Announcement

Announcement

Tacit Becomes a CVE Numbering Authority (CNA)

Tacit Becomes a CVE Numbering Authority (CNA)

Tacit becomes a CNA
Tacit becomes a CNA

Software publishers using Tacit’s platform can now request Tacit to assign CVE IDs and manage eligible vulnerability disclosures directly.

Tacit is now a CVE Numbering Authority (CNA). Software publishers using the platform can submit an eligible vulnerability, ask Tacit to assign a CVE ID, and manage the associated record and disclosure from the same environment used to track product security. Researchers and other security contributors can also contact the publisher or Tacit for the same purpose when they identify a vulnerability affecting software referenced on the platform.

Assigning CVE IDs through Tacit

The CVE™ Program provides a global system for identifying, defining, and cataloging publicly disclosed cybersecurity vulnerabilities. Each eligible vulnerability receives a unique CVE ID and a CVE Record, enabling publishers, customers, researchers, and cybersecurity teams to refer to the same issue consistently and coordinate efforts to prioritize and address the vulnerabilities.

CVE IDs are assigned and CVE Records are published by CVE Numbering Authorities (CNAs). Each CNA operates within a defined scope and is responsible for assessing eligibility, assigning identifiers, , and maintaining the records it publishes. Tacit operates under the EU Agency for Cybersecurity (ENISA), which serves as its CVE Root. CVE Records can include information such as affected products and versions, CWE classifications, CVSS scores, and references. Vulnerability databases such as the NVD and EUVD may subsequently ingest and enrich this data.

Tacit’s CNA scope is:

“Vulnerabilities affecting software products, services, or components referenced in Tacit platform by software publishers”.

This means that software publishers using Tacit platform can therefore request Tacit to assign a CVE ID for vulnerabilities affecting their own products, services, or components. Researchers and other security contributors can also report eligible vulnerabilities to the publisher or directly to Tacit. We assess each request against the CVE Program’s rules, coordinate with the relevant publisher, and, where the vulnerability is determined to be eligible, assign a CVE ID and publish the corresponding CVE Record.

Our Vulnerability Disclosure Policy describes the reporting and coordination process.

Published disclosures are available on the Tacit advisory page. Free registration is required to access it.

Connecting product security to remediation

Tacit provides Product Security teams with a continuous, evidence-based view of their software security. Security data collected from development and security tools is centralized by product and version, giving teams a consistent record of findings, incidents, and remediation actions.

When an vulnerabiltiy is identified, teams can use Tacit to assess it, involve the right internal or external stakeholders, and maintain an accurate product-level record. Tacit also connects software publishers with the organizations relying on their products. These organizations can use the same information to assess exposure, coordinate with vendors, and track remediation across their application portfolio.

Becoming a CNA makes CVE ID assignment part of that workflow rather than a separate administrative process. Eligible vulnerabilities can be validated, assigned a CVE ID, documented, disclosed, and communicated through a consistent process.

This supports Tacit’s broader objective of improving vulnerability coordination between software publishers and organizations using their software by providing a structured process for CVE assignment, controlled disclosure, and documented communication that ultimately accelerates remediation.