Stakeholder-Specific Vulnerability Categorization (SSVC)
A decision model, used by CISA, that prioritizes a vulnerability using factors such as active exploitation status and automatability rather than a single static score. Because those inputs change over time, an SSVC decision can escalate a bug that a fixed CVSS score would leave unchanged.