Increasing Vulnerability Transparency with Supplier-ADP
Since 2024, the Cybersecurity and Infrastructure Security Agency (CISA) has implemented the “Vulnrichment” program to enrich CVE data with additional information. The goal is to give additional context and help defenders in assessing the specific risk of these vulnerabilities. Each CVE from cve.org or github has an Authorized Data Publisher (ADP) container where this data is stored.
As a next level, Siemens PSIRT was advocating a further extension of this: The Supplier-ADP (SADP), which was piloted in the last months and finally introduced in April 2026. The SADP comes handy if a supplier like Siemens wants to add information to a vulnerability, which originates in an upstream dependency.