Cybersecurity Policy Report, Commerce IG Finds Flaws in NIST’s Management of Cyber Vulnerability Database, (Jun 1, 2026)
The National Institute of Standards and Technology has mismanaged a cybersecurity vulnerability database that’s key to the cyber defenses of the government and private sector, according to the Commerce Department’s inspector general.
NIST’s National Vulnerability Database (NVD) receives data from a similar data-collection effort managed by the Cybersecurity and Infrastructure Security Agency, the IG noted in its report. The common vulnerabilities and exposures (CVEs) collected by CISA feed into the NVD, where the data is manually “enriched” by, among other things, assigning each CVE a “severity” score.
But the enrichment process slowed significantly in 2024 when a contract lapsed, depriving NIST of the personnel needed to maintain the NVD, the IG explained. After awarding a new contract a few months later, NIST pledged to clear the enrichment backlog by September 2024 but failed to do so, the IG said.
“This backlog has significantly affected both the federal government and the private sector, which rely on timely NVD enrichment to automate vulnerability management and defend against cyber threats,” it said.
“In the absence of real-time enrichment, users are forced to analyze vulnerabilities themselves or turn to other sources (such as commercial products). This raises the likelihood that critical vulnerabilities will be unmitigated and increases the resources required by cybersecurity practitioners to assess risk, triage threats, and prioritize remediation,” the IG added.
The IG recommended that NIST develop “a strategic plan for the NVD that reflects the NVD’s role in the overall vulnerability management ecosystem, establishes priorities, and ensures long-term sustainability of processing capacity.”
NIST should also establish a backlog management plan, place less emphasis on adding severity scores to every vulnerability, and eliminate overlaps between NIST’s NVD and CISA’s vulnerability cataloging efforts, according to the IG. NIST concurred with the recommendations, the IG said.
NIST recently announced that it would streamline its work on the NVD by ending enrichment for vulnerabilities that seem less consequential (CPR, April 16). That step, the IG said, “aligned with our recommendations.”
“NIST considers the NVD a key piece of the U.S. cybersecurity infrastructure, but its actions to resolve and prevent processing backlogs do not reflect that characterization,” the IG said. “Until the backlog is resolved and processes are made sustainable, the NVD will not achieve its mission, and public trust in the NVD will continue to erode.”
News: FederalLegislation DataSecurity