On October 13, 2026, the deadline for NIST's Request for Information (RFI) will close. If your team hasn't submitted feedback yet, you're missing a key opportunity to influence the future of vulnerability management.
This isn't about a single breach. It's about a systemic issue: the cybersecurity community's lack of engagement with tools we rely on daily. The National Vulnerability Database processes over 20,000 CVEs annually, yet most security teams treat it as a static resource rather than a collaborative system they can help shape.
What Happened
NIST announced plans to modernize the NVD with AI technologies, specifically through a tool called V-etalon. They opened a comment period ending October 13, 2026, seeking input on how AI should enhance vulnerability management workflows.
The core issue is that the NVD's current architecture can't keep up with modern software development. Your team likely runs CI/CD pipelines that deploy multiple times a day. The NVD was designed for a time when quarterly patch cycles were the norm.
Timeline of Missed Opportunities
Years 1-3: Security teams used NVD data through scanners and SBOMs without questioning the data model. Few asked why CVSS scores appeared weeks after disclosure or why third-party vendors had to fill gaps in enrichment data.
Month 0: NIST publishes the RFI. Most security engineers don't read Federal Register notices.
Month 1-2: Vendors respond. Your tool providers submit detailed requirements, but your team continues using those tools, unaware of the feedback window.
Month 3-6: Academic researchers and large enterprises contribute. Mid-market companies, where you probably work, remain silent. The RFI deadline looms.
Post-deadline: NIST designs V-etalon based on received input. Your workflows aren't represented because you didn't participate.
Which Controls Failed or Were Missing
This failure relates to multiple control families across frameworks:
NIST 800-53, RA-5 (Vulnerability Monitoring and Scanning): Your organization likely has a control stating you "monitor and scan for vulnerabilities in the system and hosted applications." But RA-5(5) requires you to "update the system vulnerabilities to be scanned when new vulnerabilities are identified and reported."
The missing piece: you're not contributing to the system that identifies those vulnerabilities. When NIST asks how AI should prioritize which vulnerabilities get enriched first, your team's actual triage patterns aren't in the dataset.
ISO 27001, Annex A 8.8 (Management of Technical Vulnerabilities): This control requires you to "obtain information about technical vulnerabilities of information systems in use." While it doesn't explicitly require you to improve that information source, the intent is clear: vulnerability management is a continuous improvement process.
NIST CSF, ID.RA-1 (Asset Vulnerabilities): The framework expects you to "identify vulnerabilities in assets." When the primary database for vulnerability identification asks how it should evolve, and you don't respond, you're accepting whatever someone else decides your workflow should look like.
What the Standards Actually Require
Here's what your compliance documentation probably says versus what you're actually doing:
Your documented process: "We maintain current vulnerability data from authoritative sources including the NVD."
Your actual process: You ingest NVD feeds through a commercial scanner, wait for CVSS scores to populate (often 2-4 weeks after CVE publication), then manually enrich with data from vendor advisories, exploit databases, and threat intelligence feeds.
What the standards expect: Continuous improvement of your vulnerability management program. PCI DSS v4.0.1 Requirement 6.3.1 requires you to "identify security vulnerabilities using reputable outside sources for security vulnerability information." That word "reputable" implies you should care whether your sources are keeping pace with threats.
If NIST builds V-etalon without input from teams like yours, you'll end up with AI-enriched data that doesn't match your decision criteria. Maybe the AI prioritizes vulnerabilities based on theoretical exploitability, while your team needs to know about active exploitation in your industry. That gap becomes your problem to solve with yet another vendor tool.
Lessons and Action Items
For this RFI cycle (if you're reading this before October 13, 2026):
Submit feedback focused on your actual workflow gaps. Don't write a research paper. Tell NIST:
- Which vulnerability attributes you manually research because NVD doesn't provide them (patch complexity, configuration prerequisites, exploitation prerequisites)
- How you currently prioritize vulnerabilities and what data points you wish existed
- Whether your team could consume real-time AI-enriched feeds or needs batch updates
For your ongoing vulnerability management program:
Map your data dependencies: Document every vulnerability data source your team uses beyond the NVD. If you're pulling from five different sources to make patch decisions, you've identified an integration problem that AI could potentially solve.
Track enrichment lag: Measure the time between CVE publication and when you have enough data to make a patch decision. If it's consistently over 48 hours, you have a quantifiable problem to solve.
Participate in standards development: Add "review open RFIs from NIST, CISA, and relevant standards bodies" to your quarterly security roadmap planning. Assign someone to monitor Federal Register notices in the vulnerability management category.
Test AI-assisted tools now: Don't wait for V-etalon. Experiment with existing AI-based vulnerability prioritization tools and document what works versus what creates noise. This gives you concrete feedback for future RFI cycles.
Build feedback loops: When your scanner's AI-based prioritization is wrong, document why. When it's right, document that too. This operational data is what NIST needs to build effective tools.
The NVD modernization isn't a future problem. It's happening now, with or without your input. The October 13, 2026 deadline is just one milestone in a continuous process. Your team's silence is a choice that shapes the tools you'll be required to use.
If you're reading this after the deadline, the next RFI will come. Start building your feedback now.



