Software security already runs two products, and they fight.
The working one is a catalog. MITRE's CVE, from 1999, gives an identifier to a disclosed hole: CVE-2014-0160 is Heartbleed, one OpenSSL bounds miss. CWE names the class, not the incident. OWASP's Top 10, since 2003, is a ranked awareness list of those classes for web apps. OWASP's own 2021 note says the Top 10 is "primarily an awareness document" and "discourages any claims of full coverage of the OWASP Top 10, because it's simply untrue." You look an ID up. You do not recertify OpenSSL as a whole.
The other product is a seal. ISO/IEC 27001 certifies an information-security management system inside a declared scope. Common Criteria (ISO/IEC 15408) certifies a Target of Evaluation against a Security Target — the product, as claimed, in an evaluated configuration. NIST's FIPS 140-3 certifies a cryptographic module. Buyers treat those as "the system is safe." They are not CVE.
Institutions bought the seal and never built the catalog. There is no public identifier for "these two residency databases disagree" the way there is for Heartbleed. Credit ratings, management-system certificates, and "the audit was clean" are the NRSRO version. The essay points at CWE, CVE, ATT&CK, and OWASP, then asks for a research layer. It does not say that software already split the analog, and that governance copied the half that fails.
The seals say this about themselves if you read past the logo.
FIPS 140-3, approved March 2019: "conformance to this standard is not sufficient to ensure that a particular module is secure." The operator has to accept leftover risk. The Cryptographic Module Validation Program tests a module, not the agency or the product that calls it. Microsoft's FIPS page says they validate cryptographic modules used in Windows, not individual Windows services.
Common Criteria has the same limit as a composition rule. ISO/IEC 15408-1 says an evaluation "has meaning only in the context of the security properties that were evaluated and the evaluation methods that were used." Put two evaluated products together — a database on an evaluated OS — and CC v3.1 added a whole Assurance in Composition class (ACO) and Composition Assurance Packages, because the combination is a new evaluation. Pairwise certificates do not add.
ISO/IEC 27001 certifies that a management system exists inside a scope. Leftover risk is written down and accepted. The Statement of Applicability can drop controls. A later breach does not retire the certificate the way a CVE retires a version. The management system is still the management system.
That is the software version of the essay's wall, already printed on the seals. The institutional version is a rating letter.