Независимо ръководство за Регламент (ЕС) 2024/2847 · Състояние: в сила
Тази страница е автоматичен превод (с ИИ) и не е прегледана от човек. Статиите в блога са достъпни само на английски език.
← All news
CRA Insights10 August 2026

On 6 August 2026, ENISA Announced Its CVE Root Now Covers 20 Numbering Authorities, Five Weeks Before CRA Reporting Starts

On 6 August 2026, ENISA Announced Its CVE Root Now Covers 20 Numbering Authorities, Five Weeks Before CRA Reporting Starts

On 6 август 2026 г., ENISA announced that the NATO Communications and Information Agency and the security firm AISLE had joined the CVE Numbering Authorities under the ENISA Root. The Agency put the running total at 20 CNAs, of which 12 were onboarded directly by ENISA and 8 transferred across from the MITRE Root. On its face this is administrative plumbing. It is worth a closer look anyway, because it concerns the identifiers that manufacturers will be asked for from 11 септември 2026 г., and because the relationship between a CVE record and a CRA notification is one of the things people most reliably get wrong.

What the ENISA Root actually is

A CNA is an organisation authorised to assign CVE IDs and publish CVE records for vulnerabilities in its own scope. Roots recruit, train and supervise those CNAs. ENISA became a CVE Root for European entities on 20 November 2025, acting as the central point of contact in the programme for EU Member State and EU authorities, members of the EU CSIRTs Network, and cooperative partners under its mandate, in coordination with CISA and MITRE.

So the 6 August news is a capacity story: more European organisations can now issue identifiers without routing through a US-based root.

Where this meets the Cyber Resilience Act

Two connections matter. First, the reporting form. ENISA's SRP data-field table lists CVE ID и EUVD ID as fields available from the 24-hour early warning onward, optional at that stage and carried forward afterwards. A manufacturer that already works with a CNA, or is one, will have an identifier to put in the box; one that does not may file without one, which is permitted.

Second, what happens after the fix. Under Article 17(5) of the CRA, once a security update or other corrective or mitigating measure is available, ENISA shall, in agreement with the manufacturer, add the publicly known vulnerability notified under Article 14(1) or 15(1) to the Европейската база данни за уязвимости established under Article 12(2) of NIS2. The reporting pipeline and the public identifier ecosystem are therefore designed to meet at the end, not at the beginning. Our ръководството за докладване walks through the sequence and the fields.

A CVE record is not a CRA notification

This is the practical lesson, and it cuts both ways.

  • Assigning or publishing a CVE ID does not discharge Article 14. The notification is a separate act, filed through the Single Reporting Platform to the CSIRT, определен като координатор for your main establishment and, in parallel, to ENISA. Being a CNA yourself changes nothing about that duty.
  • Equally, filing under Article 14 does not publish anything. Article 17(5) requires ENISA to act in agreement with the manufacturer, and only after a corrective measure exists.
  • Waiting for an identifier does not buy time. The 24-hour, 72 часа и 14-day windows run from the moment the manufacturer becomes aware, and nothing pauses them. What can move is onward dissemination: the receiving CSIRT may delay it on cybersecurity grounds under Commission Delegated Regulation (EU) 2026/881, adopted on 11 декември 2025 г.. Separately, flagging one of the conditions in член 16, параграф 2 in the 72-hour notification restricts what ENISA sees until the CSIRT releases the full text. That is a limit on content, not an extension of time.

What to do with the five weeks left

Decide now who assigns an identifier when a vulnerability in your product is exploited: you, a vendor CNA upstream, or a national CSIRT. Record the CVE and EUVD IDs in your internal ticket so they can be copied into the notification rather than hunted for at hour 23. And keep watching the databases, because for most manufacturers awareness will arrive from outside: our SBOM and vulnerability analyzer matches a bill of materials against the NVD and the EUVD, and the maturity assessment is a quick way to see whether the handling process behind it exists on paper or only in principle.

Status at publication, 10 August 2026

Тя единната платформа за докладване is все още не работи. ENISA has scheduled it to be operational by 11 септември 2026 г., with user and security testing beforehand; the public access URL has not been published and is to appear on ENISA's SRP page before go-live. The списъкът на националните CSIRTs, определени за координатори has still not been published. ENISA states that no reporting API will be provided at this stage, and that voluntary reporting will only be enabled after 11 September 2026. A webinar is foreseen two weeks before the platform enters service.

Published 10 August 2026 · CRA Insights. Part of the CRA insights blog on cyberresilienceact.eu.