NIST Just Derailed Patch Prioritization — Here’s Your Fix
by [Matt Tankersley](/content/author/tank/ "Posts by Matt Tankersley"/index.html)
Key Takeaways
- NIST stopped automatic CVSS scoring for most CVEs on April 15 — the patch prioritization signal most organizations relied on just changed permanently.
- Only CVEs on CISA's KEV list, federal software, and EO 14028 critical software receive full NVD enrichment. Everything else is "Not Scheduled" — no automatic severity rating.
- Organizations without a dedicated security team have lost their primary free triage tool for deciding what to patch first.
- TC21-05 (Security Updates & Patch Management) paired with expert threat intelligence is the structured response — defense-in-depth means never relying on a single data source that can derail overnight.
- If you can't answer whether your patch process can survive without NVD scores, start with a free risk assessment at topcyber21.help.
On April 15, 2026, NIST derailed the patch prioritization process most organizations depend on — and most organizations haven’t noticed yet.
What NIST Changed — and Why
The National Institute of Standards and Technology (NIST) announced April 15 that it will no longer automatically enrich every CVE published to the National Vulnerability Database. For years, NVD's CVSS scores have been the de facto triage tool for patch management — the standard severity rating that tells teams whether a vulnerability is Low, Medium, High, or Critical. That signal is now gone for most vulnerabilities.
Under the new model, only CVEs meeting one of three criteria receive full enrichment: those listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, those affecting software used by the federal government, and those affecting software designated "critical" under Executive Order 14028. Everything else lands in a category NIST calls "Not Scheduled." No CVSS score. No automatic severity rating. Just a CVE ID and a description.
Why did NIST do this? The math stopped working. CVE submissions are up 263% since 2020, with Q1 2026 tracking nearly one-third higher than the same period last year. NIST enriched nearly 42,000 CVEs in 2025 — a 45% year-over-year increase — and still couldn't keep pace. The decision to triage is understandable. The consequences for unprepared organizations are not.
What the NVD Change Means for Your Patch Prioritization Process
If your organization runs a dedicated security operations team with threat intelligence feeds, CISA KEV correlation workflows, and structured patch management processes — this change is manageable. You already knew better than to rely solely on NVD as your only data source.
If your organization is like most — running Microsoft 365 or Google Workspace, operating without a dedicated SOC, depending on IT generalists who use publicly available severity data to triage patch cycles — this change just removed a critical tool without replacing it. A vulnerability can be disclosed tomorrow with no CVSS score attached. Your team may not know whether to patch it this afternoon or next quarter.
Attackers are not waiting for NIST to catch up. They know what's exploitable before a severity score ever gets assigned. This is what #CYBERinsanity looks like in 2026 — not a sophisticated breach, but an organization making patching decisions with incomplete information because the free signal they depended on quietly went dark.
The TOPCYBER21™ Response — TC21-05 and the Expert Intelligence Layer
This is exactly the environment TOPCYBER21™ was built for — not a world where every piece of vulnerability intelligence is clean, complete, and handed to you, but the real world where data sources change, signals disappear, and organizations need expert guidance to stay ahead.
TC21-05 — Security Updates & Patch Management is one of the 21 best practice areas in the TOPCYBER21™ framework because effective patch management has never been just about scores. It requires context: which assets are exposed? Which vulnerabilities are being actively exploited? Which patches carry operational risk if deployed incorrectly? That judgment can't come from a database entry. It comes from a team that knows your environment and stays current on the threat landscape.
Defense-in-depth means you don't rely on any single data source that can derail overnight. Protect first, document after, adapt accordingly. That's how our clients operate — not reactively, but with a framework and partnership that doesn't break when a government agency changes its operational model.
Three questions worth asking right now: Does your patch management process have a fallback when NVD scores aren't available? Is your team cross-referencing CISA's KEV catalog on every new CVE? And when the free signal disappears, what replaces it? If any of those answers are unclear, that's where you start.
263%
Increase in CVE submissions since 2020 — the surge NIST could no longer keep pace with, driving the permanent end of automatic severity scoring for most vulnerabilities in the NVD.
Source: NIST — National Institute of Standards and Technology
Ready to STOP the #CYBERinsanity?
The free 15-minute risk assessment at topcyber21.help tells you exactly where your gaps are — before an attacker finds them first.