The European Union Agency for Cybersecurity (ENISA) has expanded its role in the global Common Vulnerabilities and Exposures (CVE) Program by onboarding the NATO Communications and Information Agency (NCIA) and AI and cybersecurity innovator AISLE as new CVE Numbering Authorities (CNAs) under the ENISA Root. The move, announced on 6 August 2026, brings the total number of CNAs under ENISA's Root to 20, including eight that have been transferred from the MITRE Root to the ENISA Root. ENISA retains its competence in the EU under the MITRE Root, and the expansion is part of its broader effort to strengthen vulnerability management infrastructure and capabilities across Europe and internationally.

ENISA Chief Cybersecurity and Operations Officer Hans de Vries said that recent developments in the global cybersecurity landscape, coupled with the emergence of Frontier AI models and their impact on vulnerability discovery and exploitation, have underscored the need for robust vulnerability management. "Through its role in the CVE Program, ENISA reinforces its operational support to the European and wider vulnerability management community and actively contributes to a more globally representative, resilient, and scalable vulnerability identification ecosystem," he said. The addition of new CNAs from multiple sectors—including CSIRTs, vendors, suppliers, international alliances, and security research organisations—supports the CVE Program's objectives of expanding global participation, broadening diversity, improving quality, and increasing operational capacity.

This expansion follows ENISA's designation as a CVE Root for European entities in November 2025, when it became the central point of contact within the CVE Program for EU Member States, EU authorities, EU CSIRTs Network members, and cooperative partners under its mandate. That role is carried out in close coordination with CISA and MITRE, as part of a shared commitment to strengthen the resilience, quality, and long-term sustainability of the global CVE Program. As a CVE Root, ENISA recruits, onboards, trains, supports, and manages CNAs within its scope, facilitating their transition where relevant, and ensuring the effective assignment of CVE Identifiers (CVE IDs) and publication of CVE Records.

On the same day, ENISA's Head of Sector for Incident and Vulnerability Services, Nuno Rodrigues Carvalho, is scheduled to discuss the global evolution of the CVE Program at the Black Hat conference, alongside Lindsey Cerkovnik, Branch Chief for Vulnerability Response and Coordination at the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The discussion will cover the program's priorities and joint initiatives aimed at enhancing its impact on global cybersecurity.

The expansion is expected to have a moderate positive impact on EU cybersecurity stakeholders. For EU national authorities and CSIRTs, the increased number of CNAs under the ENISA Root means faster and more coordinated vulnerability identification and disclosure, improving their ability to respond to threats. For vendors and suppliers in the EU, the broader CNA network may reduce the administrative burden of coordinating with multiple numbering authorities, as ENISA provides a single point of contact. However, the transition of CNAs from the MITRE Root to the ENISA Root could introduce short-term operational adjustments for those organisations, as they adapt to new processes and reporting lines. For the wider cybersecurity community, the expansion enhances the diversity and resilience of the CVE Program, but it also places additional responsibility on ENISA to manage a growing number of CNAs effectively, which could strain its resources if not adequately funded.

← Atlas › News › Digital & Communication