Join the global CVE Program under the ENISA Root

Is your organisation involved in identifying, coordinating, or disclosing vulnerabilities?

Image
CVE: Common Vulnerabilities and Exposures

Becoming a CVE Numbering Authority (CNA) enables your organisation to assign CVE IDs and publish authoritative information about vulnerabilities within an agreed scope. This contributes directly to the global infrastructure that supports coordinated vulnerability disclosure and vulnerability management.

ENISA serves as a CVE Root for European entities, recruiting, onboarding, training, and supporting CNAs across Europe.

Why become a CNA?

  • Take ownership of vulnerabilities discovered in your products or identified by your team: Assign CVE IDs directly for vulnerabilities within your scope and publish authoritative vulnerability information at the source.
  • Make vulnerability information available faster: Reduce dependencies and delays by integrating CVE assignment directly into your vulnerability disclosure processes and vuln management workflow.
  • Support users and defenders: Help ensure vulnerabilities can be consistently identified and referenced across advisories, vulnerability databases, security tools, and remediation workflows.
  • Join a global community: Become part of the CVE Program community of vendors, CSIRTs, open-source projects, researchers, bug bounty programmes, and other vulnerability coordination organisations.
  • Strengthen Europe’s contribution to the CVE Program: Help expand European capacity and expertise while reinforcing CVE as the global identifier backbone for vulnerability information.

Who can become a CNA under the ENISA root?

The ENISA Root scope covers EU Member States and EU authorities, EU CSIRTs Network members, cooperative partners under ENISA’s mandate, and other CNAs that choose ENISA as their Root

Potential CNAs include CSIRTs, technology vendors, open-source projects and foundations, vulnerability research organisations, bug bounty programmes, and other organisations that coordinate or disclose vulnerabilities.

How to become a CNA?

1 — Check your scope

Confirm that your organisation falls within the ENISA Root scope and consider the types of vulnerabilities for which your organisation would be best positioned to assign CVE IDs.

2 — Submit the CVE Program Request Form

The form is available on the CVE Services website.

Select:

“Request information on the CVE Program.”

In your request, indicate that you are seeking to become a CNA under the ENISA Root and include:

  • a short description of your organisation; and 
  • your proposed CNA scope.

3 — Complete onboarding with ENISA

ENISA will coordinate the onboarding process with your organisation, including onboarding sessions and preparation to begin operating as a CNA.

Want to learn more?

For an overview of the CNA onboarding process visit How to Become a CNA.

Questions: Please contact the ENISA EU Vulnerability Services | CVE Program team at vuln@enisa.europa.eu.