Twenty CNAs, and how fast that number grew
On 6 August 2026 the EU Agency for Cybersecurity (ENISA) announced it has onboarded the NATO Communications and Information Agency (NCIA) and the AI-security firm AISLE as new CVE Numbering Authorities operating under the ENISA Root, taking the total to 20 CNAs: 12 onboarded directly by ENISA and 8 transferred across from the US-administered MITRE Root. Hans de Vries, ENISA's Chief Cybersecurity and Operations Officer, tied the expansion to how vulnerabilities are now found, saying that "recent developments in the global cybersecurity landscape, coupled with the emergence of Frontier AI models and their impact on vulnerability discovery and exploitation, have underscored the need to build strong vulnerability management infrastructure and capabilities."
The growth is recent and fast. As of ENISA's own count in early May 2026, the Root held 11 CNAs - 4 onboarded directly and 7 transferred from MITRE - against a pool of roughly 90 European CNAs still eligible to make the same voluntary switch. Three months on, the total has nearly doubled. ENISA itself became a CVE Root only in November 2025, meaning it has gone from zero to 20 member CNAs, including a defence-alliance agency and an AI-native security vendor, inside nine months.
What a Root actually does that a CNA does not
The distinction most coverage skates past is the one that matters for a European company weighing whether any of this touches its own compliance work. A CNA assigns CVE identifiers for vulnerabilities within its own defined scope - typically its own products - and publishes the resulting CVE records. A Root sits above a set of CNAs: it recruits, vets and trains them, oversees how they assign IDs and publish records, and answers for whether they follow CVE Program rules. ENISA's Root status, confirmed in November 2025, made it the central point of contact for that recruiting-and-oversight job across EU Member States, EU authorities, the EU CSIRTs Network and ENISA's cooperative partners.
ENISA is not the only Root, and this expansion does not create a rival vulnerability-numbering system. MITRE, CISA, Google, Red Hat and Japan's JPCERT/CC all run Roots of their own inside the same CVE Program, and a handful of EU bodies - Spain's INCIBE-CERT, Thales, CERT@VDE - held Root or senior CNA status before ENISA did. What is new is that an EU agency now runs one of those administrative branches at meaningful scale, rather than European CNAs defaulting to a US-run one because no EU alternative existed.
The scare this build-out answers
The timing is not incidental. In April 2025, the US Cybersecurity and Infrastructure Security Agency's 57.8 million dollar contract with MITRE - the funding that keeps the CVE Program's core operations running - was due to expire on 16 April. The security community learned only on 15 April that Washington was not planning to renew it. CISA exercised a contract option the night before the deadline, buying an 11-month extension on funding officials described as "incremental," and the immediate crisis passed. But for roughly 24 hours, the infrastructure nearly every vulnerability-management programme in the world quietly depends on was one missed signature from disruption.
By January 2026 CISA told the CVE board there would be no funding cliff in March and that a more durable funding arrangement was in place, so the acute danger, as of this writing, has passed. What has not changed is the structural fact the scare exposed: CVE numbering for the entire world ran through a single US federal contract, administered by a single agency, subject to a single country's budget politics. ENISA's Root, and the 20 CNAs now under it, is the concrete EU answer to that exposure - not a replacement for the US side of the program, which the EU still relies on and cooperates with, but a second administrative branch that can keep recruiting, training and overseeing CNAs in the EU's own scope regardless of what happens to any one contract in Washington.
What changes for a European company, in practice
For the overwhelming majority of EU and UK organisations - anyone who consumes CVE data to patch systems or feed a vulnerability-management tool - nothing changes. A CVE ID issued under the ENISA Root is the same kind of identifier, in the same global registry, as one issued under the MITRE Root; it is not a parallel or incompatible numbering scheme, and no integration work follows from this announcement.
What changes is narrower and more specific: any EU organisation, research team or vendor that wants CNA status - the right to assign its own CVE IDs to vulnerabilities in its own products rather than wait for a third party to process the request - can now be recruited, vetted and trained by ENISA rather than needing to go through a US-administered process. AISLE's own stated reason for seeking CNA status makes the practical benefit concrete: it can now number a vulnerability its AI tools find in its own product the same day, rather than queuing behind a third-party CNA. NCIA gets the equivalent for anything found inside the NATO enterprise. Any EU vendor doing serious in-house vulnerability research has the same option now, under EU oversight, that it did not have eighteen months ago.
Why ENISA is building this muscle now
This is not ENISA's only vulnerability-infrastructure deadline this year. From 11 September 2026, the EU Cyber Resilience Act requires manufacturers to report actively exploited vulnerabilities to ENISA within 24 hours, covering products already on the market, not just new ones. An agency that has spent the past nine months recruiting, training and overseeing 20 CNAs, and that had its own staff on stage with CISA's vulnerability-response leadership at Black Hat USA this year, is building exactly the operational muscle it will need to run that reporting channel credibly. The CNA expansion and the CRA deadline are separate obligations, but they are the same agency doing the same kind of work, on the same timeline, ahead of a legal deadline that will make it mandatory rather than optional.
Read next: 45,601 Flaws This Year. 171 Are Being Used. | Your Older Macs Needed Seven Tries to Get Patched



