The European Cybersecurity Agency, ENISA, has recently welcomed four new organisations into the Common Vulnerabilities and Exposures (CVE™) Program as CVE Numbering Authorities (CNAs) under its Root. This development marks a significant milestone in European cybersecurity, strengthening the region's operational contribution to the global CVE Program and enhancing the reliability, timeliness, and coordination of vulnerability handling across the EU. As CVE Root, ENISA supports the transition of existing European CNAs and plays a crucial role in the shared global responsibility for vulnerability management.
Hans de Vries, Chief Cybersecurity and Operations Officer, emphasised the importance of this onboarding process, stating that it strengthens Europe's operational contribution to the global CVE Program. He also highlighted the need for Europe's vulnerability management capacity to keep pace with the rapid advancements in frontier AI models, which are accelerating vulnerability discovery and exploitation. By expanding the capacity and operational maturity of EU vulnerability services, ENISA aims to address the challenges posed by these AI models and ensure the long-term sustainability of the CVE Program.
The CVE Program, with its mission to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities, relies on the efforts of CNAs worldwide. ENISA's role as CVE Root for European entities, established in November 2025, further strengthens the Agency's support to the CSIRTs Network and its broader community of partners. This role is carried out in close coordination with CISA and MITRE, reflecting a shared commitment to strengthening the resilience, quality, and long-term sustainability of the global CVE Program. ENISA's objective is to reinforce the shared global vulnerability identifier backbone, ensuring that governments, vendors, researchers, and defenders have a reliable and consistent system for identifying and addressing vulnerabilities.
The number of CNAs under ENISA is growing rapidly, with several additional organisations requesting to be onboarded in the coming weeks. ENISA works closely with these candidates during the transition and onboarding process, ensuring operational readiness, clarity of scope, and alignment with the CVE Program requirements and rules. This process is vital for maintaining the integrity and effectiveness of the CVE Program, as ENISA manages the recruitment, onboarding, training, and support of CNAs within its scope, facilitating their transition and ensuring the effective assignment of CVE Identifiers (CVE IDs) and publication of CVE Records. With over 90 CNAs in Europe voluntarily transferring under ENISA Root, the agency plays a significant role in supporting the European cybersecurity ecosystem, which already represents nearly one-fifth of all CNAs worldwide.