Geo-Specific
,
Governance & Risk Management
NCIA and AISLE Become CVE Numbering Authorities Under EU Agency’s Expanding Root
Chris Riotta (@chrisriotta) •
August 6, 2026

NATO’s technology agency and an artificial intelligence security firm joined the globally-adopted vulnerability tracking system under a growing branch run by the European Union’s cybersecurity agency.
See Also: Why Firms Need to Invest in Security as Response Strategy
The European Union Agency for Cybersecurity announced Wednesday that the NATO Communications and Information Agency and AI cybersecurity firm AISLE will serve as CVE Numbering Authorities under the ENISA Root, bringing the agency’s total to 20 CNAs – including eight transferred from the MITRE Root.
Hans de Vries, ENISA’s chief cybersecurity and operations officer, said emergence of frontier AI models “and their impact on vulnerability discovery and exploitation” has underscored the need for stronger vulnerability management infrastructure. ENISA is contributing “to a more globally representative, resilient and scalable vulnerability identification ecosystem.”
The agency said the new authorities span computer security incident response teams, vendors and suppliers, international alliances and security research organizations, all in support of the CVE Program’s goals of expanding global participation and increasing operational capacity.
ENISA became a CVE Root in November 2025, making it the central point of contact within the program for EU member states, EU authorities and members of the bloc’s CSIRTs Network. The agency said the role is carried out in close coordination with CISA and MITRE.
As a root, ENISA recruits, onboards, trains and manages the numbering authorities within its scope. It’s also tasked with overseeing the assignment of CVE identifiers and the publication of CVE records while ensuring program rules are followed.
The transatlantic expansion follows a near-collapse of the 25-year-old program, which serves as the global system for identifying and cataloging publicly disclosed software flaws (see: CISA Unveiled a New Vision for the CVE Program. Can It Work?).
Officials warned in April 2025 that federal funding for the program was set to lapse, triggering alarm across the cybersecurity community. CISA executed an option on its contract with the nonprofit hours before expiration, extending operations by 11 months. CSO reported earlier this year that CISA moved funding for the program into a protected budget line in a bid to prevent a repeat funding crisis (see: Cybersecurity Alarms Sound Over Loss of CVE Program Funding).
The episode spurred a group of CVE Board members to launch the CVE Foundation, which said the program should not depend on a single government contract and called for developing additional roots to federate the management of numbering authorities.
ENISA has steadily built out its share of the tracking system since taking on the root role, onboarding four organizations in May before Wednesday’s additions.
The agency also operates the separate European Vulnerability Database, a catalog that aggregates mitigation measures and exploitation status for flaws affecting IT products and services.