NIST Shifts NVD Enrichment Strategy Pre-March 2026
📢 NIST announced a major operational change to the National Vulnerability Database (NVD), moving to a risk-based enrichment model and ceasing enrichment for all CVEs reported before March 1, 2026. The NVD will prioritize vulnerabilities in software used by the US federal government, critical software under Executive Order 14028, and entries on the CISA Known Exploited Vulnerabilities (KEV) list. CVEs that don't meet those criteria will be labeled Not Scheduled, though all submissions will still be ingested and users may request enrichment by emailing nvd@nist.gov.
