Build1 distinct publisher3 min readUpdated
V-etalon has no release date, no repository, and no published evaluation. Teams still treating NVD enrichment as authoritative should line up a second source now.
The Engineer · Build desk
Compiled by The EngineerSomething wrong?How this is made
NIST has opened a Request for Information on the National Vulnerability Database's "scalability, automation, interoperability, transparency, and utility," and used an accompanying blog post to disclose that it has begun building an AI-enabled tool called V-etalon [1][2]. That matters because the request lands four months after NIST moved most CVEs outside routine enrichment, and less than three months after a federal audit found the agency had no strategic plan for the NVD, no workable plan to clear its backlog, and no sustainable process for keeping pace with new submissions [3][4].
The disclosure runs to one paragraph, placed under the heading "Steps We've Already Taken," in which NIST says the tool uses AI "to aid in enriching vulnerability information" and that it hopes V-etalon "will eventually provide a foundation for the evaluation of vulnerability information," with feedback and collaboration to follow via GitHub after an unspecified release [5]. According to socket.dev's reading of the post, there is no release date, no repository, no documentation, no architecture, no evaluation results, and no list of the enrichment fields the tool will address [6]. NIST does not say whether V-etalon will produce CVSS scores, assign CWEs, build CPE applicability statements, validate data supplied by CVE Numbering Authorities, or do something else entirely [7]. Aiding enrichment and evaluating enrichment are different jobs, and the post does not explain how the output would enter the production workflow or how human analysts would review it [8]. The RFI itself asks the public which vulnerability management tasks suit AI, which require human review, what safeguards apply, and how AI-driven decisions stay transparent and auditable [9]. Those are design questions for a tool NIST says is already under construction.
The pattern is older than the tool. In May 2024, while promising to clear the backlog by the end of that fiscal year, NIST cited "technology and process updates" to support automation of vulnerability management [10]. It missed the deadline, and federal auditors later calculated that hitting it would have required processing about 6,200 vulnerabilities per month, above both NIST's historical output and its estimated maximum capacity [11]. In November 2024, with the backlog past 20,000 CVEs, NIST said it was developing new systems for Authorized Data Publisher content [12]. It did ship ADP ingestion, including enrichment supplied by CISA, which improved ingestion and attribution but did not automate the core enrichment work [13]. March 2025 brought "exploring the use of machine learning" with no tasks, tools, milestones, or delivery dates named [14]. At VulnCon the following month, NVD leaders described pilot tools for Linux kernel CVE enrichment and research into machine learning methods, without a public pilot or a production deployment [15]. In April 2026, NIST again pointed to "automated systems and workflow enhancements" [16]. That is roughly 23 months between the first automation promise and the latest one [17].
The operational consequence is unglamorous. If a gate in your pipeline depends on NVD-populated CVSS vectors or CPE ranges, treat that dependency as unfunded until proven otherwise. The one enrichment improvement that actually shipped originated outside NIST: CISA's ADP enrichment, which NIST ingests [13]. Pulling enrichment from the CVE record and upstream publishers, rather than waiting on NVD analysts, is the path that currently carries weight.
Watch for the GitHub release NIST has promised [5], and specifically whether it names the fields V-etalon touches, publishes evaluation results against analyst-enriched records, and defines the human review step before any output reaches production. Watch also whether the strategic planning this RFI is meant to inform [18] yields a dated backlog plan of the kind the audit said did not exist [4].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
NIST's Request for Information seeks input on improving the NVD's "scalability, automation, interoperability, transparency, and utility."
A NIST blog post accompanying the RFI disclosed that the agency has begun developing an AI-enabled tool called V-etalon.
The announcement arrives four months after NIST moved most CVEs outside routine enrichment.
Less than three months before the announcement, a federal audit found that NIST had no strategic plan for the NVD, no workable plan to clear its backlog, and no sustainable process for keeping pace with new submissions.
NIST offered one paragraph on V-etalon under the heading "Steps We've Already Taken", saying it has begun work on a tool that uses AI technologies "to aid in enriching vulnerability information", that it hopes V-etalon "will eventually provide a foundation for the evaluation of vulnerability information", and that it will look for feedback and collaboration opportunities via GitHub once it is available, pending an upcoming release and announcement.
The V-etalon disclosure provides no release date, repository, documentation, architecture, evaluation results, or description of which enrichment fields the tool will address.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary documents quoted, single publisher
Claims rest on direct quotation of NIST's RFI and blog post plus cited federal audit findings, which is strong documentary grounding for what NIST said. But there is exactly one covering publisher, no independent corroboration of the audit or of NVD throughput figures, and the central subject (V-etalon) has no inspectable artifact anyone can verify against.
Announced tool has zero observable uptake
V-etalon has no release, repository, pilot link, or production deployment, so adoption of the announced AI capability is effectively nil. The only concrete shipped changes in the record are ADP/CISA enrichment ingestion and the April 2026 enrichment-scope reduction, neither of which is AI enrichment; earlier VulnCon-described pilots were never linked publicly.
Institutional claim outruns deliverables
NIST presents V-etalon under 'Steps We've Already Taken' and frames AI as the modernization answer while supplying no date, code, evaluation, or workflow integration plan, and while the same RFI still asks which tasks AI should handle at all; that is a substantial overstatement relative to observable delivery, reinforced by roughly 23 months of restated automation intent. The gap is attributed to the announcing agency, not to the coverage, which is explicitly skeptical.
Audit-response incentive plus vendor framing
NIST discloses an AI initiative within months of an audit finding no strategic plan and no workable backlog plan, an obvious institutional incentive to show motion. On the reporting side, the sole publisher is a software supply-chain security vendor and its dek advises teams to line up a second enrichment source, an interest in NVD substitution that the piece does not disclose. Both incentives are inferable from the supplied material; no funding, contract, or revenue figures are given.
Solid on statements, thin on verification
High confidence that NIST said what is quoted and that the artifacts are absent, because the record is largely negative evidence plus verbatim quotation. Lower confidence on program reality: one publisher, no NIST response, no independent audit text, unspecified deployment dates for ADP ingestion, and no way to test whether V-etalon is further along than the disclosure suggests.
security
One packet reboots your Cisco VPN box, and Cisco will not say who is firing it1 distinct publisher
security
Ransomware's price point is $10m to $1bn in revenue, and it is not moving1 distinct publisher
build
Your scanner finds it in seconds; the average fix now takes 252 days1 distinct publisher
security
Mythos's method, not its zero-day count, is what breaks CVE-keyed vuln management1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 16, 2026