Patch SLA windows, exception process, and KEV automatic uplift.
| Severity | Patch deadline | Exception max |
|---|---|---|
| Critical | 7 days | 14 days (with approval) |
| High | 30 days | 60 days |
| Medium | 90 days | 180 days |
| Low | 365 days | indefinite |
If a CVE is in CISA's KEV catalog, severity auto-elevates to Critical regardless of CVSS score.
original_deadline + grant_days4. Auto-reminder at T-7 days
5. Z.395 audit chain appends the exception decision
/api/v1/v27/platform/overview reports patch SLA breach count.
/api/v1/v25/support/kb?category=vuln-mgmt returns related articles.