# Cybersecurity and Infrastructure Security Agency

**Canonical:** https://apis.io/providers/cybersecurity-and-infrastructure-security-agency/  
**Website:** https://www.cisa.gov  
**APIs profiled:** 4

The Cybersecurity and Infrastructure Security Agency (CISA) is the United States federal civilian cybersecurity agency, part of the Department of Homeland Security. CISA reduces cybersecurity and physical security risk for the nation, coordinates federal civilian cyber defense, and partners with state, local, tribal, and territorial governments and the private sector. CISA publishes a number of public, unauthenticated machine-readable feeds, including the Known Exploited Vulnerabilities (KEV) catalog (mandatorily remediated by federal civilian agencies under Binding Operational Directive 22-01), Cybersecurity Advisories, and Common Security Advisory Framework (CSAF) advisories. CISA also operates an Automated Indicator Sharing (AIS) TAXII 2.1 server that delivers STIX cyber threat indicators to vetted partners under a Terms of Use and Interconnection Agreement.

## Kin Score — 38.7 / 100 (thin)

Scored 2026-08-20 under rubric 0.12.0. Trend: flat (+0.0 from 38.7).

| Facet | Score |
|---|---|
| Discoverability | 64.8 |
| Contract Quality | 59.4 |
| Governance | 60.6 |
| Contract Governance | 60.6 |
| Operational Transparency | 10.5 |
| Developer Ergonomics | 2.4 |
| Commercial Clarity | 28.6 |
| Access Clarity | 28.6 |

Regulatory layer — **Government & Public Sector**: 38.9 (matched via tags).

## Agent readiness — 24.5 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | na |
| MCP Server | no |
| Auth Clarity | no |
| Idempotency | na |
| Error Semantics | no |
| OpenAPI Examples | no |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | na |

## Access

Freemium — onboarding: unknown, pricing: freemium, trial: no (confidence: medium).

## APIs (4)

- **CISA Automated Indicator Sharing (AIS) TAXII Server** — CISA's Automated Indicator Sharing (AIS) program uses a TAXII 2.1 server to deliver STIX-formatted cyber threat indicators (CTI) and defensive measures (DM) to vetted partners. ...
- **CISA Cybersecurity Advisories** — CISA publishes Cybersecurity Advisories (CSAs), Industrial Control Systems Advisories (ICSAs), and Common Security Advisory Framework (CSAF) JSON documents describing tactics, t...
- **Cybersecurity and Infrastructure Security Agency KEV API** — Known Exploited Vulnerabilities catalog feed
- **Cybersecurity and Infrastructure Security Agency Schema API** — JSON Schema for the KEV catalog

## Agentic access (1)

- **Cybersecurity And Infrastructure Security Agency Agentic Access** — 3 operations

## Security (2)

- **Cybersecurity And Infrastructure Security Agency Domain Security** — TLSv1.3 · HSTS · DNSSEC · DMARC
- **Cybersecurity And Infrastructure Security Agency Vulnerability Disclosure** — security.txt · contact published

## Plans (1)

- **Cybersecurity And Infrastructure Security Agency Plans Pricing**

## Tags

Advisories, AIS, Binding Operational Directive, CSAF, CVE, CWE, Cybersecurity, Federal-Government, Government, ICS-CERT, Information Sharing, KEV, Known Exploited Vulnerabilities, Risk Management, Security, STIX, TAXII, Threat Intelligence, Vulnerability Management

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/cybersecurity-and-infrastructure-security-agency/). Scores are computed from the provider's own public artifacts under a published rubric.
