SecurityWeek reported that 54 organizations joined the CVE Numbering Authority (CNA) program in 2022, compared with 43 in 2021. Its December 22, 2022 report said the program then had 260 CNAs across 35 countries. These are historical figures attributed to SecurityWeek’s analysis, not a current CNA count.
How many CNAs were added in 2022?
SecurityWeek’s analysis counted 54 organizations added as CNAs during 2022, 11 more than the 43 it counted in 2021. The publication reported the figures on December 22, 2022, and said the program total at that time was 260 organizations across 35 countries. The CVE Program materials cited here do not independently confirm SecurityWeek’s exact annual count.
| Measure | Reported figure | Attribution and date |
|---|---|---|
| CNAs added in 2021 | 43 | SecurityWeek analysis reported December 22, 2022 |
| CNAs added in 2022 | 54 | SecurityWeek analysis reported December 22, 2022 |
| Program total at the time | 260 CNAs across 35 countries | SecurityWeek report, December 22, 2022 |
Read SecurityWeek’s report on the 2022 additions.
What does a CVE Numbering Authority do?
A CNA is an organization authorized to assign CVE IDs to vulnerabilities affecting products within its distinct, agreed-upon scope, for inclusion in first-time public announcements of new vulnerabilities. That is the CVE Program’s definition; CNA status is scoped authority, not a mandate to handle every vulnerability.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
Most CNAs handle vulnerabilities in their own products. Some also assign CVE IDs for third-party vulnerabilities found by their researchers, when those issues fall outside another CNA’s scope.
See the CVE Program’s CNA description.
Why does a CNA’s scope matter?
Scope determines which products and vulnerabilities an organization is authorized to handle. When a vulnerability does not fit a CNA’s remit, another CNA may be responsible; the fact that one organization discovered an issue does not automatically make it the appropriate authority to assign the CVE ID.
The program’s rules describe coordination and escalation routes: issues can move from Sub-CNAs to their Root CNAs and ultimately to the Program Root CNA. The rules also set out CNA responsibilities involving providing CVE IDs to reporters, supplying information for CVE records, and publishing records.
Review the CVE CNA Operational Rules.
What do current CNA rules say?
As of October 4, 2026, the CVE CNA Operational Rules page identifies version 4.2.0 as approved on August 20, 2026, and effective August 25, 2026. These dates describe the current rules listed on that page; they should not be read as the rules that governed every CNA admission in 2022.
Rank #3
How organizations join the CNA program
CVE Program resources include onboarding slides and videos for new CNAs. Root CNAs recruit and onboard participants, provide training, and manage the CNAs under their care. The program’s onboarding materials and rule set are the practical starting points for organizations evaluating participation.
Explore the CVE Program’s CNA onboarding resources.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

