What the 192-day rule means
The clock runs from evaluationCompletedAt. The rule applies when a vulnerability has not been fully mitigated or remediated within 192 days, or when the provider already knows it will not meet that boundary.
Do not wait until day 192 to discover the problem. Track the projected remediation date and flag records that are expected to cross the boundary early enough for review.
Required accepted-vulnerability information
- Provider tracking identifier.
- Detection time and source.
- Evaluation completion time.
- Internet-reachable classification.
- Likely exploitable classification.
- Current Potential Agency Impact N-rating.
- Explanation of why the vulnerability is accepted.
- Supplementary information that responsibly helps agencies assess or mitigate customer risk.
Acceptance does not erase response work
A vulnerability can be fully mitigated yet remain present and unremediated. Preserve the controls that reduced PAIN, their validation evidence, the residual risk, the replacement or remediation path, and review ownership.
Known Exploited Vulnerabilities retain their CISA remediation due dates. A compensating control should not silently convert a KEV deadline into an indefinite acceptance.
A defensible review packet
| Record | What it should establish |
|---|---|
| Acceptance rationale | Why the vulnerability remains and why continued operation is justified. |
| Residual-risk analysis | Current PAIN and the evidence supporting reachability and exploitability decisions. |
| Mitigation evidence | Controls that reduced risk and proof they continue to operate. |
| Customer guidance | Responsible information agencies can use to reduce their own risk. |
| Decision owner and review date | Who accepted the residual risk and when it will be reconsidered. |
| Remediation path | Replacement, vendor dependency, or engineering milestones toward elimination. |