SECURITYCYBERSCOOP
Federal audit reveals NIST’s NVD is plagued by poor planning and duplication
A federal audit found the National Institute of Standards and Technology (NIST) mismanaged its National Vulnerability Database (NVD) due to poor planning, inefficient operations, and duplication with the Cybersecurity and Infrastructure Security Agency (CISA)'s program. The backlog of unprocessed security flaws grew from 13,000 in June 2024 to over 27,000 by December 2025, with NIST failing to meet its self-imposed processing goals and wasting an estimated $200,000 on duplicated work between agencies.
Mentioned