ENISA brings its CVE Root network to 20 CNAs with the addition of NATO's NCIA and AI firm AISLE
ENISA has expanded its CVE Root network to 20 CNAs, adding NATO's NCIA and AI cybersecurity firm AISLE - a milestone in Europe's push to diversify global vulnerability management.
ENISA now oversees 20 CVE Numbering Authorities (CNAs), including eight transferred from the MITRE Root, after adding the NATO Communications and Information Agency (NCIA) and AI cybersecurity specialist AISLE to its network on 6 August 2026.[1] The move is the most visible sign yet of how quickly Europe's stake in the global vulnerability identification system has grown since ENISA first became a CNA in January 2024.[1]
From single CNA to Root in under two years
ENISA became a CVE Root for European entities in November 2025, elevating it from an authority that assigns CVE identifiers to one that recruits, trains, and supervises other CNAs.[1] The Root designation is qualitatively different from ordinary CNA membership: a Root does not merely assign CVE IDs - it onboards subordinate organizations, ensures consistent assignment quality, and maintains accountability up the hierarchy.
Working alongside CISA and MITRE, ENISA now serves as the central CVE Program contact for:[1]
- EU member states and EU authorities
- Members of the EU CSIRTs Network
- Cooperative partners covered by the agency's mandate
- International alliances such as NCIA
The new CNAs span multiple sectors - computer security incident response teams, technology vendors, suppliers, international alliances, and security research organizations.[1] Their addition is intended to broaden participation, improve the quality of vulnerability records, and increase operational capacity.[1]
AI and the urgency behind the expansion
ENISA Chief Cybersecurity and Operations Officer Hans de Vries pointed directly to frontier AI as a driver. The emergence of advanced AI models and their impact on vulnerability discovery and exploitation, he said, has underscored the need to build stronger vulnerability management infrastructure.[1] AISLE's inclusion as a CNA is a concrete expression of that concern: the firm focuses on AI-native cybersecurity and was cited in ENISA's own July 2026 report on cybersecurity in the frontier AI era.
The urgency also has a structural dimension. In April 2025, MITRE warned that its Department of Homeland Security contract to operate the CVE program was set to expire with no renewal in place, briefly threatening a shutdown of the 25-year-old system.[1] CISA issued an emergency extension, but the episode accelerated calls for a more geographically distributed governance model - exactly the direction ENISA's Root status represents.
Black Hat and the road to TL-Root
ENISA is using Black Hat 2026 to signal its ambitions publicly. Nuno Rodrigues Carvalho, ENISA's head of sector for incident and vulnerability services, appeared at the conference alongside CISA's Lindsey Cerkovnik, branch chief for vulnerability response and coordination, to discuss the program's priorities and joint transatlantic initiatives.[1]
The longer-term goal is a Top-Level Root (TL-Root) designation, which would place ENISA alongside CISA and MITRE as a global policy-setter for the entire CVE program - a status that would also give Europe its first seat on the CVE Program Board. ENISA officials have said they hope to achieve TL-Root status in 2026 or early 2027.
The pace at which ENISA's CNA roster grows from 20, and whether the Cyber Resilience Act's mandatory vulnerability reporting deadline of September 2026 accelerates further transfers from the MITRE Root, will be the clearest indicators of how fast European vulnerability governance is consolidating.

Written by Electronics Insider's automated desk from the sources above and published automatically. How we work.
Related
Design & EDAiQ Sense describes a battery-less, RFID-scale photonic implant for continuous biochemical monitoring in animals
iQ Sense CEO Brendan Emery explains how a photonic integrated circuit, wireless power, and on-device AI are co-packaged into a battery-less implant for real-time biomarker monitoring in animals.
11 Aug 2026
Design & EDASemiWiki publishes CEO interview with David Reeder, who took the helm at Entegris in August 2025
SemiWiki's CEO interview with Entegris president David Reeder covers his background, strategic priorities, and how AI-driven node transitions are reshaping demand for advanced semiconductor materials.
11 Aug 2026
SemiconductorsEuropean Commission and SpaceRISE sign IRIS² implementation agreement, expanding constellation to 348 satellites
On 7 August 2026, the EU and SpaceRISE signed the IRIS² implementation agreement, adding 66 satellites to reach 348 spacecraft and boosting secure governmental capacity by 60%.
11 Aug 2026