{
  "schema": "kallipolis.resource-quality.v1",
  "id": "resource.public-data.cisa-kev-catalog",
  "version": "1.0.0",
  "title": "CISA Known Exploited Vulnerabilities catalog boundary",
  "summary": "Official-source access, authentication, request-shaping, freshness, legal, and interpretation boundaries for CISA Known Exploited Vulnerabilities catalog.",
  "content": {
    "kind": "public-data-api-boundary",
    "facts": [
      {
        "id": "fact.cisa.kev-catalog.access",
        "statement": "Cybersecurity and Infrastructure Security Agency documents known-exploited CVE records, vendors, products, required actions, due dates, and machine-readable catalog files.",
        "normativeLevel": "informative",
        "sourceIds": [
          "source.cisa.kev-catalog"
        ]
      },
      {
        "id": "fact.cisa.kev-catalog.authentication",
        "statement": "Public reads do not grant vulnerability, remediation, directive, asset, incident, or CISA decision authority.",
        "normativeLevel": "informative",
        "sourceIds": [
          "source.cisa.kev-catalog"
        ]
      },
      {
        "id": "fact.cisa.kev-catalog.request",
        "statement": "Clients must bind catalog version, CVE identifier, vendor, product, date added, due date, known-ransomware field, and file representation.",
        "normativeLevel": "informative",
        "sourceIds": [
          "source.cisa.kev-catalog"
        ]
      },
      {
        "id": "fact.cisa.kev-catalog.boundary",
        "statement": "Catalog inclusion reflects evidence of exploitation and scoped directives; absence does not prove safety, and inclusion does not establish local exposure or exploitability.",
        "normativeLevel": "informative",
        "sourceIds": [
          "source.cisa.kev-catalog"
        ]
      }
    ]
  },
  "language": "en",
  "category": "public-data-api",
  "state": "prepared",
  "canonicalUrl": "https://platoskallipolis.com/resources/public-data-apis/cisa-kev-catalog.json",
  "contentHash": "sha256:21d02ea902818da05e6f6576b5e3d54ddacb46b728ca0dad90c959b30958f42b",
  "owner": {
    "id": "platos-kallipolis",
    "name": "Plato's Kallipolis",
    "type": "organization",
    "accountabilityUrl": "https://platoskallipolis.com/about"
  },
  "access": {
    "mode": "public",
    "url": "https://platoskallipolis.com/resources/public-data-apis/cisa-kev-catalog.json",
    "authentication": "none",
    "robotsAllowed": true
  },
  "provenance": {
    "method": "primary-source",
    "sources": [
      {
        "id": "source.cisa.kev-catalog",
        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
        "title": "CISA Known Exploited Vulnerabilities catalog documentation",
        "publisher": "Cybersecurity and Infrastructure Security Agency",
        "observedAt": "2026-08-28T18:03:05Z"
      }
    ]
  },
  "observedAt": "2026-08-28T18:03:05Z",
  "freshness": {
    "policy": "max-age",
    "state": "current",
    "nextReviewAt": "2026-09-04T18:03:05Z",
    "maxAgeSeconds": 604800
  },
  "license": {
    "id": "source-terms-apply",
    "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
    "redistributionAllowed": false
  },
  "evidence": [
    {
      "id": "evidence.cisa.kev-catalog",
      "type": "source-claim",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "observedAt": "2026-08-28T18:03:05Z"
    }
  ]
}
