Skip to main content
CybersecurityVulnerability Management

NIST Seeks Input on NVD Overhaul Amid AI-Driven Cybersecurity Shift

Person in office setting examines tablet with blank screen amidst papers and database backdrop.

"I would not trust the remediation of vulnerabilities in critical systems to AI just yet," said Tyler Reguly, underscoring a central tension in the U.S. government's latest push to bring the National Vulnerability Database into the age of automation.

NIST’s August 12 request and the October 13 deadline

On August 12, the National Institute for Standards and Technology (NIST) published a request for information (RFI) in the Federal Register seeking public input on modernizing the National Vulnerability Database (NVD). The Institute invited stakeholders to submit “forward-looking perspectives, practical recommendations and innovative models” that would help the NVD scale and better support automated, machine-consumable security workflows. Stakeholders have until October 13 to file their responses.

How the NVD works today: an hourlong ingestion and analyst enrichment

At present, the NVD automatically ingests common vulnerabilities and exposures (CVE) records within about an hour. After that automated intake, human analysts add contextual information such as severity scores and affected product versions. Those enriched records are published on the NVD website and made available to automated tools. NIST’s RFI notes this pipeline is mature, but increasingly strained by new operational realities.

NIST’s modernization goals: continuous, contextual, automated

NIST frames the proposed modernization as a response to an “evolving cybersecurity landscape increasingly shaped by AI and machine-consumable security data.” The Institute asked respondents to assess how the NVD can improve scalability, automation, interoperability, transparency and utility. The RFI explicitly envisions a system that is “continuous, contextual, and automated,” capable of responding effectively to emerging threats and organizational priorities.

AI’s promise — and its danger — in vulnerability management

The RFI positions AI both as an opportunity and a risk. NIST highlighted that vulnerability management is changing rapidly because of AI-enabled tools, faster technology cycles, growing volumes of vulnerabilities, and increasing demand for automation and near-real-time data. At the same time, the Institute acknowledged risks including AI-assisted vulnerability discovery and exploitation, signaling that any modernization must weigh automation gains against new threat vectors.

Fortra’s Tyler Reguly: discovery power versus remediation caution

Tyler Reguly, associate director of security R&D at Fortra, told the RFI’s conversation that AI can materially improve vulnerability discovery. He said AI, especially when applied to source code analysis, can identify “all sorts of obscure vulnerabilities” that human researchers might overlook. Yet he drew a clear line on corrective action: “I would not trust the remediation of vulnerabilities in critical systems to AI just yet,” he said, adding that “human-in-the-loop is still so critical.” Reguly suggested AI remediation may be appropriate in test environments and laboratories, but cautioned, “In production systems… not yet.”

What this means for technologists, affected enterprises, and adversaries

  • Technologists and security teams: The NVD’s move toward machine-consumable data and automated workflows could reduce time-to-awareness after a CVE is published, but teams will need to validate AI-driven findings and preserve human oversight for remediation—especially in critical production systems, as Reguly advised.
  • Affected enterprises and procurement leaders: Faster ingestion and richer automation could change patch prioritization and procurement decisions by offering more timely, machine-readable context. Procurement and operations groups will need to decide where they can trust automated remediation and where manual controls must remain.
  • Adversaries and threat actors: NIST itself noted that AI tools can accelerate vulnerability discovery, which implies that a more automated vulnerability landscape could be a double-edged sword—speeding defensive detection while also lowering the bar for offensive exploitation.

The RFI includes a list of 30 questions that invite concrete assessments of what the NVD should change and how it should integrate AI tools and automation workflows. That level of detail signals NIST is seeking practical input, not abstract debate.

At stake is a public-good repository that already operates on an hourly cadence for CVE intake but must now adapt to faster software cycles and smarter tooling. NIST’s stated aim is to make the NVD more useful to machines and people alike—more scalable, interoperable, and timely—without ceding critical decision-making to imperfect AI. Stakeholders have until October 13 to offer the models, guardrails and trade-offs that will define how vulnerability information is produced and consumed for years to come.

Read the original RFI: https://www.infosecurity-magazine.com/news/nist-seeks-public-input-ai-nvd/