The National Institute of Standards and Technology (NIST) is seeking industry and government input on how to modernize the National Vulnerability Database (NVD) as artificial intelligence increasingly changes the way organizations identify, assess, and remediate cybersecurity vulnerabilities.
NIST has issued a request for information (RFI) focused on the future of the NVD, asking stakeholders to weigh in on the technologies, processes and capabilities that could shape vulnerability management over the next five years. The agency is particularly interested in how AI can be incorporated while maintaining appropriate human oversight, transparency, security and data quality.
According to a notice published Wednesday in the Federal Register, NIST will accept comments on the RFI through Oct. 13, 2026.
The request comes as federal agencies and private-sector organizations assess how AI is affecting cybersecurity operations and vulnerability management. Those issues are also expected to be discussed at the 2026 FedCiv Summit on Oct. 29, where government and industry participants will examine AI adoption, cloud infrastructure, cybersecurity, and workforce enablement as part of broader federal civilian modernization efforts.
National Vulnerability Database Modernization Comes as AI Reshapes Security
The NIST NVD is a standards-based repository established and operated by NIST for the U.S. government. It has become a foundational resource for vulnerability management, software security, compliance automation, and cybersecurity risk analysis across both government and commercial environments.
The NVD receives Common Vulnerabilities and Exposures (CVE) records through automated processes, generally ingesting new records within about an hour of publication. NIST analysts subsequently enrich the records with additional information, including severity scores and details about affected product versions.


Users and cybersecurity tools can access that information through the NVD’s web interface as well as automated mechanisms. The database therefore plays an important role in helping organizations understand publicly disclosed vulnerabilities and incorporate vulnerability information into security workflows.
As AI-enabled security tools become more common, however, the way vulnerability information is collected, interpreted, prioritized, and acted upon is changing. NIST’s RFI seeks to determine how the NVD can evolve to address those changes.
NIST Seeks Answers Across Seven National Vulnerability Database Areas
NIST has organized the RFI around seven topic areas, allowing respondents to address any or all of the subjects.
- Vulnerability Management Process: NIST seeks input on using automation to reduce bottlenecks while keeping human oversight for high-risk decisions.
- Vulnerability Information Dissemination: NIST wants recommendations on tools, standards, and processes for securely and effectively sharing vulnerability data.
- Risk Assessment and Prioritization: Stakeholders are asked how AI can improve risk-based vulnerability prioritization, transparency, and interoperability.
- Remediation Development and Monitoring: NIST seeks guidance on standards and safeguards for developing, deploying, and monitoring AI-generated fixes.
- NVD Data and Standards: The RFI focuses on improving vulnerability data quality, governance, and machine-readability for security tools.
- Development Processes: NIST wants to explore how AI-enabled tools can be integrated into software development to identify and address vulnerabilities earlier.
- Future Vision for the NVD: Stakeholders are asked to recommend capabilities, services, and performance metrics for the NVD over the next five years.

