What do NIST’s NVD CVE prioritization changes mean for contractors’ vulnerability disclosure and patch timelines? 2026
Apr 18, 2026What do NIST’s NVD CVE prioritization changes mean for contractors’ vulnerability disclosure and patch timelines? 2026
GSA requires contractors to align SLAs to NIST's April 2026 NVD prioritization; patch KEVs within 15 days and report updates within 72 hours or risk payment withholding and contract suspension.