Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Shaping the NVD for the Future: We Need Your Feedback on AI-Enabled Vulnerability Management

For over two decades, the NIST National Vulnerability Database (NVD) has served as the U.S. government repository for standards-based vulnerability management data and as a foundational resource for cybersecurity risk analysis, vulnerability management, compliance automation, and software security.

New Opportunities for the NVD via Automation

Our cybersecurity landscape is changing dramatically and is being reconfigured by artificial intelligence (AI) in unique, exciting, and yes, sometimes challenging ways. This is creating openings to potentially leverage AI systems to discover and exploit vulnerabilities — but AI can also serve as a valuable tool to strengthen cybersecurity and speed up response times. As the volume of reported vulnerabilities surges and emerging technologies reshape the threat picture, it is time for traditional vulnerability management practices centered on periodic patching and manual remediation to be transformed toward continuous, automated, and contextual vulnerability management.

With the rapid growth of AI-enabled cyber tools and dramatically accelerated technology delivery cycles, NIST aims to improve the NVD’s scalability, automation, interoperability, transparency, and utility — modernizing it for the future. To guide this transformation, NIST released a Request for Information (RFI) and is seeking feedback, especially from technical experts, industry and government leaders, researchers, cybersecurity professionals, and software vendors. This is an “all hands-on deck” moment for this community. 

Your voice matters. We want to understand your priorities and challenges and to learn about opportunities you see to improve vulnerability management. We are committed to providing you with the information and tools you need to anticipate and deal with software vulnerabilities.

Steps We’ve Already Taken

We have already begun work on a tool, called V-etalon, that leverages AI technologies to aid in enriching vulnerability information. We hope that V-etalon will eventually provide a foundation for the evaluation of vulnerability information. We will be looking for feedback and collaboration opportunities once it’s available, all via GitHub (please stay tuned for an upcoming release and announcement).

Additionally, NIST has kicked off work to update the Common Platform Enumeration (CPE) specifications, a mechanism for describing vulnerable products to better apply to hardware and to improve the specifications based on learning from over a decade of use. NIST held a workshop in June to share initial directions and gather feedback. 

See the CPE page for more information.

Collaboration is Key

We need input from across the community to ensure this ecosystem is effective, scalable, and resilient in the face of emerging threats.

NIST plays a key role in this ecosystem, which relies on many other organizations and individuals (including those who identify, evaluate, provide, and implement solutions to manage cybersecurity risks). NIST intends to support a future-ready vulnerability management ecosystem that is continuous, contextual, and automated into the future.

What Key Feedback Areas Would be Most Helpful to NIST?

  • Vulnerability Management Process
  • Vulnerability Information Dissemination
  • Risk Assessment and Prioritization
  • Remediation Development, Deployment, and Monitoring
  • Vulnerability Data and Standards
  • Development Processes
  • Vision for the NVD

Ultimately, we want to know how we can modernize the NVD to better support cybersecurity outcomes while maintaining trust, transparency, accuracy, and broad accessibility.

Your RFI responses will help inform our future strategic planning efforts, new tool development, technical architecture decisions, standards and best practices development, and data governance approaches.

How to Submit Feedback

Stakeholders are encouraged to submit written comments identifying technical priorities, innovative frameworks, and practical recommendations by October 13, 2026 at 11:59 PM ET. Comments must be submitted via the Federal e-Rulemaking Portal (details below).

Quick Links:

See the full RFI HERE.

See instructions on how to submit your comments HERE.

Learn more about NIST’s NVD efforts HERE.

 

About the author

Harold Booth

Harold is a Computer Scientist and Group Manager for the Software Security Group at the National Institute of Standards and Technology in the Computer Security Division. Current projects include Dioptra, an open source software platform for the test and evaluation of machine learning systems, as well currently developing a project at the National Cybersecurity Center of Excellence (NCCoE) on Software and AI Agent Identity and Authorization. Past work includes serving as the Project Manager for the Cryptographic Algorithm Validation Program (2018-2020) and the National Vulnerability Database at NIST (2010-2017).

Jon Boyens

Jon Boyens is the Acting Chief of the Computer Security Division in the Information Technology Laboratory at NIST. His responsibilities include cryptographic standards used by the U.S. Government and internationally, Cybersecurity Research and Development at NIST, and Cybersecurity Standards and Guidelines for Federal Agency Security Programs.

Related Posts

Celebrating 1 Year of CSF 2.0

It has been one year since the release of the NIST Cybersecurity Framework (CSF) 2.0 ! To make improving your security posture even easier, in this blog we are

Comments

Add new comment

CAPTCHA
This question is for testing whether or not you are a human visitor and to prevent automated spam submissions.
Please be respectful when posting comments. We will post all comments without editing as long as they are appropriate for a public, family friendly website, are on topic and do not contain profanity, personal attacks, misleading or false information/accusations or promote specific commercial products, services or organizations. Comments that violate our comment policy or include links to non-government organizations/web pages will not be posted.
Was this page helpful?