cd /news/ai-policy/nist-rfi-for-modernizing-the-nvd-in-… · home topics ai-policy article
[ARTICLE · art-93896] src=federalregister.gov ↗ pub= topic=ai-policy verified=true sentiment=· neutral

NIST RFI for modernizing the NVD in the wake of AI

The National Institute of Standards and Technology (NIST) issued a Request for Information (RFI) seeking stakeholder input on modernizing the National Vulnerability Database (NVD) in a cybersecurity landscape increasingly shaped by artificial intelligence and machine-consumable security data. Comments must be received by October 13, 2026, at 11:59 p.m. Eastern Time.

read11 min views1 publishedAug 12, 2026
NIST RFI for modernizing the NVD in the wake of AI
Image: source

This site displays a prototype of a “Web 2.0” version of the daily Federal Register. It is not an official legal edition of the Federal Register, and does not replace the official print version or the official electronic version on GPO’s govinfo.gov.

The documents posted on this site are XML renditions of published Federal Register documents. Each document posted on the site includes a link to the corresponding official PDF file on govinfo.gov. This prototype edition of the daily Federal Register on FederalRegister.gov will remain an unofficial informational resource until the Administrative Committee of the Federal Register (ACFR) issues a regulation granting it official legal status. For complete information about, and access to, our official publications and services, go to About the Federal Register on NARA's archives.gov.

The OFR/GPO partnership is committed to presenting accurate and reliable regulatory information on FederalRegister.gov with the objective of establishing the XML-based Federal Register as an ACFR-sanctioned publication in the future. While every effort has been made to ensure that the material on FederalRegister.gov is accurately displayed, consistent with the official SGML-based PDF version on govinfo.gov, those relying on it for legal research should verify their results against an official edition of the Federal Register. Until the ACFR grants it official status, the XML rendition of the daily Federal Register on FederalRegister.gov does not provide legal notice to the public or judicial notice to the courts.

Notice

Enter a search term or FR citation e.g. 88 FR 38230 FR 78782024-13208USDA09/05/24RULE0503-AA39SORN

Choosing an item from full text search results will bring you to those results. Pressing enter in the search box will also bring you to search results. Choosing an item from suggestions will bring you directly to the content.

Thank you for taking the time to create a comment. Your input is important.

Once you have filled in the required fields below you can preview and/or submit your comment to the Commerce Department for review. All comments are considered public and will be posted online once the Commerce Department has reviewed them.

Comments in response to this notice must be received on or before October 13, 2026, at 11:59 p.m. Eastern Time. Submissions received after that date may not be considered.

Table of Contents

Enhanced Content - Table of Contents

This table of contents is a navigational tool, processed from the headings within the legal text of Federal Register documents. This repetition of headings to form internal navigation links has no substantive legal effect.

This PDF is FR Doc. 2026-16371 as it appeared on Public Inspection on 08/11/2026 at 8:45 am.

It was viewed 149 times while on Public Inspection.

If you are using public inspection listings for legal research, you should verify the contents of the documents against a final, official edition of the Federal Register. Only official editions of the Federal Register provide legal notice of publication to the public and judicial notice to the courts under 44 U.S.C. 1503 & 1507. Learn more here.

Published Document: 2026-16371 (91 FR 52042) This document has been published in the Federal Register. Use the PDF linked in the document sidebar for the official electronic format.

AGENCY:

Information Technology Laboratory (ITL), National Institute of Standards and Technology (NIST), U.S. Department of Commerce.

ACTION:

Notice; Request for Information (RFI). SUMMARY:

The National Institute of Standards and Technology (NIST) established and operates the National Vulnerability Database (NVD), which provides the U.S. government repository of standards-based vulnerability management data. NIST seeks stakeholder input on opportunities, challenges, and priorities for modernizing the NVD in an evolving cybersecurity landscape increasingly shaped by artificial intelligence (AI) and machine-consumable security data. NIST's goal is to improve the NVD's scalability, automation, interoperability, transparency, and utility.

DATES:

Comments in response to this notice must be received on or before October 13, 2026, at 11:59 p.m. Eastern Time. Submissions received after that date may not be considered.

ADDRESSES:

Comments must be submitted electronically via the Federal e-Rulemaking Portal.

  1. Click the “Comment Now!” icon, complete the required fields, including the relevant document number and title in the subject field; and

  2. Enter or attach your comments.

Additional information on the use of regulations.gov, including instructions for accessing agency documents, submitting comments, and viewing the docket is available at: www.regulations.gov/faq. If you require an accommodation or cannot otherwise submit your comments via regulations.gov, please contact NIST using the information in the FOR FURTHER INFORMATION CONTACT section below.

NIST will not accept comments for this notice by postal mail, fax, or email. To ensure that NIST does not receive duplicate copies, please submit your comments only once. Comments ( printed page 52043) containing references, studies, research, and other empirical data that are not widely published should include copies of the referenced materials.

All relevant comments received by the deadline will be posted at: https://www.regulations.gov under docket number NIST-2026-0100 without change or redaction, so commenters should not include information they do not wish to be posted publicly ( e.g., personal or confidential business information).

FOR FURTHER INFORMATION CONTACT:

For questions about this RFI contact: Cristina Ritfeld,

NVD-RFI@nist.gov. Direct media inquiries to NIST's Communications and Outreach Office at (301) 975-2762. Users of telecommunication devices for the deaf, or a text telephone may call the Federal Relay Service toll free at 1-800-877-8339. NIST will make the RFI available in alternate formats, such as Braille or large print, upon request by persons with disabilities.

SUPPLEMENTARY INFORMATION:

The National Vulnerability Database (NVD), established and operated by NIST, provides the U.S. government repository of standards-based vulnerability management data. The NVD is a foundational resource for vulnerability management, software security, compliance automation, and cybersecurity risk analysis across the public and private sectors. It provides standardized vulnerability enrichment and associated metadata consumed by a broad ecosystem of security tools and operational workflows. It is a part of the broader vulnerability management ecosystem that encompasses processes, standards, and tools involved in one or more phases of the vulnerability lifecycle of identifying, validating, disclosing, disseminating, prioritizing, and remediating software and system vulnerabilities.

Today, the NVD ingests Common Vulnerabilities and Exposures (CVE) records [1] within approximately an hour of publication using automated processes. NVD analysts then enrich CVE records with additional information and analysis such as severity scores and affected product versions. Users and security tools can access the enriched CVE records through the NVD's web interface or through automated mechanisms.

Today's vulnerability management ecosystem is rapidly evolving and is characterized by AI-enabled cyber tools and accelerated technology delivery cycles. Malicious actors may seek to leverage AI systems to discover and exploit vulnerabilities at scale and to support post-exploitation activities. The inadequacies of traditional vulnerability management approaches, which center on periodic scanning, static prioritization, and manual remediation, are increasingly apparent. Several trends present both challenges and opportunities for modernization, including the growth in the volume and complexity of disclosed vulnerabilities; a range in the quality of data; increased reliance on automation and machine-readable security data; the expansion of technology security risk management practices; the emergence of AI-assisted vulnerability discovery, triage, exploitation, and remediation; demand for near real-time vulnerability enrichment; and resource constraints associated with scaling vulnerability analysis and enrichment activities.

The advancement of AI presents an opportunity to transform the vulnerability management ecosystem. This requires input from across the community to ensure this ecosystem is effective, scalable, and resilient in the face of emerging threats. NIST plays a key role in this ecosystem, which also relies on other organizations and individuals, including those who identify, evaluate, provide, and implement solutions to manage cybersecurity risks. NIST intends to support a future-ready vulnerability management ecosystem that is continuous, contextual, and automated, while enabling cybersecurity practices to respond appropriately to real-world threats and business priorities.

NIST is using this RFI to give the broader community an opportunity to identify forward-looking perspectives, practical recommendations, and innovative models to help shape the NVD moving forward. Responses are intended to inform future strategic planning, technical architecture decisions, standards and best practices development, data governance approaches, and community collaborations related to the continued evolution of the NVD.

NIST seeks stakeholder perspectives on how the NVD can grow to better support cybersecurity outcomes while maintaining trust, transparency, accuracy, and broad accessibility.

Request for Information

This RFI provides the broader community an opportunity to identify forward-looking perspectives, practical recommendations, and innovative models to help shape the NVD. Respondents are encouraged to address any or all of the following questions.

(1) Vulnerability Management Process a. Where in today's vulnerability management lifecycle ( e.g., identifying, validating, disclosing, disseminating, prioritizing, remediating) are the biggest bottlenecks that could be improved with greater AI-enabled automation?

b. Which tasks are most appropriate for AI-enabled automation? Which tasks should require human review? For tasks requiring human review, what information is needed, and how can reviews be arranged to both minimize time spent and avoid over-reliance on AI?

c. What are the novel governance and risk management considerations that should be taken into account in modernizing the vulnerability management ecosystem?

d. What other actions could NIST and others involved in the vulnerability management process take to improve vulnerability management processes?

(2) Vulnerability Information Dissemination

a. What capabilities, products, and processes, AI or otherwise, are needed to improve the responsible and timely dissemination of vulnerability information to technology developers and the broader community of affected stakeholders?

b. What existing standards and technical guidelines are most helpful for disseminating vulnerability information? What gaps in standards and guidelines exist? How should addressing those gaps be prioritized?

c. What other actions could NIST and others involved in the vulnerability management process take to improve vulnerability information dissemination?

(3) Risk Assessment and Prioritization a. How can the use of AI or other automated mechanisms improve contextual risk prioritization? What data sources and information should be considered by NIST to inform prioritization decisions?

b. How might transparency and auditability in AI-driven prioritization decisions be enhanced?

c. What data and system context is needed by organizations to prioritize vulnerabilities accurately in production environments?

d. How can the NVD improve interoperability and integration with other vulnerability management ecosystem components ( e.g., vulnerability disclosure programs, vendor advisories, threat intelligence providers, asset management platforms, security tool vendors, remediation ( printed page 52044) workflows) to enable more timely, accurate, actionable and contextual vulnerability management?

e. What other actions could NIST and others involved in the vulnerability management process take to improve risk assessment and prioritization?

(4) Remediation Development, Deployment, and Monitoring

a. What new mechanisms, standards, and procedures may be necessary for automated vulnerability remediation? What role, if any, should AI systems have in automated vulnerability remediation?

b. What organizational structures, policies, processes, and frameworks are needed for organizations and open-source projects to manage AI-generated remediations?

c. What controls and safeguards are needed to prevent erroneous AI-generated remediations?

d. What are the biggest barriers to stakeholders ( e.g., users, developers, organizations) remediating vulnerabilities after they receive prompt and comprehensive vulnerability information?

e. What process and organizational dependencies ( e.g., discovery and asset inventory) are prerequisites for organizations to more fully operationalize automated vulnerability remediation?

f. What other actions could NIST and others involved in the vulnerability management process take to improve vulnerability remediation development, deployment, and monitoring?

(5) Vulnerability Data and Standards a. What changes are needed in organizational structures, processes, procedures, standards, and specifications to improve the quality of vulnerability data?

b. Are existing standards, context, and specifications for vulnerability data, including vulnerability identifiers, product naming schemes, and severity scoring systems, sufficient for improving actionable prioritization of vulnerabilities in the AI era? If so, please describe.

c. What gaps are there in existing standards and specifications?

d. What information is needed for organizations to efficiently and effectively manage the increasing number of identified vulnerabilities, including vulnerability prioritization and product identification?

e. What changes are needed to improve machine-readable vulnerability data ( e.g., data in the NVD) to improve vulnerability prioritization and contextualization?

f. What other actions could NIST and others involved in the vulnerability management process take to improve vulnerability data and standards?

(6) Development Processes a. How can organizations effectively integrate AI-enabled tools into technology development processes to proactively identify, reduce, and remediate security vulnerabilities, and to enhance overall vulnerability management practices throughout the system lifecycle? What changes, if any, are needed to processes, procedures, standards, and specifications to enable this integration.

(7) Vision for the NVD a. What has been the value of the NVD to organizations? To the extent practicable, please describe how organizations may use the NVD and what activities or decisions the NVD informs.

b. What capabilities and services can be integrated into the NVD to increase its impact over the next five years?

c. What emerging cybersecurity trends relevant to the vulnerability management should the NVD anticipate over the next five years?

d. What capabilities and services will enhance the NVD's utility for vulnerability analysts, technology developers, researchers, and policymakers?

e. What metrics should be considered to track and evaluate the success of the NVD and any modernization efforts?

── more in #ai-policy 4 stories · sorted by recency
── more on @national institute of standards and technology 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/nist-rfi-for-moderni…] indexed:0 read:11min 2026-08-12 ·