Inspector General Pins NVD Backlog on NIST Mismanagement — But the Real Problem Runs Deeper

A Commerce Department IG report calls out strategic failures, duplicated work, and severity scores that matched only 12% of the time. Budget cuts and genAI-driven vuln volume tell the rest of the story.

ThreatVectr Newsdesk· 3 min read
Inspector General Pins NVD Backlog on NIST Mismanagement — But the Real Problem Runs Deeper
Share

The Commerce Department's Office of Inspector General has formally blamed NIST for the metastasizing backlog in the National Vulnerability Database — citing poor strategic planning, refusal to coordinate with CISA, and enrichment processes that waste an estimated $200,000 since May 2024. NIST's Acting Director Craig Burkhardt accepted the technical recommendations while disputing the tone, calling the draft report's language beyond "objective, factual evaluation."

The coordination failure is damning on its own terms. CISA launched its Vulnrichment program in May 2024 and invited NIST to co-sign a joint statement. NIST declined. For roughly two years prior, CISA had been independently producing nearly all the same enrichment data as NIST — and NIST refused to ingest it because the NVD system couldn't attribute data to its actual source. That technical limitation wasn't resolved until March 2025. The IG report's verdict: NIST delayed vulnerability processing to preserve attribution credit between two federal agencies pulling from the same public information.

The IG estimates NIST could redirect approximately $800,000 to better use over the next two years by fixing enrichment efficiency alone.

Severity scoring draws sharper criticism. NIST uses CVSS — the industry standard — but internal OIG testing found that independent evaluators matched NIST's scores only 12% of the time. Jeff Williams, CTO at Contrast Security, put it plainly: that figure means the metric IT teams use to prioritize remediation "is barely better than guessing." He also flagged a point the IG report largely sidesteps — CISA covered close to half of NVD's funding before pulling back, and NIST's lab budget took cuts on top of that. "You can't pull that kind of money out of something this important and then act surprised when it breaks," he said.

On the legal question, Braden Perry, a regulatory attorney at Kennyhertz Perry, rejected NIST's statutory defense outright. The federal mandate NIST cites covers severity metrics for open-source software vulnerabilities specifically — not all CVEs, and not necessarily via CVSS. "The mandate is narrow and the practice is broad," Perry said. NIST wasn't required to recalculate scores vendors or CISA already produced. That was a policy choice, not a legal obligation.

Underlying all of this sits a structural problem the IG report doesn't fully account for: volume. GenAI tooling has sharply accelerated vulnerability discovery over the last two years, flooding the pipeline faster than any manual enrichment workflow can absorb. Williams argues the automation priority has been inverted — scanning and ticketing got automated, while threat modeling and architectural review remain manual work done by a small number of senior practitioners. "We automated the wrong half," he said.

NIST agreed with the report's recommendations. Whether agreement translates into execution is a different question entirely.

© 2026 Threat Vectr