CVE Foundation
CVE Foundation is a 501(c)(3) nonprofit established in April 2025 to support the sustainability, independence, and global governance of the Common Vulnerabilities and Exposures (CVE) Program. It serves technology vendors, security product companies, governmental CERTs, researchers, defenders, and 453 CNAs across 40 countries by modernizing CVE.org infrastructure and diversifying program funding.
- Company typePrivate
- Founded2025
- HeadquartersWashington, United States
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What CVE Foundation does
The CVE Foundation is a 501(c)(3) nonprofit incorporated in Washington State on April 16, 2025, established by a coalition of longtime CVE Board members to ensure the long-term sustainability, independence, and global governance of the Common Vulnerabilities and Exposures (CVE) Program. The Foundation does not own the CVE Program outright but serves as a supporting entity working alongside CISA and MITRE to transition the program from a single US-government-funded model to a diversified, multi-stakeholder nonprofit model. It serves the global cybersecurity ecosystem including technology vendors, security product companies, governmental CERTs, security researchers, operational defenders, and 453 CVE Numbering Authorities (CNAs) across 40 countries.
The Foundation's core technical product is the modernized CVE.org platform and its surrounding infrastructure: a cloud-native CNA Directory with REST APIs and webhooks, an Issue Management System for CNA-to-CNA coordination, a planned NVD-like microservices API (REST, GraphQL, Model Context Protocol), a CSAF v2.1 export pipeline, a Federated CPE Dictionary System, and VEX integration. AI features in development include a RAG-enabled LLM chatbot for CNA identification, AI-assisted CVSS/CWE scoring within Vulnogram, and AI-driven CPE entity recognition. These products collectively target improvements in data quality, CNA productivity, scalability, and alignment with the EU Cyber Resilience Act.
The Foundation's business model is that of a nonprofit funded through philanthropic contributions, grants from foundations and government entities, corporate sponsorships, individual/organizational donations, and a planned long-term endowment fund. The CVE Program itself is distributed as a free global public good with no commercial pricing. Distribution is entirely digital and self-serve via CVE.org and APIs. Customer concentration is therefore not a traditional revenue risk; rather, the strategic risk is funding concentration, which the Foundation is explicitly working to diversify following the April 2025 funding crisis that prompted its formation.
CVE Foundation firmographics
Firmographics- Name
- CVE Foundation
- Legal name
- CVE Foundation
- Website
- https://thecvefoundation.org
- Company type
- Private
- Founded year
- 2025
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- CVE Foundation is a 501(c)(3) nonprofit established in April 2025 to support the sustainability, independence, and global governance of the Common Vulnerabilities and Exposures (CVE) Program. It serves technology vendors, security product companies, governmental CERTs, researchers, defenders, and 453 CNAs across 40 countries by modernizing CVE.org infrastructure and diversifying program funding.
- Ownership category
- akta.pro rank
CVE Foundation industry classification
Industry- Product category
- Cybersecurity Vulnerability Identification Standards
- NAICS
- Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services (5182), Computer Systems Design and Related Services (54151), Custom Computer Programming Services (541511)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Integrated Systems Design (7373), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Bug Bounty, Vulnerability Disclosure & Security Services (FSAPAJAL)
Keywords
Where CVE Foundation is headquartered
LocationHeadquarters
- HQ city
- Washington
- HQ country
- United States
- HQ region
- North America
Offices6 records
Markets served
CVE Foundation business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Infrastructure, Operations, Marketing or Sales
Revenue model
- Philanthropic Contributions and Grants: Seeking contributions from foundations that support technological advancement and cybersecurity initiatives. Grants from foundations and government entities to support program operations and development.
- Corporate Sponsorships: Sponsorships from commercial entities that benefit from CVE data for their operations, contributing financially to the Program's sustainability.
- Donations: Individual and organizational donations to support the nonprofit mission of ensuring CVE stability and independence.
- Endowment Fund: Long-term endowment fund providing financial bedrock to ensure operations continue regardless of external economic fluctuations.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Monthly | Free public access to CVE identifiers and records |
Go-to-market motion1 record
Distribution channels3 records
Marketing channels7 records
CVE Foundation product offering
Product offeringCore offering
The CVE Foundation supports the sustainability and independence of the CVE Program—a globally recognized system for identifying and describing publicly disclosed cybersecurity vulnerabilities—through diversified funding and community engagement. It develops and operates infrastructure services including a CNA Directory with REST APIs, an Issue Management System, a RAG-enabled LLM CNA Identification Chatbot, an NVD-Like API for CVE.org, AI-enhanced Vulnogram tooling, a CSAF export pipeline, a Federated CPE Dictionary, and VEX integration capabilities. All CVE identifiers and records are provided free of charge to the global cybersecurity community.
Product overview
The CVE Foundation is developing a platform of infrastructure services to modernize and sustain the CVE Program. The core offerings include: the CNA Directory (cloud-native repository with REST APIs and webhooks for CNA information management), an Issue Management System (ticketing system for CNA coordination), a LLM-based CNA Identification Chatbot (RAG-enabled AI for product-to-CNA matching), and an NVD-Like API for CVE.org (microservices-based API with REST/GraphQL/MCP interfaces). Supporting tools include enhanced Vulnogram (AI-assisted CVE record creation), CSAF Export Pipeline (automated CSAF v2.1 conversion), Federated CPE Dictionary System (decentralized CPE maintenance with AI), and VEX Integration (real-time vulnerability status updates). These products collectively address CVE enrichment, scalability, data quality, and international coordination challenges while aligning with EU Cyber Resilience Act requirements.
Differentiator
Problem solved
Functional benefit
Products and services
- CNA Directory Cloud-native repository of CVE Numbering Authority (CNA) details including scope definitions and contact information, exposing scalable REST APIs that support creation, updating, and removal of CNAs and Roots, plus webhooks for event-driven notifications of CNA changes. Built for global CVE program participants and integrators.
- Issue Management System Ticketing system supporting CNA-to-CNA and CVE stakeholder-to-CNA coordination for resolving post-disclosure disputed CVEs and duplicate assignments with greater transparency and integration into third-party workflows such as GitHub.
- CNA Identification Chatbot RAG-enabled LLM-based chatbot that identifies CNAs scoped for given products based on natural language product name queries, providing relevant scope details to assist security researchers in routing vulnerability assignments.
- NVD-Like API for CVE.org Microservices-based API for CVE.org with standardized query interfaces including REST, GraphQL, and Model Context Protocol, exposing CVE data as a data lake for cloud service consumption with legacy API backward compatibility planned.
- Vulnogram Enhancement with LLM Technology AI integration into the Vulnogram tool enabling CNAs to create higher-quality enriched CVE records through automated vulnerability scoring (CVSS), CWE assignment, and affected product associations (CPE) with interactive feedback mechanisms.
- CSAF Export Pipeline Automated continuous export pipeline that converts CVE.org data into Common Security Advisory Framework (CSAF) v2.1 format with structured JSON-based formatting for seamless integration with third-party security platforms.
- Federated CPE Dictionary System Decentralized mechanism for maintaining the Common Platform Enumeration (CPE) dictionary through federated contributions from CNAs and designated cybersecurity organizations, augmented by AI-driven entity recognition for standardized CPE definitions.
- VEX Integration on CVE.org Vulnerability Applicability and Status (VEX) capability inline on CVE.org that allows CNAs to contribute real-time vulnerability status updates for open-source CVEs through the VEX framework.
Quantifiable outcome
- Enables organizations to reliably assess which vulnerabilities affect them and how well their tools cover those risks
- +2 more outcomes
Companies that use CVE Foundation
Customer profileNamed customers4 records
Segments6 records
Ideal customer profiles4 records
CVE Foundation technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration2 records
AI capability6 records
Feature5 records
CVE Foundation partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered core and major.
- MITREcoreMITRE operates the CVE Program under contract with the US government. Following the April 2025 funding crisis, MITRE has been in discussions with the CVE Foundation about program continuity and future collaboration. The Foundation is committed to building strong, transparent relationships with MITRE.
- CISA (Cybersecurity and Infrastructure Security Agency)coreCISA is the primary US government sponsor of the CVE Program. The CVE Foundation is working to maintain a strong partnership with CISA to support the CISA ICS Root and the MITRE-run CNA of last resort functions while helping expand the program globally. CISA has expressed commitment to actively seeking community feedback and fostering inclusivity in CVE stewardship.
- ENISA (European Union Agency for Cybersecurity)coreENISA operates the European Union Vulnerability Database (EUVD) as a CNA since January 2024. ENISA issues both EU-specific IDs and CVE IDs, extending and complementing the global CVE ecosystem with regionally relevant intelligence. The CVE Foundation intends to continue and expand partnerships with EU organizations.
- CVE Numbering Authorities (CNAs)coreThe CVE Program includes 453 CNAs from 40 countries that assign CVE IDs and add CVE records. CNAs are the lifeblood of CVE and the Foundation is deepening engagement with CNAs, Roots, and community contributors to elevate their voices and increase their role in shaping the program.
- NIST (National Institute of Standards and Technology)majorNIST manages the National Vulnerability Database (NVD) which enriches CVE records with CVSS scores, CWE taxonomy, and CPE product coverage. The CVE Foundation is collaborating with NVD to become an Authorized Data Provider (ADP) and integrate historical vulnerability data into CVE.org.
- FIRST (Forum of Incident Response and Security Teams)majorFIRST provides interoperable scoring standards including CVSS and EPSS that work with CVE data. The CVE Foundation works with FIRST to enable security professionals to communicate clearly, assess risk consistently, and act swiftly based on CVE data.
- Center for Cybersecurity Policy and LawmajorThe Center for Cybersecurity Policy and Law created a CVE primer whitepaper to raise awareness about challenges facing the CVE Program including governance, transparency, and funding. Kent Landfield serves as a Fellow for the Center, and the Foundation works closely on policy discourse.
- The CVE BoardcoreThe CVE Board provides governance oversight of the CVE Program. Multiple CVE Board members formed the CVE Foundation to transition CVE to a nonprofit model with diversified funding. The Foundation aims to evolve the Board into a more inclusive, globally coordinated governance structure.
Scale indicators3 records
Recent moves7 records
Expansion highlights6 records
CVE Foundation competitors and assessment
Company assessmentOthers
- Linux Foundation: Largest nonprofit stewarding open-source infrastructure, including hosting OpenSSF. Comparable as a mature nonprofit model for funding and governing critical technology infrastructure used globally.
- Apache Software Foundation: Nonprofit that supports open-source software projects and infrastructure through community-driven governance. Comparable as a nonprofit stewarding critical technology infrastructure with a sponsorship-driven funding model.
- Cloud Security Alliance: Nonprofit organization providing cybersecurity best practices, certifications, and standards. Comparable as a nonprofit cybersecurity standards body with a similar membership and corporate sponsorship funding model.
- Internet Security Research Group (ISRG): Nonprofit that operates Let's Encrypt and Prossimo, providing free internet security infrastructure as a public good. Comparable as a nonprofit operating critical security infrastructure on a free, donor-funded model.
Direct peers
- ENISA (European Union Agency for Cybersecurity): Operates the EU Vulnerability Database (EUVD) and became a CVE Numbering Authority in January 2024. Directly comparable as a regional vulnerability database operator and CNA extending the CVE ecosystem across Europe.
- NIST National Vulnerability Database: Manages the NVD, the primary enrichment layer for CVE records with CVSS, CWE, and CPE data. Directly comparable as a major CVE ecosystem participant that the Foundation is collaborating with to integrate historical vulnerability data.
- MITRE Corporation: Operates the CVE Program under US government contract and is the current program operator whose relationship with the Foundation determines the Foundation's role. Directly comparable as the operational backbone for global vulnerability identification that the Foundation was created to support.
Emerging players
- OWASP Foundation: Nonprofit that supports open-source cybersecurity resources including vulnerability catalogs and tooling. Comparable as a nonprofit stewarding critical cybersecurity infrastructure with a similar community-led, donation-and-sponsorship-driven funding model.
- OpenSSF (Open Source Security Foundation): Cross-industry initiative hosted by the Linux Foundation focused on improving open source software security. Comparable as a nonprofit consortium coordinating cybersecurity tooling, standards, and funding across vendors and foundations.
Broad incumbents
- FIRST (Forum of Incident Response and Security Teams): Global standards body for incident response that maintains CVSS and EPSS scoring frameworks used alongside CVE. Comparable as a related cybersecurity standards organization with an overlapping stakeholder community and Peter Allor as a leader in FIRST PSIRT SIG.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights6 records
Customer concentration
CVE Foundation social profiles
Digital presenceCVE Foundation financial estimates
Financial estimateRevenue estimate
Valuation estimate
CVE Foundation leadership team
Management profileNumber of profiles
Profiles5 records
CVE Foundation funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
CVE Foundation M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about CVE Foundation
What does CVE Foundation do?
The CVE Foundation supports the sustainability and independence of the CVE Program—a globally recognized system for identifying and describing publicly disclosed cybersecurity vulnerabilities—through diversified funding and community engagement. It develops and operates infrastructure services including a CNA Directory with REST APIs, an Issue Management System, a RAG-enabled LLM CNA Identification Chatbot, an NVD-Like API for CVE.org, AI-enhanced Vulnogram tooling, a CSAF export pipeline, a Federated CPE Dictionary, and VEX integration capabilities. All CVE identifiers and records are provided free of charge to the global cybersecurity community.
Is CVE Foundation a public or private company?
CVE Foundation is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was CVE Foundation founded?
CVE Foundation was founded in 2025. It employs 11 to 50 people.
Where is CVE Foundation based?
CVE Foundation is headquartered in Washington, United States, in the North America region.
How does CVE Foundation make money?
Four revenue lines are on record. Philanthropic Contributions and Grants are the primary driver. The others are corporate Sponsorships, donations and endowment Fund.
Who are CVE Foundation's main competitors?
Others on record are Linux Foundation, Apache Software Foundation, Cloud Security Alliance and Internet Security Research Group (ISRG). Direct peers are ENISA (European Union Agency for Cybersecurity), NIST National Vulnerability Database and MITRE Corporation. Emerging players are OWASP Foundation and OpenSSF (Open Source Security Foundation). FIRST (Forum of Incident Response and Security Teams) is listed as a broad incumbent.
Does CVE Foundation have an API?
Yes. CVE Foundation is developing multiple API products: (1) CNA Directory REST APIs for accessing CNA details, scope definitions, and contact information, supporting creation, updating, and removal of CNAs and Roots; (2) Issue Management System APIs for CNA-to-CNA and CVE stakeholder-to-CNA coordination; (3) Planned NVD-Like API for CVE.org with standardized query interfaces including REST, GraphQL, and Model Context Protocol; (4) Webhooks for event-driven notifications of new CNAs and changes to existing CNA information; (5) CSAF continuous export pipeline for CVE data. Legacy API backward compatibility is planned. Developer documentation is at cve.org.
What industry is CVE Foundation in?
CVE Foundation's product category is Cybersecurity Vulnerability Identification Standards. Its primary akta.pro industry code is FSAPAJAL, Bug Bounty, Vulnerability Disclosure & Security Services. Its NAICS code is 5182 and its SIC code is 7372.