The question is always who decided, when, and on what they knew that day. A decision record answers all three: it names who made the call, takes a date our server sets and no caller can supply, and freezes that day's evidence beside the call, hashed. A watch alerts you when KEV or EPSS moves. Every standard lets you carry an exception, each on its own terms. None of them lets you backdate the decision.
Already sampled? What to hand over tonight. On call tonight? The written reason goes in a decision record, and the proof link goes in your ticket. Write tonight's reason.
The record opens with that CVE's facts already filled in: KEV status, EPSS and its date, weakness class, fixed versions, each from its public source. Our server dates it. Sign in with email, Google or GitHub to keep it. The first 100 records are free.
Four fields to type: scope, verdict, one sentence of rationale, a review-by date. The evidence, the date and your name are filled. Name what holds the line in the rationale, then paste the proof link into the ticket. A call made last night is recorded now: it carries today's date, and the rationale says when you decided.
Pick Mitigated if something holds the line tonight, or Patch by a date if the fix is scheduled.
Sign in with email, Google or GitHub. The first 100 records are free.
We will not pretend you can. Hand over the approval you have, from the ticket or the form, with the CVE page beside it. The page is public and needs no account. Its dated events show what KEV and EPSS said on the day you decided, each dated by its source, so the auditor checks your account against CISA and FIRST rather than against you. Then record today's review of the exception you still carry. It is dated today because it is today's decision, and it covers the next deadline.
Six standards, and each asks a different question about the same exception. Each one has its own page: the clause, what the auditor actually requests, and a worked example on a real CVE. Pick yours.
How a SOC 2 type 2 auditor tests vulnerability exceptions: each finding past your own SLA needs an approval in place before it lapsed. Here is one.
ISO 27001 risk acceptance for vulnerabilities: the risk owner accepts in their own name, against your criteria, on that day's KEV and EPSS, until a review-by date.
PCI DSS 6.3.3 gives a critical patch one month from release, and PCI SSC FAQ 1572 says a missed control cannot be backdated. Keep dated evidence behind every compensating control.
Under NIST SP 800-37, accepted risk stays in the assessment reports, not the POA&M. A dated decision record holds that evidence and your CSF 2.0 exceptions.
FedRAMP's 2026 rules replace the POA&M and deviation requests with accepted vulnerabilities. Prove when each evaluation closed and why you accepted it.
Customer security questionnaire asking for a vulnerability exception? Answer the CAIQ GRC-04.1 follow-up by granting one approved exception to one named analyst.
Whatever the standard, an exception that survives a sample runs the same five steps and leaves the same seven fields. They can live on a form, in a ticket or in a record. What matters is that each one exists, carries its date, and could not have been written later.
Someone asks to leave a CVE open. The request names the CVE and where it applies: which systems, which versions, which scope.
KEV listing and due date, EPSS, the public exploit and the fixed version are frozen beside the request, each with the day its source published it. Our server sets the date.
The person your policy names makes one call: accept, defer, patch by a date, mitigated, or not affected. The record names them.
The rationale says what protects the system meanwhile: a WAF rule tonight, the patch in the next window.
Renew it as a new version on that day's evidence, or close it as patched. The first call stays readable beside the latest.
Those five steps fill seven fields. If you came looking for a risk acceptance form, this is the form.
Two properties no form has. Every change is a new version that carries the previous version's SHA-256, so the first call stays readable beside the latest. And a watch alerts you when KEV or EPSS moves materially. Your new call is a new version in the same chain. Nothing you deferred moves in silence.
The seven fields are an open format, free to keep in your own repo. The template and what a decision record holds.
Whatever your security exception process says on paper, when the sample lands the exception usually lives in one of four places. Each shows that someone decided. None shows what they were looking at when they did.
The issue history dates every change, so the auditor can see when the comment went in. It cannot show what KEV and EPSS said that day, and it lives in a project you administer and can delete. Keep the ticket. The record takes the same comment as its rationale, adds a verdict and a review-by date, freezes that day's evidence for you, and hands back a proof link for the ticket.
Paste the comment as the rationale. Free for your first 100 exceptions, under $5 each on Practitioner.
Already carrying dozens? The API and MCP server take them from your tracker, and each still takes its date from our server on the day it arrives.
Slack dates the message. It does not show who held the authority to approve, the thread never said what was known about the CVE, and a retention setting can remove it before the next audit.
Whoever last looked pasted a number. The source has moved since, so the row reads as though you ignored today's figure.
A signed PDF shows who agreed. It cannot show the signature came before the deadline, or what was known about the CVE when it was signed.
Two of the four carry a timestamp you can trust. None carries the evidence, and all four live in systems you administer. The record sits outside them, with that day's evidence frozen beside the call.
Take the week most security teams remember. CVE-2021-44228, Log4Shell. This is the public record for that week as the CVE page lists it today, each value dated by its source:
Replay that week as if the record had existed. On the 13th a team knows Log4Shell is KEV-listed with a due date of the 24th, and that an exploit is public. The internet-facing services are patched that night. The internal ones are deferred to the due date behind a WAF rule, named as the compensating control, with a review on the 20th. EPSS that day is 0.19. On the 14th it crosses 0.50 and the watch alerts the team with the new value and its date. On the 17th it alerts again at 0.92. Each new call the team makes is a new version in the same chain, and the first call stays readable. On the 24th the team records the patch as a new version, or re-accepts with a new date. Years later EPSS reads 0.99999, and without a record every one of those calls gets judged against that number. That is a replay: a real record carries the day it was made, never an earlier one.
Reads the recorded date against the deadline your own policy set. On time is the control operating. Late is a deviation.
Checks who decided against the risk owner your ISMS names, then the review-by date, and whether a new version followed each time the evidence moved.
Reads the fixed version as it stood that day and the compensating control you named, then re-validates the control at the next annual assessment.
Finds the accept verdict that never reached the POA&M, beside the risk factors it was weighed against.
Reads the explanation, and a timestamp you did not set for when the call was made.
Gets the one record you chose to send, dated before the questionnaire arrived, and nothing else from your register.
Same record, six readers. None has to take your word for the facts, because every value names its public source and the day that source published it: CISA, FIRST, the CVE record. The day's evidence is hashed with the record, and anyone can recompute the hash to see it is intact. None has to take ours for the chain, because the export verifies with a standalone script that imports nothing from our code, and a changed character anywhere fails it by name.
We produce the evidence artifact an obligation asks for. We do not make anyone compliant with anything. The opinion, the finding and the sign-off are always the auditor's.
One record per exception, carrying the seven fields above, in a chain with no edit and no delete. Every change is a new version.
Its accept-risk setting records that you accepted, in a tenant you administer. It is not built to freeze what KEV, EPSS and the fixed version said that day. The record dates the decision and holds that evidence beside it.
The policy, the SLA and the risk register are yours. The record is what one line of the register points to when a sample lands on it.
A record made after the deadline says so on its face. That is why one made before it is worth something.
Exceptions you already carry do not get re-keyed by hand, and importing them does not backdate them. A record that reaches the append-only API or the MCP server from your scanner or tracker is dated the day it arrives, never from the import. The evidence owner's own view is on the compliance and audit page.
The alternative is not free. It is a GRC suite seat bought to hold one control, or an engineer rebuilding the story from Slack and Jira the week the auditor arrives. A rebuilt story still cannot show it matches what was true on the day. Plans are counted in records, one per exception, and every plan includes the API. A renewal, an amendment or a new call on the same exception is a new version of that record and does not use up another. Free keeps 100, so your first 100 exceptions cost nothing. Practitioner holds 500 for $2,490 a year ($249 a month, or $1,245 in the founding first year): under $5 an exception. Custody has no limit, for $20,000 a year, or $10,000 at the founding rate.
With Custody, an auditor who samples five exceptions opens those five records directly through the grant, and nothing else. A dated receipt of each opening joins the chain. That replaces five sets of screenshots assembled the week before fieldwork.
Each one takes a date our server sets and that day's KEV status, EPSS, weakness class and fixed versions, frozen beside the call. When the next sample lands, you hand over records made before anyone asked. Start with Log4Shell, or type a CVE from your register. Sign in with email, Google or GitHub. The first 100 records are free.