Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
115 changes: 58 additions & 57 deletions Inactive_CNA_Policy.md
Original file line number Diff line number Diff line change
@@ -1,84 +1,85 @@
# CVE Program Policy and Procedure for Inactive CNAs
# CVE Policy for Inactive CNAs

| Status | Final |
| ---: | --- |
| Version | 1.2.0 |
| Approved | 2021-01-14 |
| Effective | 2021-01-14 |
Document Version: 2.0.0

## Policy for Inactive CNAs
CVE Board Approval: Month xx, 2026

This policy and procedure is enforceable by Roots and the Secretariat.
Effective Date: Month xx, 2026

Active CNA participation is critical for the CVE Program to achieve its adoption, coverage, and time-to-populate goals. Active CNAs assign CVE IDs and publish CVE Records within a distinct, agreed upon, and documented scope (hereafter referred to as scope). By assigning CVE IDs and publishing CVE Records, CNAs expand CVE Program coverage and adoption, and are critical actors in federating CVE Program operations. Active CNAs may also participate in various working groups and discussions to advance CVE Program objectives.
## Purpose and Scope

Inactive CNAs may be problematic for the CVE Program because adoption and coverage may not be achieved within a scope, even though such a scope is assigned to a CNA. However, inactive CNAs may be inactive for legitimate reasons, such as no new vulnerabilities are identified within a scope and, once identified, normal assignment and publication activities are resumed. There are also illegitimate reasons for CNA inactivity, such as the CNA is no longer interested, properly resourced, or competent to participate in the CVE Program as a CNA. CNAs that are inactive for legitimate reasons may continue to participate in the CVE Program. CNAs that are inactive for illegitimate reasons may not continue to participate in the CVE Program, unless the reasons for inactivity are satisfactorily remediated.
The effectiveness of the CVE Program’s federated model depends on active [CVE Numbering
Authority (CNA)](https://www.cve.org/ResourcesSupport/Glossary#glossaryCNA) participation to preserve program coverage, accountability, and operational
continuity.

Inactive CNAs are identified as those CNAs, over the preceding six-month period, that have not assigned CVE IDs or published CVE Records within a scope, and have not participated in any of the various working groups and discussions to advance CVE Program objectives.
This policy defines how the CVE Program identifies and addresses inactive CNAs. It is
enforceable by CVE Program [Roots](https://www.cve.org/ResourcesSupport/Glossary#glossaryRoot), [TL-Roots](https://www.cve.org/ResourcesSupport/Glossary#glossaryTLRoot), and the [Secretariat](https://www.cve.org/ResourcesSupport/Glossary#glossarySecretariat).

Inactive CNAs must be identified by their Root CNA so that: 1) the reason(s) for inactivity are determined; and 2) appropriate next steps are taken.
This policy applies to all CNAs operating under any Root within the CVE Program.

## Procedure for Contacting Inactive CNAs
## Inactive CNA Identification

1. Attempt to contact the CNA using all available contact information to determine the reason(s) for the inactivity and appropriate next steps; use the following message:
A CNA is considered inactive when, over six months (or another period defined in writing by its
TL-Root or Root), the CNA:

> <CNA NAME/POC> Active participation in the CVE Program is necessary to retain CNA status. Our records indicate that <CNA NAME> is currently inactive (i.e., over the preceding six-month period, CNA has not assigned CVE IDs or publish CVE Records within a scope, and/or has not participated in various working groups and discussions to advance CVE Program objectives). Please let us know the reasons for the inactivity by <DATE plus 2 weeks>.
* Has not assigned or reserved CVE IDs within its scope; or

If contact is made within two weeks, follow the [Reason for Inactivity](https://www.cve.org/Resources/General/Policies/Inactive-CNA-Policy.pdf#page=3&zoom=100,92,580) instructions. If contact is not made, proceed to step 2.
2. Two weeks after taking step 1, attempt to contact the CNA again (replying to the email submission from step 1) using the following message:
* Has not published any CVE Records within its scope; or

> <CNA NAME/POC> The CVE Program contacted you on <ENTER DATES HERE> to determine the reason for <CNA NAME’s> inactivity. Active participation in the CVE Program is necessary to maintain CNA status. Please let us know the reasons for the inactivity by <DATE plus 2 weeks>. We look forward to hearing from you soon.
* Has not participated in working groups or discussions to advance CVE Program
objectives; or

If contact is made within two weeks, follow the Reason for Inactivity instructions. If contact is not made, proceed to step 3.
* Fails to respond to inquiries or requests from its Root, TL-Root, or the Secretariat.

3. If contact is not made within two weeks of the step 2 communication, warn the CNA that it will be removed from the CVE Program within two weeks if they do not respond (replying to the email string from step 2); use the following statement:
The mere presence of reserved CVE IDs, if they have extraordinarily long disclosure
timeframes, is not considered a sign of activity (see the CVE Reserved but Public (RBP) Policy).

> <CNA NAME/POC> The CVE Program contacted you on <ENTER DATES HERE> to determine the reason for <CNA NAME’s> inactivity. Our records indicate that <CNA NAME> is currently inactive because <ENTER REASONS HERE>. Active participation in the CVE Program is necessary to maintain CNA status. If the CVE Program does not hear from you by <ENTER DATE HERE>, your CNA status will be revoked, which means that <ENTER CNA NAME HERE> will no longer be authorized to assign CVE IDs or populate CVE Records and will be removed from the CNA roster, CNA-specific communication, and applicable working groups.
>
> Should your CNA status be revoked, you are eligible to reapply to become a CNA in the future, provided you complete the CNA onboarding process.
>
> We look forward to hearing from you soon.
## Reasons for Inactivity

If contact is made within two weeks, follow the Reason for Inactivity instructions. If contact is not made, proceed to step 4
The CVE Program considers some reasons for inactivity to be valid, for instance, when no new
vulnerabilities have been identified within the CNA’s scope and normal assignment and
publication activities resume once vulnerabilities are identified.

4. Two weeks after step 3, if contact is not made with the CNA, inform the CNA that its CNA status is hereby revoked respond (replying to the email string from step 3), using the following statement:
The CVE Program considers other reasons for inactivity to be invalid, for instance:

> <CNA NAME/POC> The CVE Program contacted <CNA NAME> on <ENTER DATES HERE> to determine why <CNA NAME HERE> is inactive within the CVE Program. Responses to those communications were not received. Per the last communication, sent on <ENTER DATE HERE AND ATTACH THE STEP 3 EMAIL COMMUNICATION TO THE EMAIL> <ENTER CNA NAME HERE> CNA status is hereby revoked. This means that <ENTER CNA NAME HERE> is no longer authorized to assign CVE IDs or publish CVE Records and has been removed from the CNA roster, CNA-specific communication, and applicable working groups.
>
> \<ENTER CNA NAME HERE\> is eligible to reapply to become a CNA should the organization’s circumstances change. Should <ENTER CNA NAME HERE> want to be a CNA in the future, please contact <ENTER CONTACT INFORMATION HERE>.
>
> Thank you for past service to the CVE Program.
* When the CNA is no longer interested, properly resourced, or competent to participate in the
CVE Program as a CNA.

6. The next step is to follow the CVE Program’s CNA Removal Process to remove the organization as a CNA.
* When the CNA’s actions are detrimental to CVE Program objectives, for example, publishing
vulnerability records exclusively through a platform outside of the CVE Program (such as a
separate vulnerability information initiative).

## Reason for Inactivity
CNAs that are inactive for valid reasons may continue to participate in the CVE Program. CNAs
that are inactive for invalid reasons may not continue to participate, unless the reasons for
inactivity are remediated to the satisfaction of the Root.

1. No longer wants to participate: Follow the [CNA Removal Process](https://www.cve.org/Resources/General/Policies/Inactive-CNA-Policy.pdf#page=3&zoom=100,92,712).
## Identification and Engagement of Inactive CNAs

2. Legitimate: Document the reason(s) for inactivity and notify the Secretariat, the other Roots, and the CVE Board.
Roots and TL-Roots are responsible for identifying potentially inactive CNAs within their
hierarchies and taking appropriate follow-up actions.

3. Illegitimate: Document the reason(s) for inactivity and any corrective action that may be required. Notify the Secretariat, the other Roots, and the CVE Board.
When a CNA appears to be inactive, the Root or TL-Root should:

## Secretariat-specific CNA Removal Process
1. Attempt to contact the CNA using the Administrative Point of Contact and any other
available contact information to
* Confirm CNA communication status;
* Determine the reason(s) for inactivity (valid or invalid); and
* Discuss appropriate next steps, including remediation or possible
decertification and removal from the program

1. Announce the revocation of the CNA’s status:
2. Provide the CNA a reasonable timeframe (as defined by the TL-Root or Root) to respond
and, if appropriate, to propose or implement corrective actions.

a. Send an email to the private CVE Board list.
## Decertified CNAs

2. Notify Web Admin so that the CNA is removed from the CNA list on the website (<https://www.cve.org/PartnerInformation/ListofPartners>).

3. Mark the CNA as inactive in the CVE Wiki.

4. Transition the CNA’s CVE IDs to another CNA:

a. Reject all of the CNA’s reserved but not public IDs.

b. Transfer responsibility to the appropriate CNA(s) for the remaining CVE IDs.

5. Revoke the CNA’s privileges to all systems.

a. Ask Content Team to mark CNA as inactive in the CPS.

b. Remove CNA from the CNA mailing list (Only do this after the revocation message is sent).

c. Ask the Content Team to remove the CNA from the authorized GitHub contributors.
A CNA that is decertified:
* Is no longer authorized to assign CVE IDs or publish CVE Records within a defined
scope
* Will be removed from the CVE-Services, CNA-specific communications lists, and the
[List of Partners](https://www.cve.org/PartnerInformation/ListofPartners) on the cve.org website.
* Will be mentioned in a public notification on the [CVE.org](http://cve.org/) website from the Root
announcing the decertification along with the background and justification for the
decertification.
* Will be announced to the CNA mailing list.
CNAs that are decertified are eligible to reapply to become a CNA in the future. They must
complete the CNA onboarding process again and meet all current Program requirements.