National Institute of Standards and Technology (NIST) demands feedback from industry and the government on how to update the National Vulnerability Database (NVD) since artificial intelligence is changing how groups find, evaluate, and fix cybersecurity problems.
NIST has asked for information (RFI) about the future of the NVD. They want input from people on the tech, processes, and skills that could influence how to manage vulnerabilities in the next five years. The agency is especially keen on how AI can be used while keeping human control, clear communication, security, and good data quality.
According to a notice published Wednesday in the Federal Register, NIST will accept comments on the RFI through Oct. 13, 2026.
The request is made while federal agencies and private companies look at how AI impacts cybersecurity and managing risks. These topics will also likely be talked about at the 2026 FedCiv Summit on Oct. 29, where government and industry people will discuss AI use, cloud systems, cybersecurity, and making work easier for workers as part of federal updates.
National Vulnerability Database Update as AI Changes Security The NIST NVD is a standard-based database created and managed by NIST for the U.S. government. It has become a key resource for managing vulnerabilities, software security, compliance, and cybersecurity risk analysis for both government and private sectors.
The NVD gets Common Vulnerabilities and Exposures (CVE) records automatically, usually accepting new records about an hour after they are published. NIST analysts then add more information, like severity scores and details on affected product versions.
Users and security tools can find that information on the NVD’s website and through automated systems. The database is important because it helps organizations learn about public vulnerabilities and use that information in their security processes.
As security tools with AI are used more often, the way we gather, understand, rank, and respond to information about weaknesses is changing. NIST’s RFI wants to find out how the NVD can adapt to these changes.
Request for Information
This RFI provides the broader community an opportunity to identify forward-looking perspectives, practical recommendations, and innovative models to help shape the NVD. Respondents are encouraged to address any or all of the following questions.
(1) Vulnerability Management Process:
a. Where in today’s vulnerability management lifecycle ( e.g., identifying, validating, disclosing, disseminating, prioritizing, remediating) are the biggest bottlenecks that could be improved with greater AI-enabled automation?
b. Which tasks are most appropriate for AI-enabled automation? Which tasks should require human review? For tasks requiring human review, what information is needed, and how can reviews be arranged to both minimize time spent and avoid over-reliance on AI?
c. What are the novel governance and risk management considerations that should be taken into account in modernizing the vulnerability management ecosystem?
d. What other actions could NIST and others involved in the vulnerability management process take to improve vulnerability management processes?
(2) Vulnerability Information Dissemination
a. What capabilities, products, and processes, AI or otherwise, are needed to improve the responsible and timely dissemination of vulnerability information to technology developers and the broader community of affected stakeholders?
b. What existing standards and technical guidelines are most helpful for disseminating vulnerability information? What gaps in standards and guidelines exist? How should addressing those gaps be prioritized?
c. What other actions could NIST and others involved in the vulnerability management process take to improve vulnerability information dissemination?
(3) Risk Assessment and Prioritization
a. How can the use of AI or other automated mechanisms improve contextual risk prioritization? What data sources and information should be considered by NIST to inform prioritization decisions?
b. How might transparency and auditability in AI-driven prioritization decisions be enhanced?
c. What data and system context is needed by organizations to prioritize vulnerabilities accurately in production environments?
d. How can the NVD improve interoperability and integration with other vulnerability management ecosystem components ( e.g., vulnerability disclosure programs, vendor advisories, threat intelligence providers, asset management platforms, security tool vendors, remediation workflows) to enable more timely, accurate, actionable and contextual vulnerability management?
e. What other actions could NIST and others involved in the vulnerability management process take to improve risk assessment and prioritization?
(4) Remediation Development, Deployment, and Monitoring
a. What new mechanisms, standards, and procedures may be necessary for automated vulnerability remediation? What role, if any, should AI systems have in automated vulnerability remediation?
b. What organizational structures, policies, processes, and frameworks are needed for organizations and open-source projects to manage AI-generated remediations?
c. What controls and safeguards are needed to prevent erroneous AI-generated remediations?
d. What are the biggest barriers to stakeholders ( e.g., users, developers, organizations) remediating vulnerabilities after they receive prompt and comprehensive vulnerability information?
e. What process and organizational dependencies ( e.g., discovery and asset inventory) are prerequisites for organizations to more fully operationalize automated vulnerability remediation?
f. What other actions could NIST and others involved in the vulnerability management process take to improve vulnerability remediation development, deployment, and monitoring?
(5) Vulnerability Data and Standards
a. What changes are needed in organizational structures, processes, procedures, standards, and specifications to improve the quality of vulnerability data?
b. Are existing standards, context, and specifications for vulnerability data, including vulnerability identifiers, product naming schemes, and severity scoring systems, sufficient for improving actionable prioritization of vulnerabilities in the AI era? If so, please describe.
c. What gaps are there in existing standards and specifications?
d. What information is needed for organizations to efficiently and effectively manage the increasing number of identified vulnerabilities, including vulnerability prioritization and product identification?
e. What changes are needed to improve machine-readable vulnerability data ( e.g., data in the NVD) to improve vulnerability prioritization and contextualization?
f. What other actions could NIST and others involved in the vulnerability management process take to improve vulnerability data and standards?
(6) Development Processes
a. How can organizations effectively integrate AI-enabled tools into technology development processes to proactively identify, reduce, and remediate security vulnerabilities, and to enhance overall vulnerability management practices throughout the system lifecycle? What changes, if any, are needed to processes, procedures, standards, and specifications to enable this integration.
(7) Vision for the NVD
a. What has been the value of the NVD to organizations? To the extent practicable, please describe how organizations may use the NVD and what activities or decisions the NVD informs.
b. What capabilities and services can be integrated into the NVD to increase its impact over the next five years?
c. What emerging cybersecurity trends relevant to the vulnerability management should the NVD anticipate over the next five years?
d. What capabilities and services will enhance the NVD’s utility for vulnerability analysts, technology developers, researchers, and policymakers?
e. What metrics should be considered to track and evaluate the success of the NVD and any modernization efforts?
Earlier this year, NIST started a comment period for a planned update to its Guide to Operational Technology Security. They want to update it based on new lessons and include new technologies like artificial intelligence, digital twins, and zero trust systems that impact industry and key infrastructure.
InfoSecBulletin Cybersecurity for mankind
