{"slug": "nist-rfi-for-modernizing-the-nvd-in-the-wake-of-ai", "title": "NIST RFI for modernizing the NVD in the wake of AI", "summary": "The National Institute of Standards and Technology (NIST) issued a Request for Information (RFI) seeking stakeholder input on modernizing the National Vulnerability Database (NVD) in a cybersecurity landscape increasingly shaped by artificial intelligence and machine-consumable security data. Comments must be received by October 13, 2026, at 11:59 p.m. Eastern Time.", "body_md": "This site displays a prototype of a “Web 2.0” version of the daily\nFederal Register. It is not an official legal edition of the Federal\nRegister, and does not replace the official print version or the official\nelectronic version on GPO’s govinfo.gov.\n\nThe documents posted on this site are XML renditions of published Federal\nRegister documents. Each document posted on the site includes a link to the\ncorresponding official PDF file on govinfo.gov. This prototype edition of the\ndaily Federal Register on FederalRegister.gov will remain an unofficial\ninformational resource until the Administrative Committee of the Federal\nRegister (ACFR) issues a regulation granting it official legal status.\nFor complete information about, and access to, our official publications\nand services, go to\nAbout the Federal Register\non NARA's archives.gov.\n\nThe OFR/GPO partnership is committed to presenting accurate and reliable\nregulatory information on FederalRegister.gov with the objective of\nestablishing the XML-based Federal Register as an ACFR-sanctioned\npublication in the future. While every effort has been made to ensure that\nthe material on FederalRegister.gov is accurately displayed, consistent with\nthe official SGML-based PDF version on govinfo.gov, those relying on it for\nlegal research should verify their results against an official edition of\nthe Federal Register. Until the ACFR grants it official status, the XML\nrendition of the daily Federal Register on FederalRegister.gov does not\nprovide legal notice to the public or judicial notice to the courts.\n\nNotice\n\nEnter a search term or FR citation e.g.\n88 FR 38230 FR 78782024-13208USDA09/05/24RULE0503-AA39SORN\n\nChoosing an item from\nfull text search results\nwill bring you to those results. Pressing enter in the search box\nwill also bring you to search results.\nChoosing an item from\nsuggestions\nwill bring you directly to the content.\n\nThank you for taking the time to create a comment. Your input is important.\n\nOnce you have filled in the required fields below you can preview and/or submit your comment to the Commerce Department for review. All comments are considered public and will be posted online once the Commerce Department has reviewed them.\n\nComments in response to this notice must be received on or before October 13, 2026, at 11:59 p.m. Eastern Time. Submissions received after that date may not be considered.\n\nTable of Contents\n\nEnhanced Content - Table of Contents\n\nThis table of contents is a navigational tool, processed from the\nheadings within the legal text of Federal Register documents.\nThis repetition of headings to form internal navigation links\nhas no substantive legal effect.\n\nThis PDF is FR Doc. 2026-16371 as it appeared on Public Inspection on\n08/11/2026 at 8:45 am.\n\nIt was viewed\n149\ntimes while on Public Inspection.\n\nIf you are using public inspection listings for legal research, you\nshould verify the contents of the documents against a final, official\nedition of the Federal Register. Only official editions of the\nFederal Register provide legal notice of publication to the public and judicial notice\nto the courts under 44 U.S.C. 1503 & 1507.\nLearn more here.\n\nPublished Document: 2026-16371 (91 FR 52042)\n\nThis document has been published in the Federal Register. Use the PDF linked in the document sidebar for the official electronic format.\n\nAGENCY:\n\nInformation Technology Laboratory (ITL), National Institute of Standards and Technology (NIST), U.S. Department of Commerce.\n\nACTION:\n\nNotice; Request for Information (RFI).\n\nSUMMARY:\n\nThe National Institute of Standards and Technology (NIST) established and operates the National Vulnerability Database (NVD), which provides the U.S. government repository of standards-based vulnerability management data. NIST seeks stakeholder input on opportunities, challenges, and priorities for modernizing the NVD in an evolving cybersecurity landscape increasingly shaped by artificial intelligence (AI) and machine-consumable security data. NIST's goal is to improve the NVD's scalability, automation, interoperability, transparency, and utility.\n\nDATES:\n\nComments in response to this notice must be received on or before October 13, 2026, at 11:59 p.m. Eastern Time. Submissions received after that date may not be considered.\n\nADDRESSES:\n\nComments must be submitted electronically via the Federal e-Rulemaking Portal.\n\n2. Click the “Comment Now!” icon, complete the required fields, including the relevant document number and title in the subject field; and\n\n3. Enter or attach your comments.\n\nAdditional information on the use of\nregulations.gov,\nincluding instructions for accessing agency documents, submitting comments, and viewing the docket is available at:\nwww.regulations.gov/faq. If you require an accommodation or cannot otherwise submit your comments via\nregulations.gov,\nplease contact NIST using the information in the\nFOR FURTHER INFORMATION CONTACT\nsection below.\n\nNIST will not accept comments for this notice by postal mail, fax, or email. To ensure that NIST does not receive duplicate copies, please submit your comments only once. Comments\n( printed page 52043)\ncontaining references, studies, research, and other empirical data that are not widely published should include copies of the referenced materials.\n\nAll relevant comments received by the deadline will be posted at:\nhttps://www.regulations.gov\nunder docket number NIST-2026-0100 without change or redaction, so commenters should not include information they do not wish to be posted publicly (\ne.g.,\npersonal or confidential business information).\n\nFOR FURTHER INFORMATION CONTACT:\n\nFor questions about this RFI contact: Cristina Ritfeld,\nNVD-RFI@nist.gov.\nDirect media inquiries to NIST's Communications and Outreach Office at (301) 975-2762. Users of telecommunication devices for the deaf, or a text telephone may call the Federal Relay Service toll free at 1-800-877-8339. NIST will make the RFI available in alternate formats, such as Braille or large print, upon request by persons with disabilities.\n\nSUPPLEMENTARY INFORMATION:\n\nThe National Vulnerability Database (NVD), established and operated by NIST, provides the U.S. government repository of standards-based vulnerability management data. The NVD is a foundational resource for vulnerability management, software security, compliance automation, and cybersecurity risk analysis across the public and private sectors. It provides standardized vulnerability enrichment and associated metadata consumed by a broad ecosystem of security tools and operational workflows. It is a part of the broader vulnerability management ecosystem that encompasses processes, standards, and tools involved in one or more phases of the vulnerability lifecycle of identifying, validating, disclosing, disseminating, prioritizing, and remediating software and system vulnerabilities.\n\nToday, the NVD ingests Common Vulnerabilities and Exposures (CVE) records [1]\nwithin approximately an hour of publication using automated processes. NVD analysts then enrich CVE records with additional information and analysis such as severity scores and affected product versions. Users and security tools can access the enriched CVE records through the NVD's web interface or through automated mechanisms.\n\nToday's vulnerability management ecosystem is rapidly evolving and is characterized by AI-enabled cyber tools and accelerated technology delivery cycles. Malicious actors may seek to leverage AI systems to discover and exploit vulnerabilities at scale and to support post-exploitation activities. The inadequacies of traditional vulnerability management approaches, which center on periodic scanning, static prioritization, and manual remediation, are increasingly apparent. Several trends present both challenges and opportunities for modernization, including the growth in the volume and complexity of disclosed vulnerabilities; a range in the quality of data; increased reliance on automation and machine-readable security data; the expansion of technology security risk management practices; the emergence of AI-assisted vulnerability discovery, triage, exploitation, and remediation; demand for near real-time vulnerability enrichment; and resource constraints associated with scaling vulnerability analysis and enrichment activities.\n\nThe advancement of AI presents an opportunity to transform the vulnerability management ecosystem. This requires input from across the community to ensure this ecosystem is effective, scalable, and resilient in the face of emerging threats. NIST plays a key role in this ecosystem, which also relies on other organizations and individuals, including those who identify, evaluate, provide, and implement solutions to manage cybersecurity risks. NIST intends to support a future-ready vulnerability management ecosystem that is continuous, contextual, and automated, while enabling cybersecurity practices to respond appropriately to real-world threats and business priorities.\n\nNIST is using this RFI to give the broader community an opportunity to identify forward-looking perspectives, practical recommendations, and innovative models to help shape the NVD moving forward. Responses are intended to inform future strategic planning, technical architecture decisions, standards and best practices development, data governance approaches, and community collaborations related to the continued evolution of the NVD.\n\nNIST seeks stakeholder perspectives on how the NVD can grow to better support cybersecurity outcomes while maintaining trust, transparency, accuracy, and broad accessibility.\n\nRequest for Information\n\nThis RFI provides the broader community an opportunity to identify forward-looking perspectives, practical recommendations, and innovative models to help shape the NVD. Respondents are encouraged to address any or all of the following questions.\n\n(1) Vulnerability Management Process\n\na. Where in today's vulnerability management lifecycle (\ne.g.,\nidentifying, validating, disclosing, disseminating, prioritizing, remediating) are the biggest bottlenecks that could be improved with greater AI-enabled automation?\n\nb. Which tasks are most appropriate for AI-enabled automation? Which tasks should require human review? For tasks requiring human review, what information is needed, and how can reviews be arranged to both minimize time spent and avoid over-reliance on AI?\n\nc. What are the novel governance and risk management considerations that should be taken into account in modernizing the vulnerability management ecosystem?\n\nd. What other actions could NIST and others involved in the vulnerability management process take to improve vulnerability management processes?\n\n(2) Vulnerability Information Dissemination\n\na. What capabilities, products, and processes, AI or otherwise, are needed to improve the responsible and timely dissemination of vulnerability information to technology developers and the broader community of affected stakeholders?\n\nb. What existing standards and technical guidelines are most helpful for disseminating vulnerability information? What gaps in standards and guidelines exist? How should addressing those gaps be prioritized?\n\nc. What other actions could NIST and others involved in the vulnerability management process take to improve vulnerability information dissemination?\n\n(3) Risk Assessment and Prioritization\n\na. How can the use of AI or other automated mechanisms improve contextual risk prioritization? What data sources and information should be considered by NIST to inform prioritization decisions?\n\nb. How might transparency and auditability in AI-driven prioritization decisions be enhanced?\n\nc. What data and system context is needed by organizations to prioritize vulnerabilities accurately in production environments?\n\nd. How can the NVD improve interoperability and integration with other vulnerability management ecosystem components (\ne.g.,\nvulnerability disclosure programs, vendor advisories, threat intelligence providers, asset management platforms, security tool vendors, remediation\n( printed page 52044)\nworkflows) to enable more timely, accurate, actionable and contextual vulnerability management?\n\ne. What other actions could NIST and others involved in the vulnerability management process take to improve risk assessment and prioritization?\n\n(4) Remediation Development, Deployment, and Monitoring\n\na. What new mechanisms, standards, and procedures may be necessary for automated vulnerability remediation? What role, if any, should AI systems have in automated vulnerability remediation?\n\nb. What organizational structures, policies, processes, and frameworks are needed for organizations and open-source projects to manage AI-generated remediations?\n\nc. What controls and safeguards are needed to prevent erroneous AI-generated remediations?\n\nd. What are the biggest barriers to stakeholders (\ne.g.,\nusers, developers, organizations) remediating vulnerabilities after they receive prompt and comprehensive vulnerability information?\n\ne. What process and organizational dependencies (\ne.g.,\ndiscovery and asset inventory) are prerequisites for organizations to more fully operationalize automated vulnerability remediation?\n\nf. What other actions could NIST and others involved in the vulnerability management process take to improve vulnerability remediation development, deployment, and monitoring?\n\n(5) Vulnerability Data and Standards\n\na. What changes are needed in organizational structures, processes, procedures, standards, and specifications to improve the quality of vulnerability data?\n\nb. Are existing standards, context, and specifications for vulnerability data, including vulnerability identifiers, product naming schemes, and severity scoring systems, sufficient for improving actionable prioritization of vulnerabilities in the AI era? If so, please describe.\n\nc. What gaps are there in existing standards and specifications?\n\nd. What information is needed for organizations to efficiently and effectively manage the increasing number of identified vulnerabilities, including vulnerability prioritization and product identification?\n\ne. What changes are needed to improve machine-readable vulnerability data (\ne.g.,\ndata in the NVD) to improve vulnerability prioritization and contextualization?\n\nf. What other actions could NIST and others involved in the vulnerability management process take to improve vulnerability data and standards?\n\n(6) Development Processes\n\na. How can organizations effectively integrate AI-enabled tools into technology development processes to proactively identify, reduce, and remediate security vulnerabilities, and to enhance overall vulnerability management practices throughout the system lifecycle? What changes, if any, are needed to processes, procedures, standards, and specifications to enable this integration.\n\n(7) Vision for the NVD\n\na. What has been the value of the NVD to organizations? To the extent practicable, please describe how organizations may use the NVD and what activities or decisions the NVD informs.\n\nb. What capabilities and services can be integrated into the NVD to increase its impact over the next five years?\n\nc. What emerging cybersecurity trends relevant to the vulnerability management should the NVD anticipate over the next five years?\n\nd. What capabilities and services will enhance the NVD's utility for vulnerability analysts, technology developers, researchers, and policymakers?\n\ne. What metrics should be considered to track and evaluate the success of the NVD and any modernization efforts?", "url": "https://wpnews.pro/news/nist-rfi-for-modernizing-the-nvd-in-the-wake-of-ai", "canonical_source": "https://www.federalregister.gov/documents/2026/08/12/2026-16371/request-for-information-rfi-on-modernizing-the-national-vulnerability-database-in-the-age-of", "published_at": "2026-08-12 15:58:50+00:00", "updated_at": "2026-08-12 16:14:07.942633+00:00", "lang": "en", "topics": ["ai-policy"], "entities": ["National Institute of Standards and Technology", "National Vulnerability Database", "U.S. Department of Commerce"], "alternates": {"html": "https://wpnews.pro/news/nist-rfi-for-modernizing-the-nvd-in-the-wake-of-ai", "markdown": "https://wpnews.pro/news/nist-rfi-for-modernizing-the-nvd-in-the-wake-of-ai.md", "text": "https://wpnews.pro/news/nist-rfi-for-modernizing-the-nvd-in-the-wake-of-ai.txt", "jsonld": "https://wpnews.pro/news/nist-rfi-for-modernizing-the-nvd-in-the-wake-of-ai.jsonld"}}