NIST is asking how to rebuild the NVD for the AI era, and vulnerability disclosure programs are named in the architecture. Comments close October 13. Here's what a useful response looks like.
On August 12, 2026, NIST published a Request for Information on Modernizing the National Vulnerability Database in the Age of Artificial Intelligence (91 FR 52042, docket NIST-2026-0100). Comments are due October 13, 2026, at 11:59 p.m. Eastern, via regulations.gov.
If you run a vulnerability disclosure program, report vulnerabilities, or build anything that consumes CVE data, this one is worth your time. Here's why, and what a useful response might look like.
Why this matters to disclosure people specifically #
The NVD isn't an abstraction. Its enrichment data (severity scores, affected-product mappings, weakness classifications) flows downstream into FedRAMP assessments, PCI scans, SBOM tooling, and procurement checklists. When a CVE sits unenriched, a vulnerability your program received, triaged, and fixed can look unresolved, or invisible, to the auditors and customers who only see it through scanner output. Bad or missing enrichment also produces scanner false positives, and false positives have a way of getting blamed on the researcher who reported the bug in the first place.
So when NIST asks how this system should be rebuilt, the disclosure community has skin in the game, on both sides of the table.
The timing is the story #
This RFI didn't arrive in a vacuum. Four months earlier, on April 15, 2026, NIST announced a fundamental change to NVD operations: it would no longer attempt to enrich every CVE. Going forward, NIST prioritizes enrichment for CVEs in CISA's Known Exploited Vulnerabilities catalog, CVEs affecting software used in the federal government, and CVEs affecting critical software as defined under Executive Order 14028. Everything else is deemed "lowest priority," and backlogged CVEs published before March 1, 2026 were moved to a "Not Scheduled" category.
To be precise about the verb: NIST is prioritizing, not stopping. But the practical effect is that universal enrichment, the implicit promise most vulnerability-management tooling was built on, is over. NIST's own numbers explain why: CVE submissions grew 263% between 2020 and 2025, NIST enriched nearly 42,000 CVEs in 2025 (45% more than any prior year), and submissions in early 2026 were running roughly a third higher again. The math stopped working.
Add the funding backdrop. In April 2025, the CVE program itself came within hours of a contract lapse before CISA exercised an eleventh-hour extension. That crisis was resolved (the CVE Board was told in January 2026 that there would be no funding cliff), but the episode made the fragility of this infrastructure impossible to unsee.
Read against that sequence, this RFI is best understood as the design conversation for whatever comes after universal enrichment. Whatever emerges will govern a system that no longer works the way most tooling still assumes it works.
What NIST is actually asking #
The RFI poses questions across seven areas, using NIST's own headings: Vulnerability Management Process, Vulnerability Information Dissemination, Risk Assessment and Prioritization, Remediation Development Deployment and Monitoring, Vulnerability Data and Standards, Development Processes, and Vision for the NVD.
A few threads run through all of them.
AI as both cause and cure. The RFI is candid that "Malicious actors may seek to leverage AI systems to discover and exploit vulnerabilities at scale," and that the traditional model of "periodic scanning, static prioritization, and manual remediation" is showing its age. At the same time, it asks which tasks are appropriate for AI-enabled automation and which should require human review. The volume problem AI created is the same problem NIST hopes AI can help solve. That symmetry deserves scrutiny, not just enthusiasm.
Disclosure is named in the architecture. Question 3(d) asks, verbatim:
"How can the NVD improve interoperability and integration with other vulnerability management ecosystem components (e.g., vulnerability disclosure programs, vendor advisories, threat intelligence providers, asset management platforms, security tool vendors, remediation workflows) to enable more timely, accurate, actionable and contextual vulnerability management?"
Vulnerability disclosure programs, listed first. That's an open door, not a seat at the table. Nobody is obligated to walk through it on our behalf, and if the disclosure community doesn't answer, the interoperability story gets written by the vendors who do.
The whole lifecycle is in scope. The RFI frames the NVD as part of an ecosystem spanning "identifying, validating, disclosing, disseminating, prioritizing, and remediating software and system vulnerabilities." Disclosure sits in the middle of that chain. The quality of what enters the pipe upstream (from reporters, programs, and CNAs) bounds everything NIST can do downstream.
Doesn't the ecosystem already route around this? #
A fair question. CISA's Vulnrichment project has been publishing SSVC and CVSS enrichment as an ADP since 2024. ENISA operates the EUVD. OSV covers open source. Alternatives and supplements exist, and any redesign should assume a federated ecosystem rather than a single source of truth.
But the NVD's position is not really replaceable by any of them: it remains, in the RFI's own words, "the U.S. government repository of standards-based vulnerability management data," and it is the reference point compliance frameworks actually cite. A federated ecosystem with a coherent, transparent NVD at its center is a very different thing from a vacuum with six partial substitutes. Which future we get is, in part, what this comment period decides.
The AI risks a good comment should name #
If AI-assisted enrichment is coming (and the RFI strongly suggests it is), the failure modes are predictable and worth putting on the record: Hallucinated precision. Wrong CPE mappings and version ranges generated confidently at scale, feeding scanners that treat them as ground truth.Unaudited absence. False negatives nobody notices, because nobody audits what wasn't flagged.Model feedback loops. Enrichment models trained on prior AI-generated enrichment, compounding early errors.Adversarial input. CVE descriptions are attacker-influenceable text. An enrichment pipeline that ingests them is a prompt-injection surface.
The asks that follow: published error rates, provenance labels distinguishing human-reviewed from AI-generated enrichment, a correction and appeal path with a named turnaround, and human review for anything that feeds compliance decisions. A score without provenance is a liability wearing a confidence interval.
What a useful comment looks like #
Agencies discount dockets full of near-identical form letters, and they're right to. A small number of specific, evidence-bearing comments beats a thousand templated ones. If you have direct experience, here's where it lands hardest:
Answer 7(a) with real usage. NIST is asking what the NVD's value has been. Concrete "we use it for X, and here's what breaks when enrichment lags" evidence is what sustains budgets. This is the easiest high-value comment to write.Be precise about the seam (1d, 5a). Data quality at the source is mostly a CVE Program and CNA surface, not an NVD one. Comments should say plainly which fixes belong to NIST and which require CNA rule changes, rather than asking NIST for things it can't deliver.Push provenance and auditability (3b). If AI drives prioritization, ask for transparent methods, published error rates, and labeled provenance on every enriched field.Make interoperability concrete (3d). Name the standards that already work (CSAF, VEX, OSV, security.txt, SSVC) and the specific integration gaps between VDP platforms, vendor advisories, and the NVD.Demand long-tail metrics (7e). Coverage of KEV is nearly self-fulfilling. The revealing numbers are time-to-enrichment across the long tail and a published error rate. Ask for both.Offer something. The strongest comments give as well as ask. Disclosure programs and CNAs committing to publish machine-readable, structured advisories is what makes "enrich at the source" an architecture rather than a slogan.
How to comment #
Submit via regulations.gov under docket NIST-2026-0100 by October 13, 2026, 11:59 p.m. ET (that's the deadline as of this writing; the docket is authoritative if anything changes). NIST won't accept email, fax, or postal submissions for this one.
One caveat that matters for this community: comments are posted publicly, without redaction, exactly as submitted. If you operate pseudonymously or can't attach your legal name to a federal docket, factor that in before filing. We're thinking about how disclose.io can help surface input from researchers in that position as part of an organizational response; if that's you, get in touch.
The NVD's stated destination is a vulnerability ecosystem that is "continuous, contextual, and automated." Whether that ecosystem treats disclosure as core infrastructure or as an afterthought depends substantially on who shows up in the docket. Sixty days. Worth using them.