The National Institute of Standards and Technology (NIST) is seeking industry and government input on how to modernize the National Vulnerability Database (NVD) as artificial intelligence increasingly changes the way organizations identify, assess, and remediate cybersecurity vulnerabilities.
NIST has issued a request for information (RFI) focused on the future of the NVD, asking stakeholders to weigh in on the technologies, processes and capabilities that could shape vulnerability management over the next five years. The agency is particularly interested in how AI can be incorporated while maintaining appropriate human oversight, transparency, security and data quality.
According to a notice published Wednesday in the Federal Register, NIST will accept comments on the RFI through Oct. 13, 2026.
The request comes as federal agencies and private-sector organizations assess how AI is affecting cybersecurity operations and vulnerability management. Those issues are also expected to be discussed at the 2026 FedCiv Summit on Oct. 29, where government and industry participants will examine AI adoption, cloud infrastructure, cybersecurity, and workforce enablement as part of broader federal civilian modernization efforts.
The NIST NVD is a standards-based repository established and operated by NIST for the U.S. government. It has become a foundational resource for vulnerability management, software security, compliance automation, and cybersecurity risk analysis across both government and commercial environments.
The NVD receives Common Vulnerabilities and Exposures (CVE) records through automated processes, generally ingesting new records within about an hour of publication. NIST analysts subsequently enrich the records with additional information, including severity scores and details about affected product versions.
Users and cybersecurity tools can access that information through the NVD’s web interface as well as automated mechanisms. The database therefore plays an important role in helping organizations understand publicly disclosed vulnerabilities and incorporate vulnerability information into security workflows.
As AI-enabled security tools become more common, however, the way vulnerability information is collected, interpreted, prioritized, and acted upon is changing. NIST’s RFI seeks to determine how the NVD can evolve to address those changes.
NIST has organized the RFI around seven topic areas, allowing respondents to address any or all of the subjects.