---
schema: 1
kind: research
title: "ENISA expands CVE Root: four new European organisations onboarded as CVE Numbering Authorities"
headline: "ENISA expands CVE Root: four new European organisations onboarded as CVE Numbering Authorities"
summary: "On 2026-05-06 ENISA announced four additional organisations joined the CVE Program as CVE Numbering Authorities (CNAs) under ENISA Root, bringing the total under ENISA oversight to at least eleven (ENISA press release, 2026-05-06)."
discovered_at: "2026-05-09T05:00:09Z"
event_date: 2026-05-06
run_id: 2026-05-09-migrated
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - eu-nexus
regions:
  - europe
sectors: []
entities:
  - "campaign:eu-cyber-resilience-act"
cves: []
sources:
  - url: "https://www.enisa.europa.eu/news/new-cve-numbering-authorities-under-enisa-root"
    publisher: "ENISA press release — New CVE Numbering Authorities under ENISA Root, 2026-05-06"
    role: primary
closed_sources: []
evidence: []
verification: single-source-national-cert
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-05-09.md
---

On 2026-05-06 ENISA announced four additional organisations joined the CVE Program as CVE Numbering Authorities (CNAs) under ENISA Root, bringing the total under ENISA oversight to at least eleven ([ENISA press release, 2026-05-06](https://www.enisa.europa.eu/news/new-cve-numbering-authorities-under-enisa-root)). The names of the four new CNAs were not disclosed in the press release; more are expected. Over 90 European CNAs are eligible to voluntarily transfer from MITRE Root. This is part of the EU Cyber Resilience Act (CRA) implementation framework: the CRA designates ENISA as the EU-level coordination body for harmonised vulnerability reporting, and the CVE Root transfer is the operational mechanism. For defenders: an increasing proportion of EU-discovered CVEs will be assigned and initially coordinated through ENISA-supervised channels, which may affect advisory publication timing and format compared to MITRE Root coordination — particularly for products made by EU software vendors.
