Edgewatch has become a GCVE Numbering Authority, assigned GNA 129, joining the community behind the Global CVE Allocation System. Our entry is now listed in the GCVE directory https://gcve.eu/gna/129/
For us, this is a meaningful step in contributing to the infrastructure that cybersecurity teams depend on the ability to identify vulnerabilities, share information about them, and coordinate a response.
Europe can strengthen its capacity to produce and exchange security intelligence while remaining connected to the global cybersecurity community. A vulnerability identifier gives researchers, software vendors, security teams, and customers a common reference for discussing a security issue. That shared reference helps connect discovery with advisories, affected products, and remediation.
GCVE provides an open, decentralised approach to this process. Participating authorities receive their own namespace and can allocate identifiers without requesting blocks from a central allocation authority. As GNA, Edgewatch can assign identifiers within its GCVE namespace according to its scope and disclosure policies. The initiative is operated by Luxembourg’s Computer Incident Response Center, CIRCL, and developed openly with the wider security community.
Sovereignty includes the ability to operate essential security processes, contribute original intelligence, and sustain those capabilities over time.
Our view is that European organisations should help build and maintain the systems they rely on to defend themselves. Participation in GCVE creates an opportunity to exercise that responsibility through practical technical work.
GCVE allows independent authorities to publish vulnerability information from their own infrastructure, reducing dependence on a single publication database or workflow. It also preserves connections with the existing CVE ecosystem through identifier mapping and explicit cross-references.
That combination matters for European businesses, public services, and technology providers operating across international supply chains. Greater autonomy is most useful when information can still travel across borders and between tools. Open formats and clear attribution can support that exchange while helping consumers understand where a record originated.
For defenders, the practical value lies in making vulnerability information easier to connect to action. Consider a security team investigating an exposed service: it needs to establish which issue affects it, locate reliable guidance, and coordinate remediation with the relevant supplier. Clear identifiers and attributable records provide a foundation for that work.
This role fits naturally with Edgewatch’s work. Our platform helps organisations understand their external attack surface and identify weaknesses in their public-facing digital presence. Our technologies are developed and maintained in Europe, and accessible cybersecurity is a core part of our mission.
Participation in GCVE extends that mission into the wider vulnerability ecosystem. It gives us a way to contribute as a producer of security information, alongside our work helping organisations understand their exposure.
For smaller businesses in particular, the quality of shared security infrastructure matters. Many rely on vendors, service providers, and public advisories to interpret vulnerabilities and decide what needs attention. Strengthening that common foundation can benefit organisations far beyond the original discoverer or publisher.
We believe Europe’s cybersecurity capacity grows through contributions like these: operating infrastructure, publishing useful information, and participating in open technical communities. Becoming GNA is Edgewatch’s next step in that work, bringing our European roots and focus on practical security into a global effort to make vulnerability information more resilient, accessible, and useful.
If you have a vulnerability to report, start with Edgewatch’s disclosure procedure at https://edgewatch.com/legal/disclosure/
