for giggles, I just roughed it out. Bearing in mind that I had 40,000 hosts (yes really) and a database of every package + version on every single one of them to *start* with. (Those 'too hard to do right' SBOMs kids whine about these days.) I also read abnormally quickly.
At current CVE rates, I'd personally need to block off 50+ hours a month just to do triage assuming no more than *three* different operating systems all extremely standardized and actively managed.