Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Federal Civilian

Commerce OIG Calls for Changes to NIST Vulnerability Database Management

by Kristen Smith
June 2, 2026
in Federal Civilian, News
Commerce Department seal. Commerce's OIG said NIST lacks sustainable processes for managing NVD.

Commerce's OIG said NIST lacks sustainable processes for managing the National Vulnerability Database.

  • Commerce’s OIG said NIST is struggling to manage a growing vulnerability database backlog
  • The audit has identified planning, processing and coordination gaps affecting National Vulnerability Database operations
  • NIST is implementing reforms aimed at improving efficiency and stakeholder confidence

The Department of Commerce Office of Inspector General has found that the National Institute of Standards and Technology has not effectively managed the National Vulnerability Database, concluding that current processes are insufficient to eliminate a growing backlog of cybersecurity vulnerabilities and keep pace with rising submission volumes.

Table of Contents

    • You might also like
    • Lance Schroyer Nominated as ICE Director
    • USSTRATCOM Seeks to Advance EM Warfare Capabilities Through ETHEREAL FORGE
    • FBI, CISA Issue Alert on Russian Phishing Campaign Targeting Messaging App Users
  • Why Did the OIG Criticize NVD Management?
  • What Efficiency Issues Did Auditors Identify?
  • How Is NIST Responding?

You might also like

Lance Schroyer Nominated as ICE Director

USSTRATCOM Seeks to Advance EM Warfare Capabilities Through ETHEREAL FORGE

FBI, CISA Issue Alert on Russian Phishing Campaign Targeting Messaging App Users

According to the OIG’s report published May 26, NIST lacks sustainable processes for handling vulnerability submissions and will be unable to clear its backlog or prevent future delays without significant operational changes. The watchdog identified shortcomings in strategic planning, vulnerability processing, coordination with federal partners and stakeholder communications.Commerce OIG Calls for Changes to NIST Vulnerability Database Management

The challenges highlighted in the NVD report underscore the importance of cybersecurity modernization in federal civilian agencies. Learn how agencies are addressing evolving cyber risks and technology priorities at the Potomac Officers Club’s 2026 FedCiv Summit on Oct. 29. Register now!

Why Did the OIG Criticize NVD Management?

The NVD serves as a central source of vulnerability information used by government agencies, contractors and private sector cybersecurity teams. NIST enriches Common Vulnerabilities and Exposures records with additional information, such as severity ratings and affected product data, to help organizations prioritize remediation efforts.

The OIG found that a contract lapse in February 2024 contributed to a growing backlog of unprocessed vulnerabilities. Although NIST publicly stated that it expected to eliminate the backlog by September 2024, auditors said the agency lacked a realistic plan to achieve that goal. The backlog expanded from about 13,000 vulnerabilities in June 2024 to more than 27,000 by the end of 2025.

According to the report, annual vulnerability submissions could surpass 60,000 in 2026, further increasing pressure on the program.

What Efficiency Issues Did Auditors Identify?

Auditors said NIST could improve the sustainability of the NVD by reducing duplicated work and streamlining enrichment activities. The report estimated that the agency could allocate approximately $800,000 more effectively over the next two years. This would be by limiting independent severity scoring when vulnerability records already contain scores from other sources.

The OIG also found overlap between NIST’s enrichment efforts and the Cybersecurity and Infrastructure Security Agency’s Vulnrichment program. According to the report, the agencies duplicated enrichment activities on at least 21,000 vulnerabilities between May 2024 and December 2025, resulting in an estimated $200,000 in unnecessary costs.

In addition, auditors said stakeholders expressed frustration with NIST’s communications regarding the backlog and vulnerability processing status, contributing to reduced confidence in the database.

How Is NIST Responding?

NIST concurred with all recommendations included in the report and said it is taking steps to address the findings. The agency said it is developing a strategic plan for the NVD, creating a backlog management plan, coordinating more closely with CISA and establishing a communications strategy for stakeholders. NIST also said it will no longer routinely calculate severity scores when those ratings have already been provided.

NIST announced operational updates in April that align with several of the recommendations. Those changes include a revised prioritization approach that focuses enrichment efforts on vulnerabilities listed in CISA’s Known Exploited Vulnerabilities catalog, software used by federal agencies and vulnerabilities designated as critical under Executive Order 14028. Vulnerabilities outside those categories may remain published in the database but could be designated as “Not Scheduled” for enrichment.

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19

Recommended For You

Lance Schroyer Nominated as ICE Director

by Jane Edwards
June 29, 2026
Lance Schroyer. The senior adviser to the secretary of DHS has been nominated to serve as director of ICE.

President Trump has nominated Lance Schroyer to lead ICESchroyer has served as a senior adviser at DHS and led immigration enforcement coordination under the 287(g) programThe Potomac Officers...

Read moreDetails

USSTRATCOM Seeks to Advance EM Warfare Capabilities Through ETHEREAL FORGE

by Jane Edwards
June 29, 2026
AnnMarie Anthony. The JEC director at USSTRATCOM commented on the ETHEREAL FORGE initiative to advance EW capabilities.

USSTRATCOM has launched ETHEREAL FORGE to accelerate electromagnetic warfare capability deploymentThe initiative advances rapid, software-centric testing and fielding and supports MOSA-compatible systemsThe Potomac Officers Club will host two...

Read moreDetails

FBI, CISA Issue Alert on Russian Phishing Campaign Targeting Messaging App Users

by Miles Jamison
June 29, 2026
Phishing. The FBI and CISA have issued an alert on a Russian phishing campaign targeting commercial messaging app users.

The FBI has linked an ongoing messaging app phishing campaign to Russian intelligence cyber actorsThe phishing campaign targets government officials, military personnel, journalists and Ukraine-based officialsThe attackers pose...

Read moreDetails

New FedRAMP 20x Launched to Provide Better Cloud Certification

by Jamie Bennet
June 29, 2026
Federal Risk and Authorization Management Program. The FedRAMP 20x cloud certification along with 2026 rules.

The Federal Risk and Authorization Management Program's FedRAMP 20x cloud certification went live after the program released the Consolidated Rules for 2026FedRAMP 20x will eventually replace FedRAMP Rev5...

Read moreDetails

NASA Unveils 41 Awardees for 2025 Announcement of Collaboration Opportunity

by Jamie Bennet
June 29, 2026
NASA. The space agency has named the 37 companies chosen for the 2025 Announcement of Collaboration Opportunity.

NASA has announced the awardees for its 2025 Announcement of Collaboration OpportunityThirty-seven companies will execute 41 proposals centered on technologies to be used on the Moon and in...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • DHS
  • Digital Assets
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved.

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved.

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!