC
Services-Prepackaged Software (7372), Services-Computer Integrated Systems Design (7373), Services-Computer Programming, Data Processing, Etc. (7370)
akta.pro primary industry
Bug Bounty, Vulnerability Disclosure & Security Services (FSAPAJAL)

Keywords

  • Vulnerability identification
  • Cybersecurity standards
  • Vulnerability management
  • Nonprofit foundation
  • CVE program

Where CVE Foundation is headquartered

Location

Headquarters

HQ city
Washington
HQ country
United States
HQ region
North America

Offices6 records

Markets served

CVE Foundation business model

Business model
GTM type
B2B
Offering type
Software
Cost components
Personnel, Technology or R&D, Infrastructure, Operations, Marketing or Sales

Revenue model

  1. Philanthropic Contributions and Grants: Seeking contributions from foundations that support technological advancement and cybersecurity initiatives. Grants from foundations and government entities to support program operations and development.
  2. Corporate Sponsorships: Sponsorships from commercial entities that benefit from CVE data for their operations, contributing financially to the Program's sustainability.
  3. Donations: Individual and organizational donations to support the nonprofit mission of ensuring CVE stability and independence.
  4. Endowment Fund: Long-term endowment fund providing financial bedrock to ensure operations continue regardless of external economic fluctuations.

Pricing tiers

ModelBillingPrice
OtherMonthlyFree public access to CVE identifiers and records

Go-to-market motion1 record

Distribution channels3 records

Marketing channels7 records

CVE Foundation product offering

Product offering

Core offering

The CVE Foundation supports the sustainability and independence of the CVE Program—a globally recognized system for identifying and describing publicly disclosed cybersecurity vulnerabilities—through diversified funding and community engagement. It develops and operates infrastructure services including a CNA Directory with REST APIs, an Issue Management System, a RAG-enabled LLM CNA Identification Chatbot, an NVD-Like API for CVE.org, AI-enhanced Vulnogram tooling, a CSAF export pipeline, a Federated CPE Dictionary, and VEX integration capabilities. All CVE identifiers and records are provided free of charge to the global cybersecurity community.

Product overview

The CVE Foundation is developing a platform of infrastructure services to modernize and sustain the CVE Program. The core offerings include: the CNA Directory (cloud-native repository with REST APIs and webhooks for CNA information management), an Issue Management System (ticketing system for CNA coordination), a LLM-based CNA Identification Chatbot (RAG-enabled AI for product-to-CNA matching), and an NVD-Like API for CVE.org (microservices-based API with REST/GraphQL/MCP interfaces). Supporting tools include enhanced Vulnogram (AI-assisted CVE record creation), CSAF Export Pipeline (automated CSAF v2.1 conversion), Federated CPE Dictionary System (decentralized CPE maintenance with AI), and VEX Integration (real-time vulnerability status updates). These products collectively address CVE enrichment, scalability, data quality, and international coordination challenges while aligning with EU Cyber Resilience Act requirements.

Differentiator

Problem solved

Functional benefit

Products and services

  • CNA Directory Cloud-native repository of CVE Numbering Authority (CNA) details including scope definitions and contact information, exposing scalable REST APIs that support creation, updating, and removal of CNAs and Roots, plus webhooks for event-driven notifications of CNA changes. Built for global CVE program participants and integrators.
  • Issue Management System Ticketing system supporting CNA-to-CNA and CVE stakeholder-to-CNA coordination for resolving post-disclosure disputed CVEs and duplicate assignments with greater transparency and integration into third-party workflows such as GitHub.
  • CNA Identification Chatbot RAG-enabled LLM-based chatbot that identifies CNAs scoped for given products based on natural language product name queries, providing relevant scope details to assist security researchers in routing vulnerability assignments.
  • NVD-Like API for CVE.org Microservices-based API for CVE.org with standardized query interfaces including REST, GraphQL, and Model Context Protocol, exposing CVE data as a data lake for cloud service consumption with legacy API backward compatibility planned.
  • Vulnogram Enhancement with LLM Technology AI integration into the Vulnogram tool enabling CNAs to create higher-quality enriched CVE records through automated vulnerability scoring (CVSS), CWE assignment, and affected product associations (CPE) with interactive feedback mechanisms.
  • CSAF Export Pipeline Automated continuous export pipeline that converts CVE.org data into Common Security Advisory Framework (CSAF) v2.1 format with structured JSON-based formatting for seamless integration with third-party security platforms.
  • Federated CPE Dictionary System Decentralized mechanism for maintaining the Common Platform Enumeration (CPE) dictionary through federated contributions from CNAs and designated cybersecurity organizations, augmented by AI-driven entity recognition for standardized CPE definitions.
  • VEX Integration on CVE.org Vulnerability Applicability and Status (VEX) capability inline on CVE.org that allows CNAs to contribute real-time vulnerability status updates for open-source CVEs through the VEX framework.

Quantifiable outcome

  • Enables organizations to reliably assess which vulnerabilities affect them and how well their tools cover those risks
  • +2 more outcomes

Companies that use CVE Foundation

Customer profile

Named customers4 records

Segments6 records

Ideal customer profiles4 records

CVE Foundation technology and API

Technology

Technology focussed Yes

API detail

Has API
Yes
API docs
API detail

Core technology

AI maturity

App detail

Integration2 records

AI capability6 records

Feature5 records

CVE Foundation partnerships and signals

Strategic signal

Partnerships

Eight partnerships are on record, tiered core and major.

  • MITREcoreStrategic or Co-development Partner · 25 April 2025MITRE operates the CVE Program under contract with the US government. Following the April 2025 funding crisis, MITRE has been in discussions with the CVE Foundation about program continuity and future collaboration. The Foundation is committed to building strong, transparent relationships with MITRE.
  • CISA (Cybersecurity and Infrastructure Security Agency)coreStrategic or Co-development Partner · 23 April 2025CISA is the primary US government sponsor of the CVE Program. The CVE Foundation is working to maintain a strong partnership with CISA to support the CISA ICS Root and the MITRE-run CNA of last resort functions while helping expand the program globally. CISA has expressed commitment to actively seeking community feedback and fostering inclusivity in CVE stewardship.
  • ENISA (European Union Agency for Cybersecurity)coreStrategic or Co-development Partner · 1 January 2024ENISA operates the European Union Vulnerability Database (EUVD) as a CNA since January 2024. ENISA issues both EU-specific IDs and CVE IDs, extending and complementing the global CVE ecosystem with regionally relevant intelligence. The CVE Foundation intends to continue and expand partnerships with EU organizations.
  • CVE Numbering Authorities (CNAs)coreOthersThe CVE Program includes 453 CNAs from 40 countries that assign CVE IDs and add CVE records. CNAs are the lifeblood of CVE and the Foundation is deepening engagement with CNAs, Roots, and community contributors to elevate their voices and increase their role in shaping the program.
  • NIST (National Institute of Standards and Technology)majorStrategic or Co-development PartnerNIST manages the National Vulnerability Database (NVD) which enriches CVE records with CVSS scores, CWE taxonomy, and CPE product coverage. The CVE Foundation is collaborating with NVD to become an Authorized Data Provider (ADP) and integrate historical vulnerability data into CVE.org.
  • FIRST (Forum of Incident Response and Security Teams)majorStrategic or Co-development PartnerFIRST provides interoperable scoring standards including CVSS and EPSS that work with CVE data. The CVE Foundation works with FIRST to enable security professionals to communicate clearly, assess risk consistently, and act swiftly based on CVE data.
  • Center for Cybersecurity Policy and LawmajorStrategic or Co-development PartnerThe Center for Cybersecurity Policy and Law created a CVE primer whitepaper to raise awareness about challenges facing the CVE Program including governance, transparency, and funding. Kent Landfield serves as a Fellow for the Center, and the Foundation works closely on policy discourse.
  • The CVE BoardcoreStrategic or Co-development PartnerThe CVE Board provides governance oversight of the CVE Program. Multiple CVE Board members formed the CVE Foundation to transition CVE to a nonprofit model with diversified funding. The Foundation aims to evolve the Board into a more inclusive, globally coordinated governance structure.

Scale indicators3 records

Recent moves7 records

Expansion highlights6 records

CVE Foundation competitors and assessment

Company assessment

Others

  • Linux Foundation: Largest nonprofit stewarding open-source infrastructure, including hosting OpenSSF. Comparable as a mature nonprofit model for funding and governing critical technology infrastructure used globally.
  • Apache Software Foundation: Nonprofit that supports open-source software projects and infrastructure through community-driven governance. Comparable as a nonprofit stewarding critical technology infrastructure with a sponsorship-driven funding model.
  • Cloud Security Alliance: Nonprofit organization providing cybersecurity best practices, certifications, and standards. Comparable as a nonprofit cybersecurity standards body with a similar membership and corporate sponsorship funding model.
  • Internet Security Research Group (ISRG): Nonprofit that operates Let's Encrypt and Prossimo, providing free internet security infrastructure as a public good. Comparable as a nonprofit operating critical security infrastructure on a free, donor-funded model.

Direct peers

  • ENISA (European Union Agency for Cybersecurity): Operates the EU Vulnerability Database (EUVD) and became a CVE Numbering Authority in January 2024. Directly comparable as a regional vulnerability database operator and CNA extending the CVE ecosystem across Europe.
  • NIST National Vulnerability Database: Manages the NVD, the primary enrichment layer for CVE records with CVSS, CWE, and CPE data. Directly comparable as a major CVE ecosystem participant that the Foundation is collaborating with to integrate historical vulnerability data.
  • MITRE Corporation: Operates the CVE Program under US government contract and is the current program operator whose relationship with the Foundation determines the Foundation's role. Directly comparable as the operational backbone for global vulnerability identification that the Foundation was created to support.

Emerging players

  • OWASP Foundation: Nonprofit that supports open-source cybersecurity resources including vulnerability catalogs and tooling. Comparable as a nonprofit stewarding critical cybersecurity infrastructure with a similar community-led, donation-and-sponsorship-driven funding model.
  • OpenSSF (Open Source Security Foundation): Cross-industry initiative hosted by the Linux Foundation focused on improving open source software security. Comparable as a nonprofit consortium coordinating cybersecurity tooling, standards, and funding across vendors and foundations.

Broad incumbents

  • FIRST (Forum of Incident Response and Security Teams): Global standards body for incident response that maintains CVSS and EPSS scoring frameworks used alongside CVE. Comparable as a related cybersecurity standards organization with an overlapping stakeholder community and Peter Allor as a leader in FIRST PSIRT SIG.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat6 records

Key risks6 records

Key highlights6 records

Customer concentration

CVE Foundation social profiles

Digital presence

CVE Foundation financial estimates

Financial estimate

Revenue estimate

Valuation estimate

CVE Foundation leadership team

Management profile

Number of profiles

Profiles5 records

CVE Foundation funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

CVE Foundation M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about CVE Foundation

What does CVE Foundation do?

The CVE Foundation supports the sustainability and independence of the CVE Program—a globally recognized system for identifying and describing publicly disclosed cybersecurity vulnerabilities—through diversified funding and community engagement. It develops and operates infrastructure services including a CNA Directory with REST APIs, an Issue Management System, a RAG-enabled LLM CNA Identification Chatbot, an NVD-Like API for CVE.org, AI-enhanced Vulnogram tooling, a CSAF export pipeline, a Federated CPE Dictionary, and VEX integration capabilities. All CVE identifiers and records are provided free of charge to the global cybersecurity community.

Is CVE Foundation a public or private company?

CVE Foundation is a private company. It is classified as nonprofit foundation owned and is currently operating.

When was CVE Foundation founded?

CVE Foundation was founded in 2025. It employs 11 to 50 people.

Where is CVE Foundation based?

CVE Foundation is headquartered in Washington, United States, in the North America region.

How does CVE Foundation make money?

Four revenue lines are on record. Philanthropic Contributions and Grants are the primary driver. The others are corporate Sponsorships, donations and endowment Fund.

Who are CVE Foundation's main competitors?

Others on record are Linux Foundation, Apache Software Foundation, Cloud Security Alliance and Internet Security Research Group (ISRG). Direct peers are ENISA (European Union Agency for Cybersecurity), NIST National Vulnerability Database and MITRE Corporation. Emerging players are OWASP Foundation and OpenSSF (Open Source Security Foundation). FIRST (Forum of Incident Response and Security Teams) is listed as a broad incumbent.

Does CVE Foundation have an API?

Yes. CVE Foundation is developing multiple API products: (1) CNA Directory REST APIs for accessing CNA details, scope definitions, and contact information, supporting creation, updating, and removal of CNAs and Roots; (2) Issue Management System APIs for CNA-to-CNA and CVE stakeholder-to-CNA coordination; (3) Planned NVD-Like API for CVE.org with standardized query interfaces including REST, GraphQL, and Model Context Protocol; (4) Webhooks for event-driven notifications of new CNAs and changes to existing CNA information; (5) CSAF continuous export pipeline for CVE data. Legacy API backward compatibility is planned. Developer documentation is at cve.org.

What industry is CVE Foundation in?

CVE Foundation's product category is Cybersecurity Vulnerability Identification Standards. Its primary akta.pro industry code is FSAPAJAL, Bug Bounty, Vulnerability Disclosure & Security Services. Its NAICS code is 5182 and its SIC code is 7372.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
American BankerA cyberdefense 'pillar' for banks faces 'existential crisis'The Common Vulnerabilities and Exposures (CVE) program, a foundational 25-year-old cybersecurity database maintained by federally funded nonprofit MITRE, faces an existential crisis due to AI-driven surges in vulnerability submissions that are overwhelming the system and degrading data quality. The program nearly collapsed in April 2025 when government funding dried up, prompting CISA to step in with an 11-month contract extension, while the European Union accelerated development of its own vulnerability database under the Cyber Resilience Act. For U.S. banking organizations regulated under SR 22-4 requirements, a collapse or fragmentation of the CVE catalog would severely impact patch management, third-party service provider coordination, and compliance with the 36-hour incident reporting mandate.PerforceCVE Funding DisruptionThe U.S. government funding for the MITRE CVE database program was set to expire in April 2025, prompting an emergency 11-month extension secured by CISA after widespread concern from the cybersecurity community. In response to the vulnerability of relying on public funding, a group of experts established the CVE Foundation to seek greater independence and ensure continuity. The article advises security teams to diversify their vulnerability management strategies using internal databases and alternative intelligence sources to mitigate risks associated with potential future disruptions.MimecastCVE Program receives funding extension, but concerns remainThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has granted an 11-month funding extension to the Common Vulnerabilities and Exposures (CVE) Program, operated by MITRE, preventing a lapse in critical vulnerability management services. This action addresses immediate fears of disruption to national security infrastructure caused by the expiration of federal funding on April 16. The temporary solution highlights ongoing concerns regarding the program's reliance on a single government sponsor and has spurred calls for industry-wide reforms and the establishment of the non-profit CVE Foundation.GlobeNewswireConnectWise Authorized as CVE Numbering Authority by the CVE ProgramConnectWise was authorized as a CVE Numbering Authority by the CVE Program on June 5, 2024. As a CNA, it will assign CVE IDs to vulnerabilities in its products and third-party products not covered by another CNA. The authorization underscores its commitment to cybersecurity and vulnerability information.GlobeNewswireGenetec authorized by the CVE Program as a CVE Numbering Authority (CNA)Genetec Inc. announced it has been authorized by the CVE Program as a CVE Numbering Authority. The authorization allows Genetec to publish CVE Records for its physical security solutions, supporting consistent vulnerability communication. The company stated this reflects its commitment to strong cybersecurity practices.