Indeed. At least for the contractual requirement, the KEV format (BCP-07) can be used to inform customers (even if the KEV is not disclosed outside the customer-vendor relationship). I suppose some extension in the KEV assertion can be indeed added.
By the way, I did a quick mapping of CRA obligations and how GCVE can support it at the following location:
If you have any feedback or updates, feel free. Thank you!
It’s a pretty good document for the procurement aspect which is often neglected. I’m curious if we could generate a machine parseable output of all the controls points. Do you know the license of the document? and if we can freely reuse/redistribute the content? It’s clearly outside the KEV BCP-07 but it could be useful as reference point for the BCP-02 at least in the GCVE ecosystem.
A machine readable version of the CISA SAG controls is already available, along with an open source reader to process “batches” of SAG-spreadsheet responses in Excel format;
GCVE-BCP-07 - Known Exploited Vulnerability - KEV Assertion Format updated to version 2.1
Following the PTS 2026 workshop in Lille, a new version of GCVE-BCP-07 has been published.
This version introduces the index reference file format, available at https://gcve.eu/dist/references.json, and adds new metadata fields, including licenses, as requested by ENISA.
The index is a catalogue of KEV catalogues. It is not authoritative for the content of any listed catalogue and it is not required for a producer to publish BCP-07 KEV assertions. Its purpose is to facilitate discovery, correlation, and stable attribution of KEV catalogues, especially where gcve.origin_uuid or evidence[].gcve.origin_uuid values need to be resolved to a known source.