3 ms·
The latest contract[1] (I hope this is the right one) for MITRE's involvement with CVE and CWE programs was USD$29.1m for the period 2024-04-17 to 2025-04-16 wi
by dhx 1y ago
The latest contract[1] (I hope this is the right one) for MITRE's involvement with CVE and CWE programs was USD$29.1m for the period 2024-04-17 to 2025-04-16 with optional extension of expenditure up to USD$57.8m and to an end date of 2026-04-16.
Seemingly MITRE hasn't been advised yet whether the option to extend the contract from 2025-04-16 to 2026-04-16 will be executed. And there doesn't appear to be any other publicly listed approach to market for a replacement contract.
[1] https://www.fpds.gov/ezsearch/jsp/viewLinkController.jsp?agencyID=7001&PIID=70RCSJ24FR0000018&modNumber=0&transactionNumber=0&idvAgencyID=7001&idvPIID=70RSAT20D00000001&actionSource=searchScreen&actionCode=&documentVersion=1.5&contractType=AWARD&docType=C https://www.fpds.gov/ezsearch/jsp/viewLinkController.jsp?age...
- gwd 1y agoI can't figure out why the hue and cry wasn't raised until the very last minute. Did they not know a month ago that they were running out of time? Is it standard practice for the government not to say they're going to extend the contract until the day beforehand or something?
- sq_ 1y agoRight now, yes. You can pretty easily have a scenario where you’re talking to the agency you’re working with and they’re saying “we want to renew this, but we don’t know if they’ll give us the money in the end”. So you’ll get a bunch of “hopefully this week” up until it expires.
- pjmorris 1y agoI was at VulnCon last week, and an NIST representative said that there were no plans to cut CVE funding.
- breck 1y ago[dead]