Security data · CNA

CNA directory: who assigns CVE identifiers

A CNA (CVE Numbering Authority) is an organization authorized by the CVE program to reserve and publish identifiers for a defined scope: its own products, an ecosystem, or a country.

400+authorized CNAs
4families of authorities
CNA·Root·ADPthree distinct roles

In short

The CVE program is decentralized: more than 400 organizations assign identifiers, each within its own scope. That is what gives the program its coverage and speed. It is also why a CVE record is sometimes complete down to the last field, and sometimes unusable.

· 6 min read.

What a CNA actually does

When a researcher reports a flaw in a product, they contact the CNA that covers that product — usually the vendor itself. The CNA reserves an identifier, keeps the details confidential while the fix is prepared, then publishes the record on disclosure day.

MITRE plays no part in this process: it authorizes CNAs, settles disputes and serves as a safety net for products no one covers. In other words, the quality of what you read in a CVE record does not depend on the program: it depends on the organization that published it.

The CNAs you will run into most often

The complete official list is published and kept up to date by the CVE program; we do not copy its hundreds of rows here, as they would be out of date within a month. Here, instead, are the ones whose publications make up most of a French-language monitoring feed:

CNATypeScope
MITRERoot and secretariatAny product without an assigned CNA; program arbitration
MicrosoftVendorWindows, Office, Azure and the related ecosystem
AppleVendormacOS, iOS, Safari and services
Google / ChromeVendorChrome, Android, Google services
Red HatVendorRHEL and the open source packaged by Red Hat
CiscoVendorNetwork equipment and related software
OracleVendorDatabase, Java, enterprise applications
GitHub (GHSA)Vendor and coordinatorDependencies in the npm, PyPI, Maven, RubyGems… ecosystems
CERT/CCCoordinatorProducts whose vendor is not a CNA, coordinated disclosure
CISA / ICS-CERTGovernmentIndustrial systems and critical infrastructure
Patchstack, WordfenceResearcherWordPress plugins and themes, at very high volume

Four families, four behaviors

TypeWhat it publishesWhat to expect from it
VendorFlaws in its own productsPrecise affected versions, and a fix the same day
CoordinatorFlaws in third-party products with no authorized vendorA careful description, sometimes with no fix available
Researcher / platformFlaws reported by its communityVolume, with completeness that varies from one record to the next
GovernmentA national or sector-specific scopeCoverage of areas the market serves poorly

CNA, Root, ADP: who does what

  • CNA: assigns and publishes the identifiers within its scope.
  • Root: oversees a group of CNAs, recruits them and settles disputes. MITRE is the root of last resort.
  • ADP (Authorized Data Publisher): does not assign identifiers but enriches existing records. CISA is one, through its Vulnrichment program, which adds scores and classifications to records that lack them.

This last role has grown in importance since NVD enrichment slowed down: a share of records are now completed through this channel rather than through the historical path.

Why the CNA determines the quality of your alerts

A CVE record with no affected version and no standardized product identifier cannot be matched against any inventory: no tool, whatever it is, can guess whether it affects you. It will end up either ignored or surfaced “just in case” — in other words, as noise.

Yet whether these fields are present depends entirely on the publishing CNA. Some publish quickly and sparsely; others publish slowly and completely. This is a structural feature of the program, not an accident: that is why we measure source completeness and why we cross-check every record against several feeds.

What it means for you, in practice

Two useful habits:

  1. Check who is publishing before concluding that an alert is vague. A terse record from a high-volume CNA often means you need to read the vendor's advisory, which is precise.
  2. Report incomplete records. CNAs accept correction requests, and an enriched record benefits everyone — including your monitoring tool the following month.
Sources & official referencesOfficial CNA list — cve.org · CVE program rules — cve.org · Vulnrichment program (ADP) — CISA.

Key takeaways

  • A CNA assigns and publishes the CVEs within its scope.
  • Four families: vendor, coordinator, researcher, government.
  • Hierarchy: CNA → Root → root of last resort; ADPs enrich without assigning.
  • Publication volume says nothing about quality, and quality is what makes an alert actionable.

FAQ

How many CNAs are there?

More than 400 authorized organizations worldwide, and the number grows every month. The official list published by the CVE program is the only up-to-date one; any figure frozen in an article goes stale within weeks.

Can a CNA fill in its CVEs poorly?

Yes, and it happens mostly with those that publish at very high volume. The missing fields are most often the affected version and the standardized product identifier — precisely the two that enable automatic matching against an inventory.

How does an organization become a CNA?

By applying to a Root, committing to follow the program rules (timelines, record format, declared scope) and designating a reachable security contact. The process is open to vendors and open source projects alike.

Free plan, no card

Get only the CVEs that affect your actual estate.

Declare your components once. We alert you as soon as a flaw affects one of them, already prioritized by KEV and EPSS, on the channel of your choice. The first alert goes out at the next sync.

  • Free, no credit card
  • Built & hosted in France
  • Export your data at any time

Keep reading

Create a free account