The NATO Cyber Security Centre (NCSC), part of the NATO Communications and Information Agency (NCIA), has successfully onboarded as a Common Vulnerabilities and Exposures (CVE™) Numbering Authority (CNA) under the European Union Agency for Cybersecurity (ENISA) Root.
This milestone reflects NCIA's continued commitment to strengthening cyber resilience and contributing to international efforts that promote the responsible disclosure and management of cybersecurity vulnerabilities.
As a CVE Numbering Authority, the NATO Cyber Security Centre will be able to assign internationally recognised CVE identifiers (CVE IDs) to eligible vulnerabilities within the NATO enterprise. This will support more consistent vulnerability tracking and facilitate the timely exchange of information sharing with trusted partners across the global cybersecurity community.
By joining the network of organisations operating under the ENISA Root, NCIA further strengthens NATO's contribution in international cybersecurity cooperation. The designation supports a common approach for identifying, cataloguing, and communicating cybersecurity vulnerabilities, helping organisations and other users respond more effectively to emerging cyber threats.
Through its NATO Cyber Security Centre, NCIA plays a central role in protecting NATO's networks and information systems by delivering cyber defence capabilities, monitoring cyber threats and coordinating responses to cyber incidents affecting the Alliance. Becoming a CNA further enhances the Centre's ability to contribute to international vulnerability management efforts while supporting the security of NATO's digital infrastructure.
The CVE Program provides a common, standardised method for identifying, defining, and cataloguing publicly disclosed cybersecurity vulnerabilities. CVE identifiers enable governments, industry and security researchers worldwide to communicate consistently about vulnerabilities, helping organisations assess risk, prioritise remediation activities and strengthen their overall cyber resilience.