The European Union Agency for Cybersecurity said this week it is taking on a larger administrative role in the CVE Program — not by producing more vulnerability disclosures itself, but by absorbing more of the numbering authorities that do.
ENISA, the agency charged with handling the EU’s cybersecurity efforts, announced Aug. 6, 2026 that two new organizations, NATO’s Communications and Information Agency (NCIA) and AI security firm AISLE, have joined the CVE Program as CVE Numbering Authorities (CNAs) under the ENISA Root.
Eight existing CNAs have also transferred from the MITRE Root to the ENISA Root, bringing the total number of CNAs under ENISA to 20. The announcement came at the 2026 Black Hat conference in Las Vegas, where ENISA joined CISA this week for a joint session on the evolution of the CVE Program.
“Recent developments in the global cybersecurity landscape, coupled with the emergence of Frontier AI models and their impact on vulnerability discovery and exploitation, have underscored the need to build strong vulnerability management infrastructure and capabilities,” said Hans de Vries, chief cybersecurity and operations officer for ENISA.
De Vries said the expanded CVE role lets the agency offer more operational support to Europe and the broader vulnerability management community. It pushes the vulnerability identification ecosystem toward being more globally representative, resilient, and scalable, he said.
A CNA is authorized to assign CVE identifiers and publish CVE records for vulnerabilities within its scope — an administrative role, not a research one. So while ENISA’s remit is growing, the change reflects who manages disclosure coordination in Europe more than it signals a coming spike in reported vulnerabilities.
The CNA growth has already strained the back end of the CVE pipeline once. In April NIST was narrowing how much enrichment – severity scoring, affected-product data – it adds to CVE records in the National Vulnerability Database, after submissions rose 263% between 2020 and 2025.
Part of that surge traced directly to CNA growth: NIST’s own CNA count went from 23 in 2016 to 502 by March 2026. NIST is now prioritizing enrichment for flaws in CISA’s Known Exploited Vulnerabilities catalog, federal software, and “critical software” under Executive Order 14028, leaving many other CVEs labeled “Not Scheduled” for deeper analysis. ENISA’s move to 20 CNAs under its own Root doesn’t feed directly into NIST’s backlog, but it’s the same underlying dynamic of more CNAs issuing more records that is playing out on a different root.
ENISA has held CNA status itself since January 2024, and became a full CVE Root — able to recruit, train, and oversee its own network of CNAs — in November 2025. “This role is carried out in close coordination with CISA and MITRE,” the agency said, describing that Root designation, “as part of a shared commitment to strengthen the resilience, quality, and long-term sustainability of the global CVE Program.”
ENISA’s steady buildout comes against a backdrop the CVE Program itself has openly wrestled with.
In April 2025, MITRE (the nonprofit that has operated CVE under U.S. government contract since 1999) notified the CVE Board that its federal funding was set to lapse, raising the prospect of a shutdown of the system underpinning vulnerability disclosure worldwide. CISA extended the contract before the lapse took effect, but the scare prompted CVE board members to establish the independent CVE Foundation days later, explicitly to move the program off a “single funding stream” model. CISA’s Matt Hartman said at the time the agency remained “very open to reevaluating the strategy to support the continued efficacy and value of the program”.
ENISA’s Root status, granted that November, and this week’s further expansion both fit into that same push toward a less U.S.-centralized CVE ecosystem, even though neither move was a direct response to the 2025 funding episode.
The expansion also lands ahead of a concrete compliance deadline on ENISA’s own turf. Under the EU’s Cyber Resilience Act, manufacturers will be required to report actively exploited vulnerabilities through ENISA’s forthcoming Single Reporting Platform starting in September 2026. A larger CNA network under ENISA’s own Root gives the agency more direct oversight over vulnerability handling in Europe just as that mandatory reporting obligation takes effect.