Cyber Resilience

Regional Risk Watch (EU/UK)Standing

Regional risk watch: the EU and US agree on severity 93% of the time

Updated 12 August 2026 · Timeframe: Year to date (2026)

93%EU and US agree (same CVSS version) (41,885, 93.1%)EU rates higher (2,802, 6.2%)EU rates lower (290, 0.6%)
ENISA EUVD vs US (NVD), same CVSS version, 2026 YTD · security-resilience.ai

A raw comparison of ENISA's EUVD against the US NVD suggests they disagree on 30% of this year's CVEs. That figure is an artifact. The EUVD reports the CVSS 4.0 score the assigning authority supplied; NVD reports the 3.1 score; and 4.0 scores about half a point lower on the same flaw. Compare like-for-like, at the same CVSS version, and the two agree on 93% of the 44,977 CVEs both have scored this year. The EU is not re-rating vulnerabilities, it is surfacing the same vendor-assigned scores in a newer format.

Why it matters

A 'the EU disagrees with US severity' headline drives real triage under NIS2 and DORA, and it is mostly false. NVD now publishes its own score for barely a third of CVEs; the rest carry only the assigning authority's score, which both NVD and the EUVD pass through. The apparent gap is CVSS 4.0 versus 3.1, not a European re-assessment.

What to do

Our take

Reading the data correctly is the product. The regional story is not disagreement, it is that the disagreement is manufactured by mixing CVSS versions.

Earlier issues

Past states of this signal, most recent first.

08 August 2026 Regional risk watch: the EU and US agree on severity 93% of the time

Timeframe: Year to date (2026)

93%EU and US agree (same CVSS version) (40,610, 93.1%)EU rates higher (2,744, 6.3%)EU rates lower (285, 0.7%)

A raw comparison of ENISA's EUVD against the US NVD suggests they disagree on 31% of this year's CVEs. That figure is an artifact. The EUVD reports the CVSS 4.0 score the assigning authority supplied; NVD reports the 3.1 score; and 4.0 scores about half a point lower on the same flaw. Compare like-for-like, at the same CVSS version, and the two agree on 93% of the 43,639 CVEs both have scored this year. The EU is not re-rating vulnerabilities, it is surfacing the same vendor-assigned scores in a newer format.

03 August 2026 Regional risk watch: the EU and US agree on severity 93% of the time

Timeframe: Year to date (2026)

93%EU and US agree (same CVSS version) (38,918, 93.1%)EU rates higher (2,619, 6.3%)EU rates lower (280, 0.7%)

A raw comparison of ENISA's EUVD against the US NVD suggests they disagree on 31% of this year's CVEs. That figure is an artifact. The EUVD reports the CVSS 4.0 score the assigning authority supplied; NVD reports the 3.1 score; and 4.0 scores about half a point lower on the same flaw. Compare like-for-like, at the same CVSS version, and the two agree on 93% of the 41,817 CVEs both have scored this year. The EU is not re-rating vulnerabilities, it is surfacing the same vendor-assigned scores in a newer format.

29 July 2026 Regional risk watch: the EU and US agree on severity 93% of the time

Timeframe: Year to date (2026)

93%EU and US agree (same CVSS version) (37,592, 92.9%)EU rates higher (2,586, 6.4%)EU rates lower (280, 0.7%)

A raw comparison of ENISA's EUVD against the US NVD suggests they disagree on 32% of this year's CVEs. That figure is an artifact. The EUVD reports the CVSS 4.0 score the assigning authority supplied; NVD reports the 3.1 score; and 4.0 scores about half a point lower on the same flaw. Compare like-for-like, at the same CVSS version, and the two agree on 93% of the 40,458 CVEs both have scored this year. The EU is not re-rating vulnerabilities, it is surfacing the same vendor-assigned scores in a newer format.

24 July 2026 Regional risk watch: the EU and US agree on severity 93% of the time

Timeframe: Year to date (2026)

93%EU and US agree (same CVSS version) (36,456, 92.7%)EU rates higher (2,574, 6.5%)EU rates lower (289, 0.7%)

A raw comparison of ENISA's EUVD against the US NVD suggests they disagree on 32% of this year's CVEs. That figure is an artifact. The EUVD reports the CVSS 4.0 score the assigning authority supplied; NVD reports the 3.1 score; and 4.0 scores about half a point lower on the same flaw. Compare like-for-like, at the same CVSS version, and the two agree on 93% of the 39,319 CVEs both have scored this year. The EU is not re-rating vulnerabilities, it is surfacing the same vendor-assigned scores in a newer format.