ENISA Expands European Influence Over Global Vulnerability Tracking
ENISA announced that NATO's Communications and Information Agency (NCIA) and AI security firm AISLE have joined as CVE Numbering Authorities under the ENISA Root — bringing the agency's total to 20…

ENISA announced that NATO's Communications and Information Agency (NCIA) and AI security firm AISLE have joined as CVE Numbering Authorities under the ENISA Root — bringing the agency's total to 20 CNAs, eight of which migrated directly from the MITRE Root. The move tightens Europe's grip on the vulnerability cataloging pipeline that underpins patch management across governments, vendors, and defenders worldwide.
The consolidation play
ENISA assumed its CVE Root role in November 2025, establishing itself as the central European contact point within the CVE ecosystem. The mandate: recruit, onboard, train, and manage CNAs across EU member states, their CSIRT networks, and affiliated partners. The agency operates in close coordination with both MITRE and CISA.
Adding NCIA and AISLE isn't a bureaucratic headcount exercise. It's a deliberate diversification push — pulling international defense alliances and AI-focused security research into a vulnerability identification system that has historically leaned heavily on U.S.-centric structures. Eight CNAs transferred from MITRE's Root to ENISA's. That's a meaningful operational shift in who controls identifier assignment on this side of the Atlantic.
The AI justification
Hans de Vries, ENISA's Chief Cybersecurity and Operations Officer, pointed to "the emergence of Frontier AI models and their impact on vulnerability discovery and exploitation" as a driver for stronger infrastructure. The subtext reads plainly: AI is now both a tool for finding bugs and a surface for introducing them, and the vulnerability management apparatus needs to scale to match.
AISLE's inclusion as a CNA — an AI and cybersecurity firm granted direct authority to assign CVE identifiers — underscores the point. More AI-specialized entities entering this pipeline looks inevitable. Whether that improves cataloging quality or introduces coordination friction is an open question worth monitoring.
Operational implications for practitioners
A session at Black Hat this week features ENISA's Nuno Rodrigues Carvalho alongside CISA's Lindsey Cerkovnik, discussing the CVE Program's global evolution and joint initiatives. For anyone managing vulnerability response workflows, the practical signal is this: the European side of CVE is consolidating authority and expanding its intake pipeline. CNAs are migrating from MITRE's root to ENISA's. Disclosure timelines, identifier assignment, and coordination paths are shifting accordingly.
The global CVE backbone is being restructured in real time. Security teams that haven't updated their intake processes to account for a dual-root architecture risk slower response cycles — and in this business, lag compounds fast.