kbrain

Use case

Vulnerability tracking for NIS2 and the Cyber Resilience Act with AI

Teams working under NIS2 and the EU Cyber Resilience Act can query CVEs, CISA KEV, EPSS, and the ENISA EUVD from their AI assistant, with the EU cross-reference on every record and no setup.

Add the CVE brain to your AI assistant

The NIS2 Directive and the EU Cyber Resilience Act (CRA) have raised the bar for how organisations handle vulnerabilities. Teams need to understand a vulnerability quickly, know whether it is being exploited, and reference it in EU terms. The CVE brain helps with the day-to-day of that work: it answers CVE questions from current data and adds the EU Vulnerability Database (ENISA EUVD) cross-reference on every record.

Where the EU cross-reference fits

  • The ENISA EUVD is the EU's own vulnerability database, established in the context of NIS2. Having the EUVD id beside the CVE makes it easy to move between EU and global references.
  • For triage, the brain still leads with confirmed exploitation (CISA KEV) and likelihood (EPSS), then layers CVSS impact and the EU cross-reference on top.
  • Every answer carries a last-updated timestamp, which matters when a decision has to be defensible.

What it does not do

This brain is a lookup and triage aid, not a compliance product. It does not file reports, assess your specific systems, or make a legal determination about NIS2 or CRA obligations. It gives an EU-aware, always-current view of a vulnerability so the people doing that work can move faster.

Treat the EUVD cross-reference as context, not as a compliance record. For obligations under NIS2 or the CRA, follow your own process and the official ENISA and national sources.

Questions to try

  • "Is CVE-2024-3400 in the EU EUVD, and is it flagged exploited by ENISA?"
  • "Give me the CVE and EUVD id for this advisory, plus its CISA KEV status."
  • "What critical CVEs from the last week are tracked in the EUVD?"

Add the CVE brain to your AI assistant

Look up CVEs, CISA KEV exploited status, and EPSS scores from Claude, ChatGPT, or any MCP compatible assistant. Hosted and refreshed daily, with no self-hosting and no API keys to manage.

Frequently asked questions

Does the CVE brain make us NIS2 or CRA compliant?

No. It is a vulnerability lookup and triage aid, not a compliance product. It gives an EU-aware, current view of a vulnerability, including the ENISA EUVD cross-reference, to support the people doing that work.

Why does the EU cross-reference matter for these frameworks?

NIS2 and the CRA increase the focus on vulnerability handling in the EU, and the ENISA EUVD is the EU's vulnerability database. Having the EUVD id beside the CVE makes it easy to move between EU and global references when documenting or discussing a vulnerability.

Where does the EUVD data come from?

From the ENISA EU Vulnerability Database, refreshed daily and joined onto each CVE by the CVE id that EUVD entries cross-reference.