ENISA brings its CVE Root network to 20 CNAs with the addition of NATO's NCIA and AI firm AISLE
ENISA has expanded its CVE Root network to 20 CNAs, adding NATO's NCIA and AI cybersecurity firm AISLE - a milestone in Europe's push to diversify global vulnerability management.
ENISA now oversees 20 CVE Numbering Authorities (CNAs), including eight transferred from the MITRE Root, after adding the NATO Communications and Information Agency (NCIA) and AI cybersecurity specialist AISLE to its network on 6 August 2026.[1] The move is the most visible sign yet of how quickly Europe's stake in the global vulnerability identification system has grown since ENISA first became a CNA in January 2024.[1]
From single CNA to Root in under two years
ENISA became a CVE Root for European entities in November 2025, elevating it from an authority that assigns CVE identifiers to one that recruits, trains, and supervises other CNAs.[1] The Root designation is qualitatively different from ordinary CNA membership: a Root does not merely assign CVE IDs - it onboards subordinate organizations, ensures consistent assignment quality, and maintains accountability up the hierarchy.
Working alongside CISA and MITRE, ENISA now serves as the central CVE Program contact for:[1]
- EU member states and EU authorities
- Members of the EU CSIRTs Network
- Cooperative partners covered by the agency's mandate
- International alliances such as NCIA
The new CNAs span multiple sectors - computer security incident response teams, technology vendors, suppliers, international alliances, and security research organizations.[1] Their addition is intended to broaden participation, improve the quality of vulnerability records, and increase operational capacity.[1]
AI and the urgency behind the expansion
ENISA Chief Cybersecurity and Operations Officer Hans de Vries pointed directly to frontier AI as a driver. The emergence of advanced AI models and their impact on vulnerability discovery and exploitation, he said, has underscored the need to build stronger vulnerability management infrastructure.[1] AISLE's inclusion as a CNA is a concrete expression of that concern: the firm focuses on AI-native cybersecurity and was cited in ENISA's own July 2026 report on cybersecurity in the frontier AI era.
The urgency also has a structural dimension. In April 2025, MITRE warned that its Department of Homeland Security contract to operate the CVE program was set to expire with no renewal in place, briefly threatening a shutdown of the 25-year-old system.[1] CISA issued an emergency extension, but the episode accelerated calls for a more geographically distributed governance model - exactly the direction ENISA's Root status represents.
Black Hat and the road to TL-Root
ENISA is using Black Hat 2026 to signal its ambitions publicly. Nuno Rodrigues Carvalho, ENISA's head of sector for incident and vulnerability services, appeared at the conference alongside CISA's Lindsey Cerkovnik, branch chief for vulnerability response and coordination, to discuss the program's priorities and joint transatlantic initiatives.[1]
The longer-term goal is a Top-Level Root (TL-Root) designation, which would place ENISA alongside CISA and MITRE as a global policy-setter for the entire CVE program - a status that would also give Europe its first seat on the CVE Program Board. ENISA officials have said they hope to achieve TL-Root status in 2026 or early 2027.
The pace at which ENISA's CNA roster grows from 20, and whether the Cyber Resilience Act's mandatory vulnerability reporting deadline of September 2026 accelerates further transfers from the MITRE Root, will be the clearest indicators of how fast European vulnerability governance is consolidating.

Written by Electronics Insider's automated desk from the sources above and published automatically. How we work.
Related
Design & EDASignaloid founder Phillip Stanley-Marbell steps down from Cambridge chair to run probabilistic computing startup full-time
SemiWiki's CEO interview with Phillip Stanley-Marbell traces his path from Bell Labs and Apple to founding Signaloid, a Cambridge spinout whose C0-ASIC targets 1000× performance-per-watt gains.
22 Aug 2026TSMC's COUPE co-packaged optics platform enters production in the second half of 2026
TSMC's Compact Universal Photonic Engine moves from qualification to volume production in H2 2026, promising 2x power efficiency and 10x lower latency over pluggable optics.
22 Aug 2026
SemiconductorsSemiconductor Engineering frames energy efficiency as the defining constraint for AI computing through 2030
Data center electricity is set to nearly double to 945 TWh by 2030, making energy efficiency the central strategic challenge - and opportunity - for every company deploying AI at scale.
22 Aug 2026