@GossiTheDog Reading their statement, this really reads like a boilerplate phrase that uses so many words for "we're not going to do anything to diversify the stakeholder landscape". The whole first page talks about how CVE is "CISA's thing" and that they claim ownership for the program, and then there's a lukewarm phrase à la "Yeah, we'll definitely circle back to this, but don't call us. We'll call you!"
I'm more concerned about the very clear "everyone: hands off CVE" undertone.