NATO Communications and Information Agency (NCIA), along with AI and cybersecurity innovator AISLE, join the Common Vulnerabilities and Exposures (CVE) Numbering Authorities (CNAs), under the ENISA Root.
ENISA's role within the CVE™ Program spawns further with the strategic expansion in the global vulnerability management ecosystem and the transition of existing CNAs under the ENISA Root. ENISA retains competence in the EU under the MITRE Root, with 20 CNAs under ENISA Root, including 8 transferred from MITRE Root to the ENISA Root.
The Agency’s contribution to the Program has grown further, attesting to its commitment to acting as a driver and facilitator of vulnerability management at European and international level, through consistent practices, timely identification and trusted coordination among partners.
ENISA Chief Cybersecurity and Operations Officer, Hans de Vries, said: “Recent developments in the global cybersecurity landscape, coupled with the emergence of Frontier AI models and their impact on vulnerability discovery and exploitation, have underscored the need to build strong vulnerability management infrastructure and capabilities. Through its role in the CVE Program, ENISA reinforces its operational support to the European and wider vulnerability management community and actively contributes to a more globally representative, resilient, and scalable vulnerability identification ecosystem.”
The addition of new CNAs from across multiple sectors, including CSIRTs, vendors and suppliers, international alliances, and security research organisations, further supports the objectives of the CVE Program of expanding global participation, broadening diversity of participating organisations, improving quality, and increasing operational capacity.
Up next this week: Discussing the evolution of the CVE™ Program
Today, at Black Hat, ENISA’s Head of Sector for Incident and Vulnerability Services, Nuno Rodrigues Carvalho, alongside Lindsey Cerkovnik, Branch Chief for Vulnerability Response and Coordination at the U.S. Cybersecurity and Infrastructure Security Agency (CISA), will discuss the global evolution of the CVE Program, its priorities, and joint initiatives aimed at enhancing its impact on global cybersecurity.
ENISA in the CVE Program
In November 2025, ENISA became a CVE Root for European entities, serving as the central point of contact within the CVE Program for EU Member States’ and EU authorities alike, as well as for EU CSIRTs Network members, and cooperative partners under ENISA mandate. This role is carried out in close coordination with CISA and MITRE, as part of a shared commitment to strengthen the resilience, quality, and long-term sustainability of the global CVE Program.
Through its role as a CVE Root, ENISA recruits, onboards, trains, supports, and manages CNAs within its scope, facilitating their transition where relevant, and ensuring the effective assignment of CVE Identifiers (CVE IDs) and publication of CVE Records. This role also helps ensure that CVE Program rules, guidelines, and processes are followed.
By expanding the number and diversity of CNAs under its Root, ENISA is helping to reinforce the CVE Program as a shared global vulnerability identification backbone relied upon by governments, vendors, researchers, defenders, and the wider cybersecurity community.
About the CVE Program
The mission of the CVE™ Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. There is one CVE Record for each vulnerability in the catalog. The vulnerabilities are discovered then assigned and published by organizations from around the world that have partnered with the CVE Program. Partners publish CVE Records to communicate consistent descriptions of vulnerabilities. Information technology and cybersecurity professionals use CVE Records to ensure they are discussing the same issue, and to coordinate their efforts to prioritize and address the vulnerabilities.
- New CVE Numbering Authorities Under ENISA Root | ENISA
- Stepping up our role in Vulnerability Management: ENISA Becomes CVE Root | ENISA
- Consult the European Vulnerability Database to enhance your digital security! | ENISA
- Another step forward towards responsible vulnerability disclosure in Europe | ENISA
- Home | EUVD