The Hidden Cost Explosion
AI is exploding the volume of security findings and fixes. But every one still has to become proof: reviewed, approved, evidenced, and defensible to customers, suppliers, auditors, regulators, and insurers. The security back office was never built to scale manually at this speed.
See why security admin work is compounding.
CVE submission growth
NIST reported CVE submissions increased 263% from 2020 to 2025.vendor assessment work each week
Whistic 2025 TPRM survey: average weekly vendor-assessment work.initial assessments needing follow-up
Whistic 2025 TPRM survey: initial supplier assessments requiring follow-up.reporting clocks
NIS2 and Cyber Resilience Act reporting sequences include 24-hour early warning and 72-hour notification windows.More findings do not automatically mean more clarity.
NVD records, CISA KEV, and EPSS compare broad vulnerability volume with public actionability signals. The point is downstream triage load, not a complete vulnerability census.
Finding volume is an input stream, not the work itself.
Public evidence is strongest at the infrastructure level: more CVEs are entering the system, and the actionable exploited subset remains much smaller than the total universe teams have to screen.
CVE submission growth
NIST reported CVE submissions increased from 2020 to 2025.
CVEs enriched in 2025
NIST also reported this was 45% more than any prior year.
known exploited vulnerabilities in CISA KEV
Current public catalog count from CISA's KEV feed.
KEVs added in 2025
Known exploited vulnerabilities added to CISA KEV during 2025.
Default NVD builds are bounded for local reliability. Use full backfill before making publication-grade trend claims.
How to read this exhibit
The exhibit separates broad CVE visibility from the smaller exploited subset teams use for prioritization.
- CVEs show the broad input stream.
- KEV shows the smaller exploited subset.
- The administrative work is deciding what matters locally.
Optimization target: economic impact, not just passing proof.
Evident's trust graph should not stop when proof exists. It should ask whether proof was rejected, whether an incident created real cost, whether admin cost missed its target, and where reusable evidence can reduce the next cycle.
Sources behind the public numbers.
Public claims stay attached to the reports, regulator materials, and standards references used for the figures and clocks above.