YES, IT'S VERMARCABLE
Cybersecurity: Vulnerability Registries, Agencies & Standards Bodies
A free directory of the registries, agencies, and standards bodies that anchor cybersecurity — CISA, NIST and the NVD, MITRE and the CVE Program, FIRST, CERT/CC, OWASP, ISO, ENISA, the NSA, and the FBI's IC3. Each entry lists the body's role, jurisdiction, and official URL. Platform-curated public-domain reference data, free for security engineers, GRC teams, and incident responders.
{
"_type": "curated_open_data",
"as_of": "2026-07",
"links": {
"canonical": "https://verticalmarketplace.ai",
"docs_for_llms": "https://verticalmarketplace.ai/llms.txt",
"sell_your_own": "https://verticalmarketplace.ai/api/marketplace/listings",
"vertical_listings": "https://verticalmarketplace.ai/api/marketplace/listings?vertical=cybersecurity"
},
"records": [
{
"url": "https://www.cisa.gov",
"name": "CISA",
"role": "U.S. cyber defense agency; advisories and the KEV catalog",
"jurisdiction": "U.S. federal"
},
{
"url": "https://www.nist.gov/cyberframework",
"name": "NIST",
"role": "Cybersecurity Framework and the SP 800 guidance series",
"jurisdiction": "U.S. federal"
},
{
"url": "https://nvd.nist.gov",
"name": "National Vulnerability Database (NVD)",
"role": "U.S. repository of CVE data with CVSS scoring",
"jurisdiction": "U.S. federal"
},
{
"url": "https://www.mitre.org",
"name": "MITRE Corporation",
"role": "Operates the CVE Program and the ATT&CK knowledge base",
"jurisdiction": "United States (federally funded)"
},
{
"url": "https://www.cve.org",
"name": "CVE Program",
"role": "Assigns and publishes Common Vulnerabilities and Exposures IDs",
"jurisdiction": "International"
},
{
"url": "https://www.first.org",
"name": "FIRST",
"role": "Maintains CVSS and coordinates incident-response teams",
"jurisdiction": "International"
},
{
"url": "https://www.sei.cmu.edu/about/divisions/cert",
"name": "CERT Coordination Center (CERT/CC)",
"role": "Vulnerability coordination at Carnegie Mellon SEI",
"jurisdiction": "United States"
},
{
"url": "https://owasp.org",
"name": "OWASP",
"role": "Open community and the OWASP Top Ten web risks",
"jurisdiction": "International (nonprofit)"
},
{
"url": "https://www.iso.org",
"name": "ISO/IEC 27001",
"role": "International standard for information security management",
"jurisdiction": "International"
},
{
"url": "https://www.enisa.europa.eu",
"name": "ENISA",
"role": "European Union Agency for Cybersecurity",
"jurisdiction": "European Union"
},
{
"url": "https://www.nsa.gov/cybersecurity",
"name": "National Security Agency (Cybersecurity)",
"role": "Cybersecurity guidance and advisories",
"jurisdiction": "U.S. federal"
},
{
"url": "https://www.ic3.gov",
"name": "FBI Internet Crime Complaint Center (IC3)",
"role": "Collects cybercrime complaints and publishes annual reports",
"jurisdiction": "U.S. federal"
},
{
"url": "https://www.cisecurity.org",
"name": "Center for Internet Security (CIS)",
"role": "Publishes the CIS Controls and hardening Benchmarks",
"jurisdiction": "United States (nonprofit)"
},
{
"url": "https://www.sans.org",
"name": "SANS Institute",
"role": "Security training and the Internet Storm Center",
"jurisdiction": "United States"
}
],
"sources": [
{
"url": "https://www.cisa.gov",
"name": "CISA"
},
{
"url": "https://www.cve.org",
"name": "MITRE CVE Program"
},
{
"url": "https://www.first.org",
"name": "FIRST"
}
],
"category": "directory",
"vertical": "cybersecurity",
"data_note": "All records are public-domain facts compiled from the cited sources as of the asOf date. This content is authored and served by the platform itself — it is not seller data, so the marketplace's zero-storage promise about seller datasets is unaffected.",
"record_count": 14,
"what_this_is": "A platform-published open-data listing curated by Open Data Desk, the marketplace's in-house public-data seller. It is real free inventory: it counts in marketplace statistics and is purchasable for $0 through the normal purchase flow, which delivers this payload with an Ed25519-signed receipt.",
"record_schema": {
"url": "Official website",
"name": "Official name of the registry, agency, or body",
"role": "What it publishes, coordinates, or standardizes",
"jurisdiction": "Scope of authority"
},
"buyer_use_cases": [
"Route vulnerability and incident questions to the correct authority",
"Build a control-mapping reference across NIST, ISO, and CIS",
"Onboard analysts to the registries that underpin threat intelligence"
]
}The full dataset is delivered after purchase. Fingerprint: sha256:339aead726bf920cd0e579fbbaa380919f1f5d33d5cb0636f86aeb603550a1a0
No answered questions yet — ask the seller anything about this listing.
Data is contributed by independent third-party sellers. Vertical Marketplace facilitates the transaction; sellers keep 95% on everyday sales from $20 to $49,999.99 under the year-one founding rate locked through 2027-06-30 (full schedule: GET /api/meta). Prohibited content (digital keys/licenses/game codes, and health data the seller does not own — e.g. patient records) is not permitted; individuals may sell their own personal health data only via the signed Health Data Consent Flow. See /terms.
- Use the purchased data for your own commercial and non-commercial work
- Create derivative analyses, models, and works from the data
- No reselling or re-listing the purchased data on this or any other marketplace
- No redistributing the raw dataset as-is to third parties
- Exclusive listings are sold to a single buyer and delisted on purchase
- Limited listings are sold to a capped number of buyers and delisted once sold out
No key? Register an agent — it's free.
For agents — buy by prompt
Bring your own agent. Open HTTP API + MCP — works with compatible agent runtimes that support the required API calls and authentication. Vermarco is not affiliated with, endorsed by, or partnered with Anthropic, OpenAI, Google, xAI, or Perplexity. One-click consumer-app connectors are not built yet; connect via API key or MCP from your agent runtime.