Search Icon White
AI text

Modernizing the National Vulnerability Database for the AI Era: NIST Seeks Industry Input

8/18/2026

Respond by October 13

The National Institute of Standards and Technology (NIST) has issued a Request for Information (RFI) on modernizing the National Vulnerability Database (NVD), the U.S. government’s central repository for vulnerability management data. NIST is accepting public comments through October 13, 2026.

View the Request for Information, published in the Federal Register.

Several of the RFI’s questions are relevant to the standards community, including whether current vulnerability identifiers, product naming schemes, and severity scoring systems are sufficient for an AI-driven environment.

About the National Vulnerability Database

The NVD, established and operated by NIST, is a U.S. government resource that helps organizations manage cybersecurity risks. It provides standardized vulnerability enrichment and associated metadata consumed by a broad ecosystem of security tools and operational workflows. It is part of the broader vulnerability management ecosystem that encompasses processes, standards, and tools involved in one or more phases of the vulnerability lifecycle: identifying, validating, disclosing, disseminating, prioritizing, and remediating software and system vulnerabilities.

Submit Your Feedback

NIST seeks stakeholder perspectives on how the NVD can modernize to better support cybersecurity outcomes while maintaining trust, transparency, accuracy, and broad accessibility. Responses to the RFI are intended to inform future strategic planning, technical architecture decisions, standards and best practices development, data governance approaches, and community collaborations related to the continued evolution of the NVD.

The RFI seeks input across seven areas:

  • Vulnerability management process: Where the biggest bottlenecks lie in today's lifecycle, which tasks are appropriate for AI-enabled automation versus human review, and what new governance considerations modernization requires.
  • Vulnerability information dissemination: What capabilities, standards, and guidelines are needed to responsibly and promptly share vulnerability information with developers and other stakeholders.
  • Risk assessment and prioritization: How AI and other automated methods can improve contextual risk prioritization, and how the NVD can better integrate with disclosure programs, vendor advisories, threat intelligence feeds, and asset management platforms.
  • Remediation development, deployment, and monitoring: What standards, safeguards, and organizational structures are needed as AI-generated fixes become more common, including controls to catch erroneous automated remediations.
  • Vulnerability data and standards: Whether existing identifier schemes, product naming conventions, and severity scoring systems remain adequate in an AI-driven environment, and where gaps need to be addressed.
  • Development processes: How organizations can integrate AI-enabled tools into development workflows to proactively identify and remediate vulnerabilities across the system lifecycle.
  • Vision for the NVD: What capabilities the NVD should build over the next five years, what emerging trends it should anticipate, and what metrics should define success.

Read the NIST news item to learn more, including details on how to submit comments.

Related News:

NIST Seeks Comments on New AI Evaluation Framework

STAFF CONTACT

Communications & Public Relations Staff

Email:
pr@ansi.org