NVD Enrichment Distribution Calculator
51,000
GAP CVES / YEAR
$0.20 – $1.20
$ / CVE (P50 – P95 COMPUTE)
$10K – $60K
ANNUAL COMPUTE (P50 – P95)
~6,800
REVIEWER-HOURS / YEAR (P50)

Pre-pilot model. All values shown are estimates that the Phase 0 calibration pilot is designed to test. The calculator presents p50 / p80 / p95 distributions rather than single averages, because pre-pilot estimates do not justify single-number precision. The Pilot Mode toggle reflects pilot-scale variance and lower cache hit rates; the Steady-State Mode toggle reflects a mature pipeline. After the pilot concludes, this calculator will incorporate the measured distributions as a calibrated preset.

Distributional cost outcomes

Per-CVE compute cost

Distribution across the gap CVE population under current parameters and the selected mode.
$0.00$2.50
P50
$0.20
expected median
P80
$0.50
moderately adverse
P95
$1.20
planning bound

Annual compute spend

Per-CVE distribution scaled to annual gap CVE volume.
P50
$10,000
expected median
P80
$25,000
moderately adverse
P95
$60,000
planning bound
Pilot run cost (configurable sample)
$200 – $1,200
Compute-only. Add expert reviewer compensation separately for pilot total.

Cost driver decomposition (p50)

Share of expected compute cost attributable to base inference, retrieval, and validation/critique passes.
Base inference
Retrieval
Validation

Tier contribution (p50)

Share of expected annual compute cost attributable to each tier.
Simple
Moderate
Complex

Reviewer time distribution

Per-CVE human review minutes under current rubber-stamp / consensus split.
P50
7 min
typical record
P80
12 min
harder record
P95
20 min
consensus-tail
Annual reviewer-hours (p50)
~6,800
Volunteers at 2 hr/wk: ~68.

Compute vs human cost (p50)

Share of total p50 cost attributable to AI compute vs compensated review at the configured reviewer rate.
Compute
Reviewer
All-in p50 annual cost
$10,000
Compute + reviewer compensation at the rate set below.

Sensitivity / stress test

Multiplier scales p50 token usage, retrieval frequency, and reviewer minutes simultaneously. Tests program robustness against parameter excursions. The economic feasibility test is whether the 10× p50 figure remains within non-profit-feasible bounds.
StressPer-CVE (p50)Annual compute (p50)Reviewer-hours (p50)All-in annual (p50)
1× (baseline)
10×

Volume and scope

Annual CVE submissions
60,000
NIST priority coverage
15%
KEV, federal, EO 14028 critical software handled by NIST and excluded from gap.
Pilot sample size
1,000
Records processed during Phase 0 calibration.
Validation multiplier
1.4×
Overhead from self-critique and output formatting passes.
Cache hit rate
90%
Pilot mode default: 70%. Steady-state default: 90%.
Reviewer rate ($/hr)
$0
$0 = volunteer model. Set to compensated rate to see all-in annual cost.

Per-tier token distributions, retrieval, and model selection

Simple tier
%
Fresh input tokens (distribution)
Cached / output tokens
Per-retrieval tokens
Model
$ / M (in / cache / out)
Moderate tier
%
Fresh input tokens (distribution)
Cached / output tokens
Per-retrieval tokens
Model
$ / M (in / cache / out)
Complex tier
%
Fresh input tokens (distribution)
Cached / output tokens
Per-retrieval tokens
Model
$ / M (in / cache / out)

Reviewer time per tier

Simple — minutes
Rubber-stamp (single reviewer)
Consensus (two reviewers, each)
Moderate — minutes
Rubber-stamp (single reviewer)
Consensus (two reviewers, each)
Complex — minutes
Rubber-stamp (single reviewer)
Consensus (two reviewers, each)