The US National Institute of Standards and Technology (NIST) has made a significant move in the cybersecurity landscape by unveiling plans to transfer certain aspects of the management of the National Vulnerability Database (NVD) to an industry consortium. The NVD, launched by NIST in 2005, is the world’s most widely used software vulnerability repository.
The Transition
NIST’s decision to hand over the reins of NVD management comes after years of operation by the agency itself. The transition aims to enhance collaboration and efficiency in maintaining this critical resource. The official announcement was made during the VulnCon cybersecurity conference, hosted by the Forum of Incident Response and Security Teams (FIRST) in Raleigh, North Carolina.
Why the Change?
The recent slowdown in vulnerability enrichment data uploads on the NVD website raised concerns among security researchers. In February 2024, NIST halted the enrichment process, leaving over 4,000 Common Vulnerabilities and Exposures (CVEs) unanalysed. Given that the NVD serves as the backbone for organisations worldwide to deploy updates and patches, this situation posed a significant risk.
Tom Pace, CEO of firmware security provider NetRise, emphasised the challenge: “Asking the entire cybersecurity community to manually identify vulnerabilities across operating systems, software packages, applications, firmware, and devices overnight is an impossible task.” The absence of timely analysis could leave organisations vulnerable and disrupt their overall security posture.
Industry Collaboration
To address the NVD backlog, several security companies, including VulnCheck, Anchore, and RiskHorizon AI, have stepped up to develop alternative solutions. These initiatives aim to complement the traditional vulnerability disclosure provided by the NVD. However, the industry eagerly awaits the formal establishment of the consortium to ensure a coordinated and sustainable approach.
Dan Lorenc, co-founder and CEO of software security provider Chainguard, highlighted the urgency: “Scanners, analysers, and most vulnerability tools rely on the NVD to determine software affected by vulnerabilities. Without effective triage, organisations face increased risk.”
The NVD consortium represents a collaborative effort to safeguard the digital ecosystem. As the transition unfolds, the cybersecurity community anticipates improved tools, methods, and a more resilient NVD.



