# Use CISA SSVC to decide what happens after severity and KEV screening

> CVSS describes severity and KEV confirms exploitation, but neither supplies every organization-specific decision. Use CISA SSVC with deployment, mission, safety, and change context to assign an accountable response.

- Canonical URL: https://update.dsesecurity.com/updates/use-cisa-ssvc-to-decide-what-happens-after-severity-and-kev-screening/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-08-04T22:53:02+00:00
- Modified: 2026-08-04T22:53:02+00:00
- Last reviewed by DSE: 2026-08-04
- Resource type: Guide
- DSE priority: Advisory
- Topics: Business Continuity, Cybersecurity, IT
- Reading time: 3 minutes

## What you need to know

CVSS describes severity and KEV confirms exploitation, but neither supplies every organization-specific decision. Use CISA SSVC with deployment, mission, safety, and change context to assign an accountable response.

## Potentially affected

Vulnerability management teams, system owners, security operations, IT operations, change managers, and business continuity leaders.

## DSE recommendation

Keep KEV as an exploited-vulnerability gate, apply SSVC to the remaining queue with local evidence, and record the decision, owner, deadline, assumptions, and reassessment triggers.

## Article

## Source fact: severity, exploitation, and priority answer different questions

A CVSS score is useful, but it is not an organization-specific risk decision. NIST says CVSS provides a qualitative measure of severity and should be one input to prioritization; NVD base assessments do not include the environmental factors unique to a deployment or threat information that changes over time. CISA’s Known Exploited Vulnerabilities catalog answers a different question: whether there is reliable evidence that a vulnerability has been exploited in the wild. CISA calls KEV a living catalog and urges organizations to prioritize timely remediation of catalog entries. Those distinctions are documented by [NIST’s vulnerability-metrics guidance](https://nvd.nist.gov/vuln-metrics) and the [CISA KEV catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog).

CISA’s Stakeholder-Specific Vulnerability Categorization, or SSVC, adds a decision model. The [CISA SSVC Guide](https://www.cisa.gov/sites/default/files/publications/cisa-ssvc-guide%20508c.pdf) describes a decision tree that considers exploitation status, technical impact, mission prevalence, and effects on public well-being. Its outcomes are Track, Track*, Attend, and Act. They progress from monitoring and standard remediation through closer monitoring, supervisory attention, and urgent leadership-coordinated action. SSVC does not erase local judgment, and its labels are not universal service-level deadlines.

## DSE recommendation: use a layered decision queue

DSE recommendation: preserve the existing KEV-first rule, then use SSVC to structure decisions for the much larger non-KEV backlog. This supplements DSE’s published KEV guidance; it does not replace it.

- Confirm applicability. Match the vulnerable product, version, component, configuration, and deployment to an owned asset or service. Record when the team cannot yet prove whether the component is present.

- Apply the exploitation gate. If the CVE is in KEV and the affected component is deployed, move it into the exploited-vulnerability response path. Document compensating controls and change constraints, but do not use a lower CVSS score to demote known exploitation.

- Run SSVC on the rest. Use current official advisories and threat evidence for exploitation status. Ask what an attacker can achieve, how broadly the vulnerable function supports the mission, and whether failure could harm safety or public well-being. Choose the most supportable answer and record uncertainty rather than silently converting missing data into low risk.

- Translate the outcome into local action. Map Track, Track*, Attend, and Act to the organization’s own response lanes, notification rules, and change process. The mapping should name an owner and a completion or review date; it should not imply that CISA prescribed that local date.

- Plan a safe change. Include testing, dependencies, maintenance windows, rollback, and temporary protections. Urgency and operational safety belong in the same decision, especially for identity, clinical, industrial, life-safety, or other critical services.

## Keep the decision reproducible

For each material vulnerability, retain the affected deployment, business service, evidence links, SSVC input values, assumptions, outcome, compensating controls, action owner, approver, due date, and rollback plan. The [NVD vulnerability API documentation](https://nvd.nist.gov/developers/vulnerabilities) can support automated enrichment, but a feed cannot supply DSE’s local mission and change context.

Include the decision timestamp and the evidence version or retrieval time. That makes later review possible when feeds, advisories, or exploitation status change. If multiple deployments have different exposure or mission effects, create separate decisions rather than averaging them into one label.

Define reassessment triggers before closing the record: addition to KEV, new exploit evidence, a vendor advisory, exposure or configuration change, control failure, missed due date, or a change in service criticality. Sample completed decisions for consistency and challenge repeated use of low-impact answers that lack evidence. Measure time from new evidence to a new decision, not only time from publication to patch.

## What this approach prevents

It prevents three common errors: treating every high CVSS score as equally urgent, treating every non-KEV issue as safe to defer, and assigning an SSVC label without a business owner. The result is still a risk decision, not a mathematical truth. Where evidence is weak or potential harm is high, escalate the uncertainty and obtain the accountable owner’s decision.

## Official sources

- [CISA: Stakeholder-Specific Vulnerability Categorization Guide](https://www.cisa.gov/sites/default/files/publications/cisa-ssvc-guide%20508c.pdf)

- [CISA: Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)

- [NIST NVD: Vulnerability Metrics](https://nvd.nist.gov/vuln-metrics)

- [NIST NVD: Vulnerabilities API](https://nvd.nist.gov/developers/vulnerabilities)

## Primary reference

- Name: CISA Stakeholder-Specific Vulnerability Categorization Guide
- Authority: Cybersecurity and Infrastructure Security Agency
- URL: https://www.cisa.gov/sites/default/files/publications/cisa-ssvc-guide%20508c.pdf
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Use CISA SSVC to decide what happens after severity and KEV screening,” DSE Security, https://update.dsesecurity.com/updates/use-cisa-ssvc-to-decide-what-happens-after-severity-and-kev-screening/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
