Software law is compounding
Security's catalog of known software flaws grew year after year, and the industry answered with a shared catalog, severity scores, checks where code is written, and a list of the flaws attackers actually use. Software law is on a similar curve now, and the same answers are arriving in years rather than decades. This chart sets the two side by side. This page always carries its latest version.
How to read it
- The left panel counts CVEs, the public catalog of known software flaws, by publication date. The dotted line under it counts the flaws on the list of vulnerabilities known to be exploited kept by the US Cybersecurity and Infrastructure Security Agency, by the year in each CVE ID.
- The right panel counts provisions of software law still in force today, by the date each began to bind. Law repealed since then is not in the library, so the earlier years read low, and provisions with no start date on record are not drawn. The light band is law already enacted with a later start date. The dotted line is the 2021 to 2025 pace carried forward: an assumption, not a forecast.
- The dotted line under it is GDPR fines imposed by regulators in the EU, the UK and the EEA, as a running total. It counts one regime's government fines, not every legal action: private lawsuits have no comparable public count.
- The ladder pairs each step security took with where software law stands today.
Sources
- The National Vulnerability Database of the US National Institute of Standards and Technology: CVEs by publication date, rejected records excluded, counted through its API. This product uses the National Vulnerability Database API but is not endorsed or certified by the National Vulnerability Database.
- The Known Exploited Vulnerabilities catalog of the US Cybersecurity and Infrastructure Security Agency.
- DLA Piper GDPR Fines and Data Breach Survey, January 2026 and earlier editions.
- The LexLint law library and its map of changes.
- EU Cyber Resilience Act reporting: since , reporting an actively exploited vulnerability within 24 hours is a legal obligation.
Use and credit
The chart is © 2026 UnGovr, which makes LexLint, and is licensed under Creative Commons Attribution 4.0 (CC BY 4.0): share and adapt it, including commercially, with credit to UnGovr and a link to this page. The license covers the chart. The sources above keep their own terms, and logos and wordmarks belong to their owners.