TechOnPurpose Logo

NIST Just Derailed Patch Prioritization — Here’s Your Fix

by | Apr 16, 2026

⏱ 3 min read

Key Takeaways

  • NIST stopped automatic CVSS scoring for most CVEs on April 15 — the patch prioritization signal most organizations relied on just changed permanently.
  • Only CVEs on CISA's KEV list, federal software, and EO 14028 critical software receive full NVD enrichment. Everything else is "Not Scheduled" — no automatic severity rating.
  • Organizations without a dedicated security team have lost their primary free triage tool for deciding what to patch first.
  • TC21-05 (Security Updates & Patch Management) paired with expert threat intelligence is the structured response — defense-in-depth means never relying on a single data source that can derail overnight.
  • If you can't answer whether your patch process can survive without NVD scores, start with a free risk assessment at topcyber21.help.

On April 15, 2026, NIST derailed the patch prioritization process most organizations depend on — and most organizations haven’t noticed yet.

What NIST Changed — and Why

The National Institute of Standards and Technology (NIST) announced April 15 that it will no longer automatically enrich every CVE published to the National Vulnerability Database. For years, NVD's CVSS scores have been the de facto triage tool for patch management — the standard severity rating that tells teams whether a vulnerability is Low, Medium, High, or Critical. That signal is now gone for most vulnerabilities.

Under the new model, only CVEs meeting one of three criteria receive full enrichment: those listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, those affecting software used by the federal government, and those affecting software designated "critical" under Executive Order 14028. Everything else lands in a category NIST calls "Not Scheduled." No CVSS score. No automatic severity rating. Just a CVE ID and a description.

Why did NIST do this? The math stopped working. CVE submissions are up 263% since 2020, with Q1 2026 tracking nearly one-third higher than the same period last year. NIST enriched nearly 42,000 CVEs in 2025 — a 45% year-over-year increase — and still couldn't keep pace. The decision to triage is understandable. The consequences for unprepared organizations are not.


What the NVD Change Means for Your Patch Prioritization Process

If your organization runs a dedicated security operations team with threat intelligence feeds, CISA KEV correlation workflows, and structured patch management processes — this change is manageable. You already knew better than to rely solely on NVD as your only data source.

If your organization is like most — running Microsoft 365 or Google Workspace, operating without a dedicated SOC, depending on IT generalists who use publicly available severity data to triage patch cycles — this change just removed a critical tool without replacing it. A vulnerability can be disclosed tomorrow with no CVSS score attached. Your team may not know whether to patch it this afternoon or next quarter.

Attackers are not waiting for NIST to catch up. They know what's exploitable before a severity score ever gets assigned. This is what #CYBERinsanity looks like in 2026 — not a sophisticated breach, but an organization making patching decisions with incomplete information because the free signal they depended on quietly went dark.


The TOPCYBER21™ Response — TC21-05 and the Expert Intelligence Layer

This is exactly the environment TOPCYBER21™ was built for — not a world where every piece of vulnerability intelligence is clean, complete, and handed to you, but the real world where data sources change, signals disappear, and organizations need expert guidance to stay ahead.

TC21-05 — Security Updates & Patch Management is one of the 21 best practice areas in the TOPCYBER21™ framework because effective patch management has never been just about scores. It requires context: which assets are exposed? Which vulnerabilities are being actively exploited? Which patches carry operational risk if deployed incorrectly? That judgment can't come from a database entry. It comes from a team that knows your environment and stays current on the threat landscape.

Defense-in-depth means you don't rely on any single data source that can derail overnight. Protect first, document after, adapt accordingly. That's how our clients operate — not reactively, but with a framework and partnership that doesn't break when a government agency changes its operational model.

Three questions worth asking right now: Does your patch management process have a fallback when NVD scores aren't available? Is your team cross-referencing CISA's KEV catalog on every new CVE? And when the free signal disappears, what replaces it? If any of those answers are unclear, that's where you start.


263%

Increase in CVE submissions since 2020 — the surge NIST could no longer keep pace with, driving the permanent end of automatic severity scoring for most vulnerabilities in the NVD.

Source: NIST — National Institute of Standards and Technology

Ready to STOP the #CYBERinsanity?

The free 15-minute risk assessment at topcyber21.help tells you exactly where your gaps are — before an attacker finds them first.


About the Author

Matt Tankersley, CISSP is a US Navy combat veteran, Founder & CEO of TechOnPurpose, and creator of the TOPCYBER21™ Framework. With 35+ years in IT and cybersecurity, he helps organizations STOP the #CYBERinsanity and build real, layered protection that works.

About TechOnPurpose

At TechOnPurpose, we help organizations move from under-resourced and "stuck in the cybersecurity headlights" to fully supported and protected in hours or days—not weeks. Through comprehensive IT support and our TOPCYBER21™ framework, we assess cyber risk in 15 minutes and build defense-in-depth protection fast. As a veteran-owned MSSP and globally recognized Top 250 provider, we don't just support and secure—we elevate the role of trusted technology partner.

Chrome Zero Day Patch: Update Now

Chrome Zero Day Patch: Update Now

Chrome zero day patch #4 of 2026 covers two actively exploited vulnerabilities. CISA deadline: April 15. Your timeline should match.

View Next

Diagram showing how Texas cybersecurity law applies to every business, with two outcome paths — documented before a breach leads to safe harbor, documented after leads to full legal exposure

Texas Cybersecurity Law: What Every Business Must Know

⏱ 6 min readKey Takeaways Texas cybersecurity law already requires every business, regardless of size, to protect sensitive personal information and report breaches within 60 days of discovery. SB 2610 offers a safe harbor from punitive damages — but only if you can...
AI-Enabled Device Code Phishing — TechOnPurpose Identity & Access Management MFA Bypass Prevention

AI-Enabled Device Code Phishing Is Bypassing MFA — What Your Microsoft 365 Users Are Up Against

⏱ 4 min readKey Takeaways Device code phishing abuses a legitimate Microsoft OAuth flow — no passwords stolen, no MFA prompt triggered, full M365 access granted. AI-generated lures are now role-specific and hyper-personalized — standard phishing training won't catch...
Chrome Zero-Day Patch — TechOnPurpose TC21-05 Endpoint Patch Management Urgency

Chrome Zero Day Patch: Update Now

⏱ 4 min readKey Takeaways This chrome zero day patch isn’t routine maintenance — it covers two vulnerabilities already being weaponized. CVE-2026-5289 scored a 9.6 CVSS — a full sandbox escape. If exploited, an attacker owns the endpoint. CISA added CVE-2026-5281 to...
Russian CTRL Toolkit remote desktop hijacking — TechOnPurpose TC21-15 secure remote access defense

Russian Malware CTRL: Remote Desktop Hijacking Undetected

⏱ 4 min readKey Takeaways Newly disclosed Russian remote access toolkit called CTRL is enabling remote desktop hijacking attacks that bypass all known threat intelligence platforms — including VirusTotal CTRL is a newly disclosed Russian-origin remote access toolkit...
Old vulnerabilities cyber risk — TechOnPurpose patch management defense-in-depth

#CYBERinsanity: The Vulnerabilities Attacking You Today Were Published a Decade Ago

⏱ 5 min readKey Takeaways 32% of the most active exploits are old vulnerabilities, more than ten years old — patches exist, they're just not being applied. Attackers start with the low-hanging fruit: automated scans for known, unpatched flaws before deploying anything...
Defense in depth strategy — TechOnPurpose TOPCYBER21 cybersecurity framework protects your organization from vulnerability exploits

Why Patching Alone Won’t Stop 40% of Cyberattacks

⏱ 4 min readKey Takeaways A defense in depth strategy is no longer optional — it's the only architecture that holds when patching alone fails. Nearly 40% of all intrusions in Q4 2025 were caused by exploited vulnerabilities — not phishing, not credential theft. Some...
2026 National Cyber Strategy Blog Post image

2026 National Cybersecurity Strategy: What It Means for You

⏱ 5 min readKey Takeaways The White House's 2026 national cybersecurity strategy introduces six strategic pillars — the clearest federal signal yet that passive cyber defense is no longer acceptable. All six pillars align directly to the TOPCYBER21™ framework — if...
TechOnPurpose achieves MSSP Alert's prestigious 2025 Top 250 Managed Security Service Providers (MSSPs) list, ranking #159 globally—a significant jump of 32 positions from last year's #191.

TechOnPurpose Named to MSSP Alert’s 2025 List of Top 250 MSSPs – Climbs 32 Spots Year-Over-Year

TechOnPurpose is proud to announce its inclusion in MSSP Alert's prestigious 2025 Top 250 Managed Security Service Providers (MSSPs) list, ranking #159 globally - a significant jump of 32 positions from last year's #191. This marks the second consecutive year...
#STOPtheCYBERinsanity image - Is Pen Testing a Dollars-Before-Defense Mistake

#CYBERinsanity: When Pen Testing Becomes a Dollars-Before-Defense Mistake

The Fallacy of Pen Testing as a Priority in Cybersecurity If you’ve been following our STOP the #CYBERinsanity series, you already know this uncomfortable truth: Most cybersecurity failures aren’t caused by brilliant hackers or exotic zero-day exploits. They’re caused...
#STOPtheCYBERinsanity "NOT Assessing Cyber Risk Early and Often" image

#CYBERinsanity – Habit 7: NOT Assessing Cyber Risk Early & Often

Still think you’ll “deal with cyber risk later?" Hackers are counting on it. Most organizations don’t get breached because they’re irresponsible. They get breached because they delay. Constantly delaying and pushing: “After the next quarter…” “When the new IT hire is...
en_US