CWE

Common Weakness Enumeration

A community-developed list of SW & HW weaknesses that can become vulnerabilities

New to CWE? click here!
CWE Most Important Hardware Weaknesses
CWE Top 25 Most Dangerous Weaknesses
Home > Compatibility > CWE Compatibility Program  
ID

CWE Compatibility Program

Introduction

The CWE Compatibility Program is a process for organizations wishing to declare their information security products and services as CWE-Compatible and have them posted on the "CWE-Compatible Products and Services" page on the CWE website.

The CWE Compatibility Program includes three phases: Declaration, Evaluation, and Publication.

Phase 1 – Declaration Phase

The Declaration Phase requires the completion of a short informational "CWE Compatibility Declaration Form" used to register an organization's declaration of intent with respect to CWE compatibility. In this phase you are asked to review the compatibility requirements and then make a statement regarding whether your organization believes that its product or service currently fulfills the compatibility requirements, or if your organization is working towards fulfilling the requirements. As long as the products or services are commercially or publicly available, the declaration and an endorsement quote from you (if desired) is posted on the CWE website.

Phase 2 – Evaluation Phase

The Evaluation Phase requires completion of Phase 1 with "yes" as the answer for support of CWE output, CWE searchable, and CWE documentation. A major component of this phase requires specific details about how your organization has satisfied each of the mandatory requirements in the Requirements and Recommendations for CWE Compatibility document. The Phase 2 "CWE Compatibility Requirements Evaluation Form" also requires the signature of an authorized representative of your organization.

Phase 3 – Publication Phase

Once your organization’s detailed statement describing how your product or service fulfills the requirements for CWE compatibility is received by the CWE Program, that statement will be scheduled for posting on the CWE website. Phase 1 and Phase 2 must be completed before Phase 3 can occur.

Contact and Submission Instructions

To begin the registration process, review the official CWE Compatibility Program detailed above then send an email to cwe@mitre.org requesting the Declaration Form along with your company name and contact information, the type of product, and the name of the product or service.

You will receive specific instructions for completing and submitting additional information as the process continues.

Page Last Updated: June 06, 2023