Base
NoticeOpen for Comment2026-163712026-08-12

Request for Information (RFI) on Modernizing the National Vulnerability Database in the Age of Artificial Intelligence

Commerce Department, National Institute of Standards and Technology

Abstract

The National Institute of Standards and Technology (NIST) established and operates the National Vulnerability Database (NVD), which provides the U.S. government repository of standards-based vulnerability management data. NIST seeks stakeholder input on opportunities, challenges, and priorities for modernizing the NVD in an evolving cybersecurity landscape increasingly shaped by artificial intelligence (AI) and machine-consumable security data. NIST's goal is to improve the NVD's scalability, automation, interoperability, transparency, and utility.

Action & Dates

Action
Notice; Request for Information (RFI).
Dates
Comments in response to this notice must be received on or before October 13, 2026, at 11:59 p.m. Eastern Time. Submissions received after that date may not be considered.

Public Comment

Comments Close
2026-10-13 — Open for comment

Document Excerpt

Document Headings Document headings vary by document type but may contain the following: the agency or agencies that issued and signed a document the number of the CFR title and the number of each part the document amends, proposes to amend, or is directly related to the agency docket number / agency internal file number the RIN which identifies each regulatory action listed in the Unified Agenda of Federal Regulatory and Deregulatory Actions See the Document Drafting Handbook for more details. Department of Commerce National Institute of Standards and Technology [Docket Number: 260805-0401] XRIN 0693-XC139 AGENCY: Information Technology Laboratory (ITL), National Institute of Standards and Technology (NIST), U.S. Department of Commerce. ACTION: Notice; Request for Information (RFI). SUMMARY: The National Institute of Standards and Technology (NIST) established and operates the National Vulnerability Database (NVD), which provides the U.S. government repository of standards-based vulnerability management data. NIST seeks stakeholder input on opportunities, challenges, and priorities for modernizing the NVD in an evolving cybersecurity landscape increasingly shaped by artificial intelligence (AI) and machine-consumable security data. NIST's goal is to improve the NVD's scalability, automation, interoperability, transparency, and utility. DATES: Comments in response to this notice must be received on or before October 13, 2026, at 11:59 p.m. Eastern Time. Submissions received after that date may not be considered. ADDRESSES: Comments must be submitted electronically via the Federal e-Rulemaking Portal. 1. Go to www.regulations.gov and enter NIST-2026-0100 in the search field; 2. Click the “Comment Now!” icon, complete the required fields, including the relevant document number and title in the subject field; and 3. Enter or attach your comments. Additional information on the use of regulations.gov, including instructions for accessing agency documents, sub

Read full document on FederalRegister.gov →

Full Document

Citation: 91 FR 52042