Developer docs
API playgroundTry for free, no card

Search company profiles

The Computer Incident Response Center Luxembourg

Full company profile

uuid002ce6p

Namestring
The Computer Incident Response Center Luxembourg
Legal namestring
CIRCL Computer Incident Response Center Luxembourg
Websiteurl
circl.lu
Company typeenum
Private
Founded yearint
2008
Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
11–50
akta.pro rankint
HeadquartersLuxembourg, Luxembourg
HQ citystring
Luxembourg
HQ countrystring
Luxembourg
HQ regionstring
Europe
Markets served

Serves global market

Offices1 record

Each record includes

City, Country, Type, Description, Source

Keyword5 values
computer incident response, threat intelligence sharing, vulnerability coordination, malware analysis services, CERT operations
Industry1 code
1Critical Infrastructure Protection (CIP) & NERC-CIP Compliance
CodeHDADAJACPrimaryYes
SIC code1 code
  • Communications Services, Nec4899
Product category
Cybersecurity Incident Response Services
Social media profiles2 records
GTM motion1 record

Each record includes

Type, Description, Source

Revenue model1 record
1Government Funding
TypeManaged Services
Description

CIRCL is a government-driven initiative operated as part of Luxembourg's national cybersecurity infrastructure, funded through government appropriations rather than commercial revenue generation.

circl.lu
Marketing channels5 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels4 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components4 values
Personnel, Technology or R&D, Operations, Infrastructure
GTM typeB2B
B2B
Offering typeSoftware
Software
Brand1 of 11 records shown
1MISP
Description

Malware Information Sharing Platform - a threat intelligence platform for sharing, storing and correlating Indicators of Compromise from targeted malware, attacks, or other cybersecurity threats.

circl.lu
+10 more records
Core offering1 text field

CIRCL is the national Computer Emergency Response Team (CERT/CSIRT) for Luxembourg's private sector, communes, and non-governmental entities. It provides incident response coordination, threat intelligence sharing via MISP, malware analysis, coordinated vulnerability disclosure (CVD), and operates multiple open-source cybersecurity platforms and public services including Vulnerability-Lookup, GCVE, Pandora, and Hash Lookup.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 3 values shown
  • Free incident reporting and response services for Luxembourg organizations
+2 more records
Product overview1 text field

CIRCL operates as Luxembourg's national Computer Emergency Response Team (CERT/CSIRT), providing a comprehensive cybersecurity platform comprising open-source tools, public services, and coordinated vulnerability management. The core portfolio includes MISP for threat intelligence sharing, Dynamic Malware Analysis (DMA) for automated malware analysis, CIRCLean for USB sanitization, Passive DNS for historical DNS records, and Vulnerability-Lookup for aggregating vulnerability data from over 25 sources. The recently launched GCVE (Global CVE Allocation System) provides a decentralized alternative to the US CVE program, hosted on European-controlled infrastructure. Additional services include Hash Lookup API, BGP Ranking, PGP Key Server, Pandora document analysis, and various open-source tools including Lookyloo (web forensics), AIL Project (dark web monitoring), Kunai (threat hunting), FlowIntel (case management), and Cerebrate (trusted directory). CIRCL also serves as the national Coordinated Vulnerability Disclosure coordinator under NIS 2 and operates as a CVE Numbering Authority (CNA) under the ENISA CVE Root.

Product and service10 records
1MISP (Malware Information Sharing Platform)
CategoryThreat Intelligence Platform
Description

Open-source threat intelligence platform for sharing, storing, and correlating Indicators of Compromise (IOCs) and tactical threat intelligence, enabling private sharing communities for coordinated defense across organizations.

2Dynamic Malware Analysis (DMA)
CategoryMalware Analysis Service
Description

Automated sandbox environment for analyzing malicious software, examining behavior patterns, and generating detailed threat reports for security researchers and incident responders.

3CIRCLean
CategoryDocument Sanitization Tool
Description

Open-source tool that automatically cleans documents from untrusted USB keys, removing potentially malicious content while preserving legitimate files, used by organizations handling untrusted media.

4Passive DNS
CategoryHistorical DNS Database
Description

Database service storing historical DNS records for incident response, threat intelligence, and security investigations, accessible to security professionals.

5Vulnerability-Lookup
CategoryVulnerability Lookup Service
Description

Fast vulnerability lookup and correlation platform aggregating data from over 25 public sources, providing a collaborative space for coordinated vulnerability disclosure.

6Global CVE Allocation System (GCVE)
CategoryDecentralized Vulnerability Identification System
Description

Decentralized alternative to the CVE program for identifying and numbering software security vulnerabilities. Allows independent numbering authorities to allocate identifiers without centralized control while maintaining backward compatibility with existing CVE infrastructure.

7Hash Lookup
CategoryFile Hash Lookup Service
Description

Public API service to lookup hash values against known database of malicious and benign files for threat identification, available to the security community.

8BGP Ranking
CategoryNetwork Security Analysis Service
Description

Service for ranking and analyzing BGP (Border Gateway Protocol) data to identify potentially malicious network activity, used by network operators and security researchers.

9PGP Key Server
CategoryPGP Key Server
Description

Public key server for PGP/GPG keys, supporting secure communication and email encryption for the security community.

10Pandora Document and File Analysis
Scale indicator4 records

Each record includes

Type, Value, Description, Source

Partnership7 partners
Strategic tierCoreTypeStrategic or Co-development PartnerAnnounced on2026-05-20
Description

CIRCL became a CVE Numbering Authority (CNA) under the ENISA CVE Root, enabling CIRCL to assign CVE IDs and publish CVE Records within its scope.

2MeliCERTes Project
Strategic tierMinorTypeStrategic or Co-development PartnerAnnounced on2022-01-01
Description

MeliCERTes was a three-year project to create open platforms for collaboration on cybersecurity, concluding in 2022.

circl.lu
Strategic tierFlagshipTypeStrategic or Co-development PartnerAnnounced on2008-01-01
Description

CIRCL operates under the Luxembourg House of Cybersecurity, a government initiative that houses Luxembourg's national cybersecurity capabilities. Copyright states 2008-2023 CIRCL operating under LHC.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

CIRCL is a member of FIRST, the global forum for incident response and security teams, enabling collaboration and information sharing with other national and organizational CERTs worldwide.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

CIRCL is a member of OASIS, participating in international standards development for cybersecurity and information sharing.

Strategic tierCoreTypeTechnology or Integration
Description

CIRCL launched and operates the Global CVE Allocation System (GCVE), a decentralized alternative for identifying software security vulnerabilities. The initiative addresses governance concerns after the traditional CVE program nearly collapsed.

Strategic tierCoreTypeTechnology or Integration
Description

CIRCL is a key contributor and operator of the MISP (Malware Information Sharing Platform) threat intelligence sharing platform, offering private sharing communities.

Recent move5 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight5 records

Each record includes

Type, Description

Peers10 records
TypeBroad incumbent
Description

EU-level cybersecurity agency that oversees the ENISA CVE Root under which CIRCL operates as a CNA. Directly comparable as the pan-European counterpart to CIRCL's national CERT role, with overlapping mandate in coordinated vulnerability disclosure and EU-wide cybersecurity coordination.

2CERT-Bund (Germany Federal Office for Information Security)
TypeBroad incumbent
Description

Germany's federal CERT operated by BSI. Comparable as a national CERT providing incident response coordination and vulnerability disclosure for German public and private sector entities, with similar regulatory and sovereign positioning.

TypeBroad incumbent
Description

Dutch national CERT providing incident response, threat intelligence, and coordinated vulnerability disclosure. Comparable as a European national CERT serving both private and public sector constituencies.

TypeBroad incumbent
Description

UK's national CERT and cybersecurity authority. Directly comparable in role and function as a national government CERT providing incident response, vulnerability coordination, and threat intelligence to private and public sector entities.

5SWITCH-CERT
TypeDirect peer
Description

Swiss national CERT serving the academic, research, and private sector communities. Comparable as a smaller national CERT with similar mandate structure and active open-source tool contributions to the global CERT ecosystem.

TypeBroad incumbent
Description

France's national cybersecurity agency. Comparable as a peer national CERT providing incident response, vulnerability management, and threat intelligence services, with a similarly strong government-driven mandate.

TypeBroad incumbent
Description

US national cybersecurity agency that operates alongside NIST NVD and MITRE in the CVE ecosystem. Comparable as a national CERT with a much larger scope, and a key stakeholder in the global vulnerability numbering infrastructure that GCVE seeks to complement.

8CCCS (Canadian Centre for Cyber Security)
TypeBroad incumbent
Description

Canada's national CERT providing incident response and cybersecurity services to government, private sector, and critical infrastructure operators. Comparable in role and structure to CIRCL as a national authority.

TypeOthers
Description

Commercial vulnerability management and exposure platform. While not a national CERT, Tenable is a relevant adjacent player whose commercial vulnerability intelligence capabilities overlap with CIRCL's Vulnerability-Lookup aggregation function.

TypeEmerging player
Description

Independently funded successor initiative for the CVE program, explicitly formed as an alternative governance model. Directly comparable as a peer initiative addressing vulnerability numbering governance, and a competing alternative to CIRCL's GCVE.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses2 records

Each record includes

Headline, Details, Source

Competitive moat5 records

Each record includes

Type, Details

Key risks5 records

Each record includes

Headline, Details, Source

Key highlights6 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers3 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment3 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile3 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
Yes

Docs URL, Description

AI maturity
App detail

Has app

Feature15 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
No data
Compliance5 records

Each record includes

Name, Class, Description

Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

The Computer Incident Response Center Luxembourg

Cybersecurity Incident Response Servicescircl.lu

The Computer Incident Response Center Luxembourg firmographics

Firmographics
Name
The Computer Incident Response Center Luxembourg
Legal name
CIRCL Computer Incident Response Center Luxembourg
Website
https://circl.lu
Company type
Private
Founded year
2008
Operating status
Operating
Headcount range
11–50 employees
Ownership category
akta.pro rank

The Computer Incident Response Center Luxembourg industry classification

Industry
Product category
Cybersecurity Incident Response Services
SIC
Communications Services, Nec (4899)
akta.pro primary industry
Critical Infrastructure Protection (CIP) & NERC-CIP Compliance (HDADAJAC)

Keywords

  • Computer incident response
  • Threat intelligence sharing
  • Vulnerability coordination
  • Malware analysis services
  • CERT operations

Where The Computer Incident Response Center Luxembourg is headquartered

Location

Headquarters

HQ city
Luxembourg
HQ country
Luxembourg
HQ region
Europe

Offices1 record

Markets served

The Computer Incident Response Center Luxembourg business model

Business model
GTM type
B2B
Offering type
Software
Cost components
Personnel, Technology or R&D, Operations, Infrastructure

Revenue model

  1. Government Funding: CIRCL is a government-driven initiative operated as part of Luxembourg's national cybersecurity infrastructure, funded through government appropriations rather than commercial revenue generation.

Go-to-market motion1 record

Distribution channels4 records

Marketing channels5 records

The Computer Incident Response Center Luxembourg product offering

Product offering

Core offering

CIRCL is the national Computer Emergency Response Team (CERT/CSIRT) for Luxembourg's private sector, communes, and non-governmental entities. It provides incident response coordination, threat intelligence sharing via MISP, malware analysis, coordinated vulnerability disclosure (CVD), and operates multiple open-source cybersecurity platforms and public services including Vulnerability-Lookup, GCVE, Pandora, and Hash Lookup.

Product overview

CIRCL operates as Luxembourg's national Computer Emergency Response Team (CERT/CSIRT), providing a comprehensive cybersecurity platform comprising open-source tools, public services, and coordinated vulnerability management. The core portfolio includes MISP for threat intelligence sharing, Dynamic Malware Analysis (DMA) for automated malware analysis, CIRCLean for USB sanitization, Passive DNS for historical DNS records, and Vulnerability-Lookup for aggregating vulnerability data from over 25 sources. The recently launched GCVE (Global CVE Allocation System) provides a decentralized alternative to the US CVE program, hosted on European-controlled infrastructure. Additional services include Hash Lookup API, BGP Ranking, PGP Key Server, Pandora document analysis, and various open-source tools including Lookyloo (web forensics), AIL Project (dark web monitoring), Kunai (threat hunting), FlowIntel (case management), and Cerebrate (trusted directory). CIRCL also serves as the national Coordinated Vulnerability Disclosure coordinator under NIS 2 and operates as a CVE Numbering Authority (CNA) under the ENISA CVE Root.

Differentiator

Problem solved

Functional benefit

Brands

  • MISP: Malware Information Sharing Platform - a threat intelligence platform for sharing, storing and correlating Indicators of Compromise from targeted malware, attacks, or other cybersecurity threats.
  • CIRCLean
  • GCVE
  • Vulnerability-Lookup
  • Lookyloo
  • Pandora
  • Kunai
  • Flowintel
  • Cerebrate
  • AIL Project
  • Lacus

Products and services

  • MISP (Malware Information Sharing Platform) Open-source threat intelligence platform for sharing, storing, and correlating Indicators of Compromise (IOCs) and tactical threat intelligence, enabling private sharing communities for coordinated defense across organizations.
  • Dynamic Malware Analysis (DMA) Automated sandbox environment for analyzing malicious software, examining behavior patterns, and generating detailed threat reports for security researchers and incident responders.
  • CIRCLean Open-source tool that automatically cleans documents from untrusted USB keys, removing potentially malicious content while preserving legitimate files, used by organizations handling untrusted media.
  • Passive DNS Database service storing historical DNS records for incident response, threat intelligence, and security investigations, accessible to security professionals.
  • Vulnerability-Lookup Fast vulnerability lookup and correlation platform aggregating data from over 25 public sources, providing a collaborative space for coordinated vulnerability disclosure.
  • Global CVE Allocation System (GCVE) Decentralized alternative to the CVE program for identifying and numbering software security vulnerabilities. Allows independent numbering authorities to allocate identifiers without centralized control while maintaining backward compatibility with existing CVE infrastructure.
  • Hash Lookup Public API service to lookup hash values against known database of malicious and benign files for threat identification, available to the security community.
  • BGP Ranking Service for ranking and analyzing BGP (Border Gateway Protocol) data to identify potentially malicious network activity, used by network operators and security researchers.
  • PGP Key Server Public key server for PGP/GPG keys, supporting secure communication and email encryption for the security community.
  • Pandora Document and File Analysis

Quantifiable outcome

  • Free incident reporting and response services for Luxembourg organizations
  • +2 more outcomes

Companies that use The Computer Incident Response Center Luxembourg

Customer profile

Named customers3 records

Segments3 records

Ideal customer profiles3 records

The Computer Incident Response Center Luxembourg technology and API

Technology

Technology focussed Yes

API detail

Has API
Yes
API docs
API detail

Core technology

AI maturity

App detail

Feature15 records

The Computer Incident Response Center Luxembourg partnerships and signals

Strategic signal

Partnerships

Seven partnerships are on record, tiered core, minor and flagship.

  • ENISA (European Union Agency for Cybersecurity)coreStrategic or Co-development Partner · 20 May 2026CIRCL became a CVE Numbering Authority (CNA) under the ENISA CVE Root, enabling CIRCL to assign CVE IDs and publish CVE Records within its scope.
  • MeliCERTes ProjectminorStrategic or Co-development Partner · 1 January 2022MeliCERTes was a three-year project to create open platforms for collaboration on cybersecurity, concluding in 2022.
  • LHC - Luxembourg House of CybersecurityflagshipStrategic or Co-development Partner · 1 January 2008CIRCL operates under the Luxembourg House of Cybersecurity, a government initiative that houses Luxembourg's national cybersecurity capabilities. Copyright states 2008-2023 CIRCL operating under LHC.
  • FIRST (Forum of Incident Response and Security Teams)coreStrategic or Co-development PartnerCIRCL is a member of FIRST, the global forum for incident response and security teams, enabling collaboration and information sharing with other national and organizational CERTs worldwide.
  • OASIS OpencoreStrategic or Co-development PartnerCIRCL is a member of OASIS, participating in international standards development for cybersecurity and information sharing.
  • GCVE InitiativecoreTechnology or IntegrationCIRCL launched and operates the Global CVE Allocation System (GCVE), a decentralized alternative for identifying software security vulnerabilities. The initiative addresses governance concerns after the traditional CVE program nearly collapsed.
  • MISP ProjectcoreTechnology or IntegrationCIRCL is a key contributor and operator of the MISP (Malware Information Sharing Platform) threat intelligence sharing platform, offering private sharing communities.

Scale indicators4 records

Recent moves5 records

Expansion highlights5 records

The Computer Incident Response Center Luxembourg competitors and assessment

Company assessment

Broad incumbents

  • ENISA (European Union Agency for Cybersecurity): EU-level cybersecurity agency that oversees the ENISA CVE Root under which CIRCL operates as a CNA. Directly comparable as the pan-European counterpart to CIRCL's national CERT role, with overlapping mandate in coordinated vulnerability disclosure and EU-wide cybersecurity coordination.
  • CERT-Bund (Germany Federal Office for Information Security): Germany's federal CERT operated by BSI. Comparable as a national CERT providing incident response coordination and vulnerability disclosure for German public and private sector entities, with similar regulatory and sovereign positioning.
  • NCSC-NL (National Cyber Security Centre Netherlands): Dutch national CERT providing incident response, threat intelligence, and coordinated vulnerability disclosure. Comparable as a European national CERT serving both private and public sector constituencies.
  • NCSC (UK National Cyber Security Centre): UK's national CERT and cybersecurity authority. Directly comparable in role and function as a national government CERT providing incident response, vulnerability coordination, and threat intelligence to private and public sector entities.
  • ANSSI (Agence Nationale de la Sécurité des Systèmes d'Information): France's national cybersecurity agency. Comparable as a peer national CERT providing incident response, vulnerability management, and threat intelligence services, with a similarly strong government-driven mandate.
  • CISA (Cybersecurity and Infrastructure Security Agency): US national cybersecurity agency that operates alongside NIST NVD and MITRE in the CVE ecosystem. Comparable as a national CERT with a much larger scope, and a key stakeholder in the global vulnerability numbering infrastructure that GCVE seeks to complement.
  • CCCS (Canadian Centre for Cyber Security): Canada's national CERT providing incident response and cybersecurity services to government, private sector, and critical infrastructure operators. Comparable in role and structure to CIRCL as a national authority.

Direct peers

  • SWITCH-CERT: Swiss national CERT serving the academic, research, and private sector communities. Comparable as a smaller national CERT with similar mandate structure and active open-source tool contributions to the global CERT ecosystem.

Others

  • Tenable (Nessus / Vulnerability Management): Commercial vulnerability management and exposure platform. While not a national CERT, Tenable is a relevant adjacent player whose commercial vulnerability intelligence capabilities overlap with CIRCL's Vulnerability-Lookup aggregation function.

Emerging players

  • CVE Foundation: Independently funded successor initiative for the CVE program, explicitly formed as an alternative governance model. Directly comparable as a peer initiative addressing vulnerability numbering governance, and a competing alternative to CIRCL's GCVE.

Market position

Strengths5 records

Weaknesses2 records

Competitive moat5 records

Key risks5 records

Key highlights6 records

Customer concentration

The Computer Incident Response Center Luxembourg social profiles

Digital presence

The Computer Incident Response Center Luxembourg compliance and trust

Trust signal

Compliance5 records

The Computer Incident Response Center Luxembourg financial estimates

Financial estimate

Revenue estimate

Valuation estimate

The Computer Incident Response Center Luxembourg leadership team

Management profile

Number of profiles

The Computer Incident Response Center Luxembourg funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

The Computer Incident Response Center Luxembourg M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about The Computer Incident Response Center Luxembourg

What does The Computer Incident Response Center Luxembourg do?

CIRCL is the national Computer Emergency Response Team (CERT/CSIRT) for Luxembourg's private sector, communes, and non-governmental entities. It provides incident response coordination, threat intelligence sharing via MISP, malware analysis, coordinated vulnerability disclosure (CVD), and operates multiple open-source cybersecurity platforms and public services including Vulnerability-Lookup, GCVE, Pandora, and Hash Lookup.

Is The Computer Incident Response Center Luxembourg a public or private company?

The Computer Incident Response Center Luxembourg is a private company. It is classified as state government owned and is currently operating.

When was The Computer Incident Response Center Luxembourg founded?

The Computer Incident Response Center Luxembourg was founded in 2008. It employs 11 to 50 people.

Where is The Computer Incident Response Center Luxembourg based?

The Computer Incident Response Center Luxembourg is headquartered in Luxembourg, Luxembourg, in the Europe region.

How does The Computer Incident Response Center Luxembourg make money?

One revenue line is on record: government Funding.

Who are The Computer Incident Response Center Luxembourg's main competitors?

Broad incumbents on record are ENISA (European Union Agency for Cybersecurity), CERT-Bund (Germany Federal Office for Information Security), NCSC-NL (National Cyber Security Centre Netherlands), NCSC (UK National Cyber Security Centre), ANSSI (Agence Nationale de la Sécurité des Systèmes d'Information), CISA (Cybersecurity and Infrastructure Security Agency) and CCCS (Canadian Centre for Cyber Security). SWITCH-CERT is listed as a direct peer. Tenable (Nessus / Vulnerability Management) is listed as an others. CVE Foundation is listed as an emerging player.

Does The Computer Incident Response Center Luxembourg have an API?

Yes. Vulnerability-Lookup provides a public API for vulnerability data access. The API endpoint is available at /api/ with JSON dumps of vulnerability data including CSAF feeds from multiple vendors (Cisco, Microsoft, Siemens, F5, etc.), OSV data, NVD data, KEV entries, and other vulnerability catalogs. Hash lookup service provides a public API to lookup hash values against known database of files. Developer documentation is at vulnerability.circl.lu/api.

What industry is The Computer Incident Response Center Luxembourg in?

The Computer Incident Response Center Luxembourg's product category is Cybersecurity Incident Response Services. Its primary akta.pro industry code is HDADAJAC, Critical Infrastructure Protection (CIP) & NERC-CIP Compliance. Its SIC code is 4899.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
CyberScoopGCVE launches as a decentralized system for tracking software vulnerabilitiesThe Computer Incident Response Center Luxembourg (CIRCL) has launched the Global CVE Allocation System (GCVE), a decentralized alternative for identifying and numbering software security vulnerabilities, addressing governance and sustainability concerns exposed when the traditional CVE program nearly collapsed last April after CISA initially failed to renew its contract with MITRE. The new system allows independent numbering authorities to allocate identifiers without centralized control while maintaining backward compatibility with existing CVE infrastructure through a reserved numbering authority designation. Multiple competing initiatives are emerging, including the CVE Foundation formed in the U.S., which aims to establish private-sector and multi-government funding for vulnerability tracking.ForbesNew Security Vulnerability Database Launches In The EUA new vulnerability database (db.gcve.eu) has launched in the EU as a decentralized alternative to the US-based CVE program, created by the Global Cybersecurity Vulnerability Enumeration and administered by the Computer Incident Response Centre Luxembourg. The platform enables autonomous assignment and publication of vulnerability identifiers without central approval, addressing concerns raised after US CVE funding was pulled and reinstated in April 2025. Experts have responded positively, noting the initiative reduces global dependence on a single vulnerability database and strengthens cyber resilience.