NIST Is Asking the Public How to Fix the NVD. Comments Close October 13.
On August 12, NIST published an official Request for Information asking the public how to modernize the National Vulnerability Database for the AI era — the clearest sign yet that the agency itself recognizes the strain we've been documenting since the NVD moved to a triage-only enrichment model back in April. Comments close October 13, 2026, submitted through regulations.gov under docket NIST-2026-0100.
Why this RFI exists
NIST's own framing in the notice is unusually candid about the problem. Today, the NVD ingests CVE records within about an hour of publication using automated processes, but human analysts still enrich those records with severity scores and affected-product data — the exact bottleneck that produced the current backlog. NIST names the pressure directly: "the inadequacies of traditional vulnerability management approaches, which center on periodic scanning, static prioritization, and manual remediation, are increasingly apparent," citing growing disclosure volume, inconsistent data quality, and — notably — "the emergence of AI-assisted vulnerability discovery, triage, exploitation, and remediation" as a force reshaping the whole ecosystem from both the offensive and defensive sides at once.
That's a striking acknowledgment from the agency that runs the NVD: the same AI capability driving incidents like Hugging Face and the UK AISI findings covered here this month is also, per NIST's own words, an "opportunity to transform the vulnerability management ecosystem" — assuming the infrastructure underneath it can actually keep pace.
What NIST is actually asking
The RFI poses questions across seven areas: where AI-enabled automation could relieve the biggest bottlenecks in the vulnerability lifecycle (and which tasks should stay human-reviewed); how to responsibly disseminate vulnerability information faster; how AI could improve contextual risk prioritization while staying auditable; what governance is needed around AI-generated remediations specifically, including "what controls and safeguards are needed to prevent erroneous AI-generated remediations"; whether existing data standards and severity-scoring systems are sufficient for the AI era; how organizations should integrate AI tools into development processes to catch vulnerabilities earlier; and a direct question about NVD's five-year vision — what capabilities should be added, and what metrics should track whether modernization actually worked.
Why this matters beyond a normal comment period
The NVD isn't a peripheral data source — it's foundational infrastructure that BOD 26-04, FedRAMP's VDR/VER rules, and a huge share of the commercial vulnerability-management ecosystem all build on directly or indirectly. NIST asking, in writing, whether its own severity-scoring and product-naming standards remain "sufficient for improving actionable prioritization of vulnerabilities in the AI era" is NIST questioning the durability of infrastructure most of this ecosystem currently assumes will keep working the way it always has. Whatever NIST does with the responses it gets — and RFIs are explicitly non-binding, a step toward "future strategic planning" rather than a proposed rule — the fact that this question is being asked publicly, on the record, is itself a signal worth taking seriously.
What to do about it
Organizations with a real stake in how the NVD evolves — and that's a wide set, given how much downstream tooling assumes NVD data as ground truth — have a genuine, low-cost opportunity to shape that evolution before October 13. Per the notice itself, comments are submitted at regulations.gov: search "NIST-2026-0100," then use the "Comment Now!" button. Comments are posted publicly once received, unredacted, so avoid including anything you don't want made public.