On 6 August 2026, ENISA Announced Its CVE Root Now Covers 20 Numbering Authorities, Five Weeks Before CRA Reporting Starts
On 6. srpna 2026, ENISA announced that the NATO Communications and Information Agency and the security firm AISLE had joined the CVE Numbering Authorities under the ENISA Root. The Agency put the running total at 20 CNAs, of which 12 were onboarded directly by ENISA and 8 transferred across from the MITRE Root. On its face this is administrative plumbing. It is worth a closer look anyway, because it concerns the identifiers that manufacturers will be asked for from 11. září 2026, and because the relationship between a CVE record and a CRA notification is one of the things people most reliably get wrong.
What the ENISA Root actually is
A CNA is an organisation authorised to assign CVE IDs and publish CVE records for vulnerabilities in its own scope. Roots recruit, train and supervise those CNAs. ENISA became a CVE Root for European entities on 20 November 2025, acting as the central point of contact in the programme for EU Member State and EU authorities, members of the EU CSIRTs Network, and cooperative partners under its mandate, in coordination with CISA and MITRE.
So the 6 August news is a capacity story: more European organisations can now issue identifiers without routing through a US-based root.
Where this meets the Cyber Resilience Act
Two connections matter. First, the reporting form. ENISA's SRP data-field table lists CVE ID a EUVD ID as fields available from the 24-hour early warning onward, optional at that stage and carried forward afterwards. A manufacturer that already works with a CNA, or is one, will have an identifier to put in the box; one that does not may file without one, which is permitted.
Second, what happens after the fix. Under Article 17(5) of the CRA, once a security update or other corrective or mitigating measure is available, ENISA shall, in agreement with the manufacturer, add the publicly known vulnerability notified under Article 14(1) or 15(1) to the Evropské databáze zranitelností established under Article 12(2) of NIS2. The reporting pipeline and the public identifier ecosystem are therefore designed to meet at the end, not at the beginning. Our průvodce hlášením walks through the sequence and the fields.
A CVE record is not a CRA notification
This is the practical lesson, and it cuts both ways.
- Assigning or publishing a CVE ID does not discharge Article 14. The notification is a separate act, filed through the Single Reporting Platform to the CSIRT určený jako koordinátor for your main establishment and, in parallel, to ENISA. Being a CNA yourself changes nothing about that duty.
- Equally, filing under Article 14 does not publish anything. Article 17(5) requires ENISA to act in agreement with the manufacturer, and only after a corrective measure exists.
- Waiting for an identifier does not buy time. The 24-hour, 72 hodin a 14-day windows run from the moment the manufacturer becomes aware, and nothing pauses them. What can move is onward dissemination: the receiving CSIRT may delay it on cybersecurity grounds under Commission Delegated Regulation (EU) 2026/881, adopted on 11. prosince 2025. Separately, flagging one of the conditions in čl. 16 odst. 2 in the 72-hour notification restricts what ENISA sees until the CSIRT releases the full text. That is a limit on content, not an extension of time.
What to do with the five weeks left
Decide now who assigns an identifier when a vulnerability in your product is exploited: you, a vendor CNA upstream, or a national CSIRT. Record the CVE and EUVD IDs in your internal ticket so they can be copied into the notification rather than hunted for at hour 23. And keep watching the databases, because for most manufacturers awareness will arrive from outside: our SBOM and vulnerability analyzer matches a bill of materials against the NVD and the EUVD, and the maturity assessment is a quick way to see whether the handling process behind it exists on paper or only in principle.
K jednotná platforma pro hlášení is dosud není v provozu. ENISA has scheduled it to be operational by 11. září 2026, with user and security testing beforehand; the public access URL has not been published and is to appear on ENISA's SRP page before go-live. The seznam národních CSIRTs určených jako koordinátoři has still not been published. ENISA states that no reporting API will be provided at this stage, and that voluntary reporting will only be enabled after 11 September 2026. A webinar is foreseen two weeks before the platform enters service.
