IC Oversight — 2026-06-21

NDAA Amendment Would Codify CISA Authority Over Global CVE Vulnerability Program with New Board Structure

BLUFAbsent a named sponsor willing to champion it through conference, codification of CISA's CVE authority in the FY2027 NDAA is unlikely by year's end, leaving the program's accountability gap unresolved.

The amendment text, reviewed by Nextgov/FCW but listing no sponsoring lawmaker, would create a 15-member CVE Board with permanent seats for CISA, NIST, and senior CVE authorities and rotating representation from industry, academia, research, and foreign governments 12. It would also require a joint CISA-NIST modernization plan and make vulnerability enrichment a formal part of CVE's mission, directing the board to set record-content standards 12. House Homeland Security Committee Democratic cyber policy lead Moira Bergen, speaking at RSAC earlier this year, said existing authorization leaves CISA without a specific statutory tasking for CVE, complicating congressional accountability 12. Both Armed Services Committees have advanced FY2027 defense bills, with the House Rules Committee setting a Thursday submission deadline for amendments; CISA declined to comment on the proposal 12.

Analysis
The unnamed-sponsor status makes enactment by end of calendar year 2026 unlikely. Moderate confidence in that assessment rests on a structural indicator: no named sponsor means no floor advocate to carry the provision through House-Senate conference reconciliation. Single-source reporting from Nextgov/FCW, with one verbatim secondary pickup and no independent corroboration of the amendment text, limits sourcing weight. A formal statutory home would shift accountability from a contractual arrangement with MITRE to direct congressional oversight. Foreign government rotating seats would bind allied vulnerability disclosure to U.S. statutory authority, complicating any future withdrawal from the board structure. Provisions with documented committee-staff backing and allied government interest often survive NDAA conference without named floor sponsors, and this amendment has both. CISA program managers and MITRE contract officers face divergent planning requirements: enactment triggers statutory compliance obligations; failure extends contractual governance indefinitely.
2 sources
  1. Planned NDAA amendment would codify CISAs role in cyber vulnerability program - Nextgov
  2. Planned NDAA amendment would codify CISA's role in cyber vulnerability program - Malware News

View in full brief →

UNCLASSIFIED // OPEN SOURCE