Whats New in CSAF v2.1: Key Updates Explained @FIRSTdotorg
Whats New in CSAF v2.1: Key Updates Explained  @FIRSTdotorg
Uploaded August 2025 | Updated September 2026, 2 hours ago
Justin Murphy (DHS/CISA, US), Thomas Schmidt (BSI, DE)

Justin Murphy is a Vulnerability Analyst with the Cybersecurity and Infrastructure Security Agency (CISA). He helps to coordinate the remediation, mitigation, and public disclosure of newly identified cybersecurity vulnerabilities in products and services with affected vendor(s), ranging from industrial control systems (ICS), operational technology (OT), medical devices, and traditional information technology (IT) vulnerabilities. Justin is involved with many other vulnerability management related efforts, including CISA's Software Bill of Materials (SBOM) and Vulnerability Exploitability eXchange (VEX) work, and he serves as a co-chair for the OASIS Common Security Advisory Framework (CSAF) and OpenEoX Technical Committees. Justin is also the co-founder of the Global Community of Practice on Coordinated Vulnerability Disclosure (Global CVD-COP). Justin is a former high school mathematics teacher turned cybersecurity professional and has a M.Sc. in Computer Science from Tennessee Technological University, and a B.Sc. degree in Statistics from the University of Tennessee (Knoxville).

Thomas Schmidt works in the 'Industrial Automation and Control Systems' section of the German Federal Office for Information Security (BSI). His focus is the automation of advisories at both sides: vendors/CERTs and asset owners. Schmidt has been a leader in the OASIS Open CSAF technical committee, and key in bridging this work with the CISA SBOM work. Prior to this, Schmidt was BSI's lead analyst for TRITION/TRISIS/HatMan and developed, together with partners, a rule set for Recognizing Anomalies in Protocols of Safety Networks: Schneider Electric's TriStation (RAPSN SETS). To increase security of ICS and the broader ecosystem, BSI responsibilities cover many areas including establishing trust and good relations with vendors and asset owners. Mr. Schmidt completed his masters in IT-Security at Ruhr-University Bochum (Germany) which included a period of research at the SCADA Security Laboratory of Queensland University of Technology (Brisbane, Australia).
--
The Common Security Advisory Framework (CSAF), an international, open standard for producing, distributing, and discovering machine-readable security advisories has been making strides in enhancing transparency and efficiency for vulnerability management processes.This talk will explore the key changes introduced in CSAF v2.1 compared to CSAF v2.0, highlighting the enhanced capabilities and flexibility of the new version. Through concrete examples, the presentation will demonstrate what can now be achieved with CSAF v2.1 that was either not possible or more challenging with CSAF v2.0. Specific focus will be given to new features, support for other updated standards like CVSS and TLP, shifting of perspectives (score to metrics, cwe to cwes, etc.), and incorporating support for the Exploit Prediction Scoring System (EPSS) and Stakeholder Specific Vulnerability Categorization (SSVC) frameworks. The session will also address migration strategies, tooling needs and updates, easy conversion, and offer practical scenarios for moving CSAF v2.0 content to v2.1, ensuring organizations can smoothly adopt the updated standard while maximizing its benefits. As the number of vulnerabilities identified rapidly increase, possibly at an exponential rate, this talk is essential for those looking to stay ahead in vulnerability management and make the most of CSAF v2.1's new features.
Whats New in CSAF v2.1: Key Updates ExplainedArcana: A Unified Framework for Incident Response Documentation and Knowledge ManagementFrom Discovery to Fix: What 10,000 Open Source Projects Reveal About CVE RemediationLightning Talks!Anti-Forensics - You are Doing it Wrong (Believe Me, Im an IR Consultant)What Can Cybersecurity Incident Responders Learn from Real-World Crises?Enhancing Incident Response with AWS CIRT, MSSPs, and ISVsEpisode 55: Merike Kaeo, FIRSTCON26 Program ChairProactive EDR Against Adaptive Evasion: Countering Self‑Modifying Agentic MalwareProduction Is the New Attack Surface: Why Post-Deployment Endpoint Detection Is Now CriticalOROCHIFY - An Assist to Product Developers in Manufacturing Industry to Find VulnerabilitiesRemediation-Aware Reachability: Patching Containers, Prioritizing with Agentic-CTI, and Scaling...
FIRST |

What's New in CSAF v2.1: Key Updates Explained

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER