8/18/2026
The National Institute of Standards and Technology (NIST) has issued a Request for Information (RFI) on modernizing the National Vulnerability Database (NVD), the U.S. government’s central repository for vulnerability management data. NIST is accepting public comments through October 13, 2026.
View the Request for Information, published in the Federal Register.
Several of the RFI’s questions are relevant to the standards community, including whether current vulnerability identifiers, product naming schemes, and severity scoring systems are sufficient for an AI-driven environment.
About the National Vulnerability Database
The NVD, established and operated by NIST, is a U.S. government resource that helps organizations manage cybersecurity risks. It provides standardized vulnerability enrichment and associated metadata consumed by a broad ecosystem of security tools and operational workflows. It is part of the broader vulnerability management ecosystem that encompasses processes, standards, and tools involved in one or more phases of the vulnerability lifecycle: identifying, validating, disclosing, disseminating, prioritizing, and remediating software and system vulnerabilities.
Submit Your Feedback
NIST seeks stakeholder perspectives on how the NVD can modernize to better support cybersecurity outcomes while maintaining trust, transparency, accuracy, and broad accessibility. Responses to the RFI are intended to inform future strategic planning, technical architecture decisions, standards and best practices development, data governance approaches, and community collaborations related to the continued evolution of the NVD.
The RFI seeks input across seven areas:
Read the NIST news item to learn more, including details on how to submit comments.
Related News: