Build1 publisher3 min readPublished
NIST answers an NVD audit with an AI tool nobody outside NIST has seen
V-etalon has no release date, no repository, and no published evaluation. Teams still treating NVD enrichment as authoritative should line up a second source now.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- NIST's Request for Information seeks input on improving the NVD's "scalability, automation, interoperability, transparency, and utility."
- A NIST blog post accompanying the RFI disclosed that the agency has begun developing an AI-enabled tool called V-etalon.
- The announcement arrives four months after NIST moved most CVEs outside routine enrichment.
- Less than three months before the announcement, a federal audit found that NIST had no strategic plan for the NVD, no workable plan to clear its backlog, and no sustainable process for keeping pace with new submissions.
- NIST offered one paragraph on V-etalon under the heading "Steps We've Already Taken", saying it has begun work on a tool that uses AI technologies "to aid in enriching vulnerability information", that it hopes V-etalon "will eventually provide a foundation for the evaluation of vulnerability information", and that it will look for feedback and collaboration opportunities via GitHub once it is available, pending an upcoming release and announcement.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
NIST has opened a Request for Information on the National Vulnerability Database's "scalability, automation, interoperability, transparency, and utility," and used an accompanying blog post to disclose that it has begun building an AI-enabled tool called V-etalon [1][2]. That matters because the request lands four months after NIST moved most CVEs outside routine enrichment, and less than three months after a federal audit found the agency had no strategic plan for the NVD, no workable plan to clear its backlog, and no sustainable process for keeping pace with new submissions [3][4].
The disclosure runs to one paragraph, placed under the heading "Steps We've Already Taken," in which NIST says the tool uses AI "to aid in enriching vulnerability information" and that it hopes V-etalon "will eventually provide a foundation for the evaluation of vulnerability information," with feedback and collaboration to follow via GitHub after an unspecified release [5]. According to socket.dev's reading of the post, there is no release date, no repository, no documentation, no architecture, no evaluation results, and no list of the enrichment fields the tool will address [6]. NIST does not say whether V-etalon will produce CVSS scores, assign CWEs, build CPE applicability statements, validate data supplied by CVE Numbering Authorities, or do something else entirely [7]. Aiding enrichment and evaluating enrichment are different jobs, and the post does not explain how the output would enter the production workflow or how human analysts would review it [8]. The RFI itself asks the public which vulnerability management tasks suit AI, which require human review, what safeguards apply, and how AI-driven decisions stay transparent and auditable [9]. Those are design questions for a tool NIST says is already under construction.
The pattern is older than the tool. In May 2024, while promising to clear the backlog by the end of that fiscal year, NIST cited "technology and process updates" to support automation of vulnerability management [10]. It missed the deadline, and federal auditors later calculated that hitting it would have required processing about 6,200 vulnerabilities per month, above both NIST's historical output and its estimated maximum capacity [11]. In November 2024, with the backlog past 20,000 CVEs, NIST said it was developing new systems for Authorized Data Publisher content [12]. It did ship ADP ingestion, including enrichment supplied by CISA, which improved ingestion and attribution but did not automate the core enrichment work [13]. March 2025 brought "exploring the use of machine learning" with no tasks, tools, milestones, or delivery dates named [14]. At VulnCon the following month, NVD leaders described pilot tools for Linux kernel CVE enrichment and research into machine learning methods, without a public pilot or a production deployment [15]. In April 2026, NIST again pointed to "automated systems and workflow enhancements" [16]. That is roughly 23 months between the first automation promise and the latest one [17].
The operational consequence is unglamorous. If a gate in your pipeline depends on NVD-populated CVSS vectors or CPE ranges, treat that dependency as unfunded until proven otherwise. The one enrichment improvement that actually shipped originated outside NIST: CISA's ADP enrichment, which NIST ingests [13]. Pulling enrichment from the CVE record and upstream publishers, rather than waiting on NVD analysts, is the path that currently carries weight.
Watch for the GitHub release NIST has promised [5], and specifically whether it names the fields V-etalon touches, publishes evaluation results against analyst-enriched records, and defines the human review step before any output reaches production. Watch also whether the strategic planning this RFI is meant to inform [18] yields a dated backlog plan of the kind the audit said did not exist [4].