= Paid content
2 min read

ENISA expands role in CVE Program with 20 CNAs

The European Union Agency for Cybersecurity (ENISA) now oversees 20 CVE Numbering Authorities (CNAs), including NATO’s NCIA and AI cybersecurity specialist AISLE, following its expanded role in the Common Vulnerabilities and Exposures (CVE) Program. The move aims to strengthen Europe’s vulnerability management infrastructure and coordination, reducing reliance on non-European systems while ensuring consistent practices across the cybersecurity community. (EENEWS EUROPE)

ENISA expands its role in the CVE Program
The European Union Agency for Cybersecurity (ENISA) is expanding its role in the Common Vulnerabilities and Exposures (CVE) Program, adding the NATO Communications and Information Agency (NCIA) and AI cybersecurity specialist AISLE as CVE Numbering Authorities (CNAs). ENISA now oversees 20 CNAs, including eight transferred from the MITRE Root. For eeNews Europe readers, the move could improve how vulnerabilities affecting European electronics, software and infrastructure are identified and communicated. A broader CNA network should also help vendors and security teams coordinate responses using consistent CVE records. Building Europe’s CNA network CNAs are responsible for assigning CVE identifiers and publishing records for publicly disclosed cybersecurity vulnerabilities. ENISA said its growing role will support more timely identification, consistent practices and trusted coordination across the European and international cybersecurity community. “Recent developments in the global cybersecurity landscape, coupled with the emergence of Frontier AI models and their impact on vulnerability discovery and exploitation, have underscored the need to build strong vulnerability management infrastructure and capabilities. Through its role in the CVE Program, ENISA reinforces its operational support to the European and wider vulnerability management community and actively contributes to a more globally representative, resilient, and scalable vulnerability identification ecosystem,” said ENISA Chief Cybersecurity and Operations Officer Hans de Vries. The new CNAs span multiple sectors, including computer security incident response teams, technology vendors, suppliers, international alliances and security research organizations. Their addition is intended to broaden participation in the CVE Program, improve the quality of vulnerability records and increase operational capacity. European CVE coordination ENISA became a CVE Root for European entities in November 2025. It serves as the central CVE Program contact for EU member states, EU authorities, members of the EU CSIRTs Network and other partners covered by the agency’s mandate. Working with the US Cybersecurity and Infrastructure Security Agency (CISA) and MITRE, ENISA recruits, trains, supports and manages CNAs within its scope. It also oversees the assignment of CVE IDs, publication of CVE records and compliance with the program’s rules and processes. NCIA and AISLE join the network under this structure, strengthening Europe’s representation in the global system used by governments, vendors, researchers and cybersecurity defenders. CVE Program takes the stage ENISA will also discuss the evolution of the CVE Program at Black Hat this week. Nuno Rodrigues Carvalho, ENISA’s head of sector for incident and vulnerability services, will appear with Lindsey Cerkovnik, CISA’s branch chief for vulnerability response and coordination. The session will cover the program’s priorities and joint initiatives designed to increase its global cybersecurity impact. The CVE Program maintains one standardized record for each cataloged vulnerability, helping security professionals identify, prioritize and address the same issue across organizations. The post ENISA expands its role in the CVE Program appeared first on eeNews Europe.
Subscribe to our newsletter

Subscribe to our newsletter to get the latest updates and news

Member discussion