CSAF
Common Security Advisory Framework
Standard für maschinenlesbare Sicherheitshinweise
CSAF is an open standard for machine-readable security advisories. Instead of publishing advisories as prose, CSAF describes them in a structured format that can be processed automatically — who is affected, in which version, with which remediation. It is the answer to the simple fact that no human can manually read all relevant advisories any more.
History & facts. CSAF is maintained by the standards consortium OASIS; the current version 2.0 supersedes the older CVRF. The advisories are structured as JSON and can answer for machines whether a concrete product in a concrete version is affected. An important profile is VEX (Vulnerability Exploitability eXchange), with which manufacturers can actively communicate that a vulnerability that is present in principle is not exploitable in the concrete product. Authorities such as the Federal Office for Information Security (Germany) (BSI) and the United States of America (US) Cybersecurity and Infrastructure Security Agency (USA) (CISA) actively promote its adoption.
Outlook & recommendation. With the Cyber Resilience Act (CRA) obliging manufacturers to communicate vulnerabilities in a structured way, CSAF gains considerably in importance. For operators the value lies in automation: machine-readable advisories can be matched directly against one's own inventory instead of being reviewed by hand. Anyone developing products today should plan for CSAF/Vulnerability Exploitability eXchange (VEX) output as a future expectation.