SECNORA operates a coordinated vulnerability disclosure (CVD) program and is in the process of becoming a CVE Numbering Authority (CNA) under the CVE Program. This policy explains how SECNORA receives, coordinates, and discloses security vulnerabilities within its scope, so that affected parties can remediate before details become public and the security community can engage with us on clear, predictable terms.
The CVE-assignment provisions in this policy (in particular Sections 5–6) describe how SECNORA will operate once authorised as a CNA and take effect on authorisation. Until then, SECNORA coordinates disclosure and works with the relevant existing CNA — or the CNA of Last Resort (CISA / MITRE) — to obtain CVE identifiers for eligible vulnerabilities.
This policy is written to align with the CVE Program CNA Operational Rules and recognised coordinated vulnerability disclosure practice.
This policy applies to vulnerabilities within SECNORA’s CNA scope, as published in the CVE Program CNA List. The authoritative scope statement is maintained in SECNORA’s CNA record; where this policy and that record differ, the CNA record governs.
The following are out of scope for CVE assignment by SECNORA:
If a report falls outside our scope, we will tell you and, where possible, point you to the appropriate CNA or to the CNA of Last Resort.
If you believe you have found a vulnerability within our scope, please report it to us before public disclosure so we can coordinate a fix.
Where you can, please include:
A non-disclosure agreement is not required to report to us.
| Stage | Target |
|---|---|
| Acknowledge receipt | Within 3 business days |
| Initial triage and reproduction | Within 10 business days |
| CVE ID reserved (if eligible and in scope) | On confirmation, typically before public details are released |
| Coordinated disclosure window | 90 calendar days from notification of the affected vendor or maintainer (default) |
| Public disclosure / CVE Record published | On or before the agreed disclosure date |
The 90-day window is a default, not a fixed rule. We will:
Where SECNORA discovers a vulnerability itself, the same principles apply: we make a reasonable effort to notify the vendor or maintainer, agree a timeline, and publish the record with a public reference at disclosure.
If you believe SECNORA has not handled an assignment in line with the CNA Rules — for example, an unreasonable delay, a refused assignment, or a record we have not populated — please raise it with us first at the contact address above. If it cannot be resolved, it may be escalated to our Root CNA under the CVE Program, which acts as the adjudication point for scope and rule-compliance issues. (Root to be named on onboarding.)
SECNORA supports good-faith security research. If you make a good-faith effort to comply with this policy while investigating and reporting a vulnerability, SECNORA will consider your research authorised, will not pursue or support legal action against you for it, and will work with you to resolve the issue.
To stay within good faith, please:
This safe harbour covers SECNORA’s own conduct only. It does not authorise testing against third parties’ systems and does not bind vendors, maintainers, or other parties.
We credit reporters who wish to be named, using the name or handle you provide. Tell us if you would prefer to remain anonymous or if credit should be shared across a team.
This policy is reviewed at least annually and updated as the CVE Program rules and SECNORA’s scope evolve. Material changes to scope, contact details, or the disclosure location are reflected in SECNORA’s CVE Program CNA record.
SECNORA OÜ · Estonia · Registry code 14515469 Contact: · Policy: https://secnora.com/security/cve-disclosure-policy
Copyright @ 2026 SECNORA®