A federal audit revealed that NIST lacked a strategic plan for managing the National Vulnerability Database and wasted approximately $200,000 on duplicate enrichment work performed simultaneously by NIST and CISA through the same contractor. The agency missed its September 2024 deadline to clear the backlog, which grew from 13,000 to over 27,000 vulnerabilities by the end of 2025, while also failing to promptly integrate CISA’s enrichment data into its systems.