Exception lifecycle for Jira

Put an expiry on accepted risk.

Watch risk-accepted tickets for their expiry date. When a deferred CVE enters CISA KEV, reopen or escalate the issue and notify its owner.

Start prepaid pilot · $99/mo

About 20 watched tickets · prepaid monthly

Expiry date

Return expired exceptions to the queue.

WaiveWatch checks the accepted-until field nightly. When the date passes, it comments on the Jira issue and transitions it out of the accepted state. The record stays with the ticket.

CISA KEV

Revisit the decision when exploitation is known.

WaiveWatch checks the ticket's CVE ID against CISA's Known Exploited Vulnerabilities catalog. A match reopens or escalates the issue and notifies the owner.

Your scanner finds it.
Your Jira ticket carries the decision.

Keep your existing findings workflow in DefectDojo, Tenable or similar tools. WaiveWatch handles the expiry and KEV review of exceptions already recorded in Jira.

Start with your exception queue.

Prepaid pilot for about 20 watched tickets.
Prepaid monthly. Cancel anytime.

$99 / month

Start prepaid pilot

Before the pilot

What happens when an accepted risk expires?

WaiveWatch's nightly job checks the accepted-until date, comments on the Jira issue and transitions it out of the accepted state so the finding returns to the remediation queue.

What happens when a deferred CVE enters CISA KEV?

If the ticket's CVE ID appears in CISA's Known Exploited Vulnerabilities catalog, WaiveWatch reopens or escalates the issue and notifies the owner.

Is WaiveWatch a vulnerability scanner?

No. It watches the lifecycle of existing exceptions in Jira. Your scanner and remediation process remain responsible for finding and fixing vulnerabilities.

Who is the pilot for?

VM and AppSec leads who record risk acceptances in Jira and need to revisit them at expiry or when a deferred CVE enters KEV.