NVD Banner
Vulnerabilities Checklists 800-53/800-53A Product Dictionary Impact Metrics Data Feeds Statistics
Home SCAP SCAP Validated Tools SCAP Events About Contact Vendor Comments
Mission and Overview
NVD is the U.S. government repository of standards based vulnerability management data. This data enables automation of vulnerability management, security measurement, and compliance (e.g. FISMA).
Resource Status

NVD contains:

55066 CVE Vulnerabilities
202Checklists
231 US-CERT Alerts
2690 US-CERT Vuln Notes
8140OVAL Queries

Last updated:  02/13/13

CVE Publication rate:

17 vulnerabilities / day
Email List

NVD provides five mailing lists to the public. For information and subscription instructions please visit NVD Mailing Lists

Workload Index
Vulnerability Workload Index: 8.05
About Us

NVD is a product of the NIST Computer Security Division and is sponsored by the Department of Homeland Security’s National Cyber Security Division. It supports the U.S. government multi-agency (OSD, DHS, NSA, DISA, and NIST) Information Security Automation Program. It is the U.S. government content repository for the Security Content Automation Protocol (SCAP).

Security Content Automation Protocol Validated Products

This webpage contains a list of products that have been validated by NIST as conforming to the Security Content Automation Protocol (SCAP) and its component standards. Click on the vendor or product name to see a full description of the products validation information and status.

Please visit the SCAP validation program webpage for a description of the validation process and information on the SCAP capabilities referenced in the table below. For more information relating to SCAP please visit http://scap.nist.gov.

Support for U.S. Government Programs

Federal Desktop Core Configuration Initiative

The U.S. Office of Management and Budget has required, in the July 31st, 2007 memorandum to Federal CIOs, that "Information technology providers must use S-CAP validated tools, as they become available, to certify their products do not alter these configurations, and agencies must use these tools when monitoring use of these configurations."

Situational Awareness and Incident Response SmartBUY

The General Services Administration is requiring SCAP validation within blanket purchase agreements for vulnerability and configuration management products (Solicitation Number: Reference-Number-QTA0-08-HC-B-0003).

Security Content Automation Protocol (SCAP) Validated Products
Product Vendor
Product Name
SCAP Validations
Security Analysis Solution
Security Configuration and Vulnerability Management Pack
BMC Automation Server
BMC BladeLogic Client Automation
CA IT Client Manager
CIS - Configuration Audit Tool
Core IMPACT Professional
Frontline Vulnerability Manager
Dell KACE K1000 System Management Appliance
Retina
SecureVue
Greenbone Networks GmbH Greenbone Security Manager
SCAP Scanner
LANDesk Patch Manager 9.0 Extensions for Federal Desktops
LANDesk Security Suite 9.0 Extensions for Federal Desktops
Patchlink Security Configuration Management for Patchlink Update
PatchLink Security Configuration Management for PatchLink Scan
Policy Auditor
Vulnerability Manager
System Center Configuration Manager Extensions for SCAP
Configuration Compliance Manager
IP360
NetIQ Secure Configuration Manager
Prism Microsystems Inc. EventTracker Enterprise
QualysGuard FDCC Scanner
Nexpose
Vulnerability Scanner
Shavlik Security Suite: NetChk Configure
Shavlik Security Suite: NetChk Protect
Enterprise Trust Server
SCAP Compliance Checker
policy management Control Compliance Suite
Symantec Risk Automation Suite
Xacta IA Manager (Xacta HostInfo)
Xacta IA Manager Continuous Assessment
Security Center
Secutor Magnus with ThreatView
Secutor Prime
S-CAT
Tripwire Enterprise
Resolution Manager
VMware vCenter Protect Essentials Government Edition (with SCAP Processor)
VMware vCenter Configuration Manager)





Laboratories Accredited to do SCAP Testing

The labs listed below have been accredited by the NIST National Voluntary Laboratory Accreditation Program (NVLAP) to perform SCAP validation testing. Click on the lab name to see a full listing of the lab's accredited scopes

NVLAP Accredited Independent SCAP Testing Laboratories
Laboratory Name
Accredited Testing Scopes
AEGISOLVE, Inc.
  • SCAP
  • CVE
  • CCE
  • CPE
  • CVSS
  • XCCDF
  • OVAL
ATSEC
  • SCAP
  • CVE
  • CCE
  • CPE
  • CVSS
  • XCCDF
  • OVAL
BAH
  • SCAP
  • CVE
  • CCE
  • CPE
  • CVSS
  • XCCDF
  • OVAL
COACT
  • SCAP
  • CVE
  • CCE
  • CPE
  • CVSS
  • XCCDF
  • OVAL
Cygnacom
  • SCAP
  • CVE
  • CCE
  • CPE
  • CVSS
  • XCCDF
  • OVAL
EWA - Canada
  • SCAP
  • CVE
  • CCE
  • CPE
  • CVSS
  • XCCDF
  • OVAL
ICSA Labs
  • SCAP
  • CVE
  • CCE
  • CPE
  • CVSS
  • XCCDF
  • OVAL
InfoGard
  • SCAP
  • CVE
  • CCE
  • CPE
  • CVSS
  • XCCDF
  • OVAL
SAIC
  • SCAP
  • CVE
  • CCE
  • CPE
  • CVSS
  • XCCDF
  • OVAL