vciy
Vulnerability exceptions, by standard

They sampled the vulnerability you deferred. Hand over the exception, dated before they asked.

The question is always who decided, when, and on what they knew that day. A decision record answers all three: it names who made the call, takes a date our server sets and no caller can supply, and freezes that day's evidence beside the call, hashed. A watch alerts you when KEV or EPSS moves. Every standard lets you carry an exception, each on its own terms. None of them lets you backdate the decision.

Already sampled? What to hand over tonight. On call tonight? The written reason goes in a decision record, and the proof link goes in your ticket. Write tonight's reason.

Try it on CVE-2021-44228

Record the exception you are carrying. Start with Log4Shell.

The record opens with that CVE's facts already filled in: KEV status, EPSS and its date, weakness class, fixed versions, each from its public source. Our server dates it. Sign in with email, Google or GitHub to keep it. The first 100 records are free.

On call tonight

The written reason: four fields, while the incident is open.

Four fields to type: scope, verdict, one sentence of rationale, a review-by date. The evidence, the date and your name are filled. Name what holds the line in the rationale, then paste the proof link into the ticket. A call made last night is recorded now: it carries today's date, and the rationale says when you decided.

Pick Mitigated if something holds the line tonight, or Patch by a date if the fix is scheduled.

Sign in with email, Google or GitHub. The first 100 records are free.

Already in the sample

You cannot make last spring's record now.

We will not pretend you can. Hand over the approval you have, from the ticket or the form, with the CVE page beside it. The page is public and needs no account. Its dated events show what KEV and EPSS said on the day you decided, each dated by its source, so the auditor checks your account against CISA and FIRST rather than against you. Then record today's review of the exception you still carry. It is dated today because it is today's decision, and it covers the next deadline.

01

Pick your standard. Each one has its own page.

Six standards, and each asks a different question about the same exception. Each one has its own page: the clause, what the auditor actually requests, and a worked example on a real CVE. Pick yours.

SOC 2 · 2017 Trust Services Criteria, points of focus revised 2022

Your policy sets the deadline. In a SOC 2 type 2, the exception has to be approved before it.

How a SOC 2 type 2 auditor tests vulnerability exceptions: each finding past your own SLA needs an approval in place before it lapsed. Here is one.

ISO/IEC 27001:2022 · Clause 6.1.3 f) · Annex A 8.8

ISO 27001 risk acceptance turns on who accepted. The sample checks it was the risk owner.

ISO 27001 risk acceptance for vulnerabilities: the risk owner accepts in their own name, against your criteria, on that day's KEV and EPSS, until a review-by date.

PCI DSS v4.0.1 · 6.3.1 · 6.3.3 · 11.3.1 · Appendices B and C

PCI DSS 6.3.3 gives a critical patch one month from release. The QSA asks what you knew on day one.

PCI DSS 6.3.3 gives a critical patch one month from release, and PCI SSC FAQ 1572 says a missed control cannot be backdated. Keep dated evidence behind every compensating control.

NIST SP 800-53 Rev. 5, Release 5.2.0 · CSF 2.0

NIST 800-53: The POA&M tracks what you will fix. RA-7 asks what you decided.

Under NIST SP 800-37, accepted risk stays in the assessment reports, not the POA&M. A dated decision record holds that evidence and your CSF 2.0 exceptions.

FedRAMP · Vulnerability Detection and Response · Vulnerability Evaluation and Reporting · mandatory 7 December 2026

Nobody approves a FedRAMP accepted vulnerability. So the date has to prove itself.

FedRAMP's 2026 rules replace the POA&M and deviation requests with accepted vulnerabilities. Prove when each evaluation closed and why you accepted it.

Customer security questionnaires · CAIQ v4.1 · SIG · HECVAT

Your security questionnaire said Yes. Now they want the exception.

Customer security questionnaire asking for a vulnerability exception? Answer the CAIQ GRC-04.1 follow-up by granting one approved exception to one named analyst.

02

A vulnerability exception process, step by step.

Whatever the standard, an exception that survives a sample runs the same five steps and leaves the same seven fields. They can live on a form, in a ticket or in a record. What matters is that each one exists, carries its date, and could not have been written later.

1. Request

Subject

Someone asks to leave a CVE open. The request names the CVE and where it applies: which systems, which versions, which scope.

2. Evidence frozen that day

EvidenceDate

KEV listing and due date, EPSS, the public exploit and the fixed version are frozen beside the request, each with the day its source published it. Our server sets the date.

3. Named owner approves

VerdictActor

The person your policy names makes one call: accept, defer, patch by a date, mitigated, or not affected. The record names them.

4. Compensating control holds the line

Rationale

The rationale says what protects the system meanwhile: a WAF rule tonight, the patch in the next window.

5. Review-by date comes due

Review by

Renew it as a new version on that day's evidence, or close it as patched. The first call stays readable beside the latest.

Those five steps fill seven fields. If you came looking for a risk acceptance form, this is the form.

Subject
the CVE, and where it applieswhich systems, which versions, which scope
Evidence
what the public record said that dayKEV listing and due date, EPSS and its date, public exploit, affected ranges, fixed version, each with the day its source published it
Verdict
accept, defer, patch by, mitigated, not affectedone call, stated plainly
Rationale
why, and what holds the line meanwhilethe compensating control goes here: a WAF rule tonight, the patch in the next window
Actor
who decidedyour policy says who may, at what severity; the record names the person, so the auditor can check one against the other
Date
when, set by our serverno caller can supply one, you included
Review by
when it must be looked at againa deferral is not permanent, and this is where it expires

Two properties no form has. Every change is a new version that carries the previous version's SHA-256, so the first call stays readable beside the latest. And a watch alerts you when KEV or EPSS moves materially. Your new call is a new version in the same chain. Nothing you deferred moves in silence.

The seven fields are an open format, free to keep in your own repo. The template and what a decision record holds.

03

What gets handed over today, and why it fails.

Whatever your security exception process says on paper, when the sample lands the exception usually lives in one of four places. Each shows that someone decided. None shows what they were looking at when they did.

The Jira ticket

“Low risk, deferring.”

The issue history dates every change, so the auditor can see when the comment went in. It cannot show what KEV and EPSS said that day, and it lives in a project you administer and can delete. Keep the ticket. The record takes the same comment as its rationale, adds a verdict and a review-by date, freezes that day's evidence for you, and hands back a proof link for the ticket.

Paste the comment as the rationale. Free for your first 100 exceptions, under $5 each on Practitioner.

Already carrying dozens? The API and MCP server take them from your tracker, and each still takes its date from our server on the day it arrives.

The Slack thread

The approval is a thumbs-up.

Slack dates the message. It does not show who held the authority to approve, the thread never said what was known about the CVE, and a retention setting can remove it before the next audit.

The spreadsheet row

The EPSS score has no date.

Whoever last looked pasted a number. The source has moved since, so the row reads as though you ignored today's figure.

The risk acceptance form

The date is whatever the signer typed.

A signed PDF shows who agreed. It cannot show the signature came before the deadline, or what was known about the CVE when it was signed.

Two of the four carry a timestamp you can trust. None carries the evidence, and all four live in systems you administer. The record sits outside them, with that day's evidence frozen beside the call.

04

One record, read six ways.

Take the week most security teams remember. CVE-2021-44228, Log4Shell. This is the public record for that week as the CVE page lists it today, each value dated by its source:

Public exploit
2021-12-09proof of concept, public
Published
2021-12-10CVE record
CISA KEV
listed 2021-12-10remediation due 2021-12-24
EPSS, 13 December
0.19FIRST, dated series
EPSS, 14 December
0.50FIRST, dated series
EPSS, 17 December
0.92FIRST, dated series

Replay that week as if the record had existed. On the 13th a team knows Log4Shell is KEV-listed with a due date of the 24th, and that an exploit is public. The internet-facing services are patched that night. The internal ones are deferred to the due date behind a WAF rule, named as the compensating control, with a review on the 20th. EPSS that day is 0.19. On the 14th it crosses 0.50 and the watch alerts the team with the new value and its date. On the 17th it alerts again at 0.92. Each new call the team makes is a new version in the same chain, and the first call stays readable. On the 24th the team records the patch as a new version, or re-accepts with a new date. Years later EPSS reads 0.99999, and without a record every one of those calls gets judged against that number. That is a replay: a real record carries the day it was made, never an earlier one.

SOC 2 auditor

Before the SLA lapsed?

Reads the recorded date against the deadline your own policy set. On time is the control operating. Late is a deviation.

ISO auditor

Who accepted, and was it revisited?

Checks who decided against the risk owner your ISMS names, then the review-by date, and whether a new version followed each time the evidence moved.

QSA

What was the constraint?

Reads the fixed version as it stood that day and the compensating control you named, then re-validates the control at the next annual assessment.

NIST assessor

Where is the acceptance?

Finds the accept verdict that never reached the POA&M, beside the risk factors it was weighed against.

Agency reviewer, FedRAMP

Why is it accepted?

Reads the explanation, and a timestamp you did not set for when the call was made.

Customer risk analyst

Was this written for us?

Gets the one record you chose to send, dated before the questionnaire arrived, and nothing else from your register.

Same record, six readers. None has to take your word for the facts, because every value names its public source and the day that source published it: CISA, FIRST, the CVE record. The day's evidence is hashed with the record, and anyone can recompute the hash to see it is intact. None has to take ours for the chain, because the export verifies with a standalone script that imports nothing from our code, and a changed character anywhere fails it by name.

05

What this is, and where it stops.

We produce the evidence artifact an obligation asks for. We do not make anyone compliant with anything. The opinion, the finding and the sign-off are always the auditor's.

What it is

The dated decision

One record per exception, carrying the seven fields above, in a chain with no edit and no delete. Every change is a new version.

Not a scanner

Your scanner dates the detection

Its accept-risk setting records that you accepted, in a tenant you administer. It is not built to freeze what KEV, EPSS and the fixed version said that day. The record dates the decision and holds that evidence beside it.

Not a GRC platform

Your register stays yours

The policy, the SLA and the risk register are yours. The record is what one line of the register points to when a sample lands on it.

Not a retrofit

We do not backdate your history

A record made after the deadline says so on its face. That is why one made before it is worth something.

Exceptions you already carry do not get re-keyed by hand, and importing them does not backdate them. A record that reaches the append-only API or the MCP server from your scanner or tracker is dated the day it arrives, never from the import. The evidence owner's own view is on the compliance and audit page.

06

Cheaper than the week before fieldwork.

The alternative is not free. It is a GRC suite seat bought to hold one control, or an engineer rebuilding the story from Slack and Jira the week the auditor arrives. A rebuilt story still cannot show it matches what was true on the day. Plans are counted in records, one per exception, and every plan includes the API. A renewal, an amendment or a new call on the same exception is a new version of that record and does not use up another. Free keeps 100, so your first 100 exceptions cost nothing. Practitioner holds 500 for $2,490 a year ($249 a month, or $1,245 in the founding first year): under $5 an exception. Custody has no limit, for $20,000 a year, or $10,000 at the founding rate.

Free
$0 · 100 recordsthe artifact: dated records for the exceptions you already carry
Practitioner
$2,490 a year · 500 recordsa renewal, an amendment or a new call on the same exception is a new version of that record and does not use up another. The process, running: $249 a month, or $1,245 in the founding first year. Records come due at their review-by date, and a watch alerts you when KEV or EPSS moves.
Custody
$20,000 a year · no record limit$10,000 a year at the founding rate. Custody adds a shared register your team writes to, and a grant for your auditor: they open the sampled record themselves, and a dated receipt of what they opened joins the chain with their attestation. This is the tier for whoever hands records to an auditor.

With Custody, an auditor who samples five exceptions opens those five records directly through the grant, and nothing else. A dated receipt of each opening joins the chain. That replaces five sets of screenshots assembled the week before fieldwork.

Before the next sample

Record the exceptions you carry today.

Each one takes a date our server sets and that day's KEV status, EPSS, weakness class and fixed versions, frozen beside the call. When the next sample lands, you hand over records made before anyone asked. Start with Log4Shell, or type a CVE from your register. Sign in with email, Google or GitHub. The first 100 records are free.