{"componentChunkName":"component---src-templates-blog-template-js","path":"/blog/esaqa-becomes-cve-numbering-authority","result":{"data":{"markdownRemark":{"html":"<p>Effective September 9th, 2026, <strong>esaqa GmbH is a CVE Numbering Authority (CNA) operating under the ENISA Root</strong>.\nThis allows us to assign CVE Identifiers (CVE IDs) and publish CVE Records for eligible vulnerabilities within our scope, including\nvulnerabilities affecting products developed and maintained by esaqa GmbH, such as Psono.</p>\n<p>Joining the global <a href=\"https://www.cve.org/\">CVE Program</a> is an important step in the continued development of our\nvulnerability-management processes. It gives researchers, customers, vendors, and defenders a consistent way to identify\nand discuss publicly disclosed vulnerabilities in our products.</p>\n<h2>What Is a CVE Numbering Authority?</h2>\n<p>The mission of the CVE Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. Each\nqualifying vulnerability receives a unique CVE ID and a corresponding CVE Record. These records provide a shared reference\nthat security teams, software vendors, vulnerability scanners, and public databases can use when discussing and addressing\nthe same issue.</p>\n<p>CNAs are organizations authorized by the CVE Program to assign CVE IDs and publish CVE Records for vulnerabilities within\nan agreed scope. As a CNA, esaqa GmbH can now manage this process directly where we have assignment authority. Our\nresponsibilities include:</p>\n<ul>\n<li>Reviewing and triaging vulnerability reports</li>\n<li>Determining whether an issue qualifies for a CVE ID under the CVE Program rules</li>\n<li>Reserving and assigning CVE IDs for eligible vulnerabilities within our scope</li>\n<li>Coordinating disclosure with researchers and other affected parties</li>\n<li>Publishing accurate CVE Records with affected versions, impact, and remediation information</li>\n<li>Updating published records when relevant information changes</li>\n</ul>\n<h2>What This Means for Psono Users and Security Researchers</h2>\n<p>Our CNA status creates a more direct path from a confirmed vulnerability report to a globally recognized identifier and\npublic record. When a vulnerability in scope requires an identifier, we no longer need to rely on another CNA to\nassign its CVE ID.</p>\n<p>This should make our vulnerability-handling process more consistent and help us communicate advisories, affected versions,\nfixes, and mitigations clearly and effectively. It also makes it easier for customers and security tools to track an issue across release\nnotes, advisories, scanners, and vulnerability databases.</p>\n<p>Becoming a CNA does not mean that vulnerabilities cannot occur, and a CVE ID is not a severity rating or security\ncertification. It means that we are taking direct responsibility for transparent, timely, and coordinated handling of\neligible vulnerabilities in our scope.</p>\n<h2>Working Under the ENISA Root</h2>\n<p><a href=\"https://www.enisa.europa.eu/\">ENISA</a>, the European Union Agency for Cybersecurity, became a CVE Root for European entities\nin November 2025. In this role, ENISA recruits, trains, supports, and manages CNAs within its scope while helping ensure that\nCVE Program rules and processes are followed.</p>\n<p>Operating under the ENISA Root connects our work to a growing European vulnerability-management ecosystem while remaining\npart of the shared global CVE Program. We appreciate ENISA's guidance and support throughout the onboarding process.</p>\n<h2>Reporting a Vulnerability</h2>\n<p>We welcome reports from security researchers, customers, partners, and other members of the security community. If you\nbelieve you have found a vulnerability in Psono or another product or service developed or maintained by esaqa GmbH, please\nreview our <a href=\"https://esaqa.com/vulnerability-disclosure-policy\">Vulnerability Disclosure Policy</a> and contact\n<a href=\"mailto:security@esaqa.com\">security@esaqa.com</a>.</p>\n<p>Reports may be submitted in English or German. Sensitive reports can be encrypted using the OpenPGP key referenced in our\n<a href=\"https://esaqa.com/.well-known/security.txt\">security.txt</a> file. Please include the affected product and version, a clear\ndescription of the issue and its impact, and reproduction steps or a proof of concept where possible.</p>\n<p>Our CNA responsibilities build on the security practices we already follow: coordinated vulnerability disclosure, regular independent\nsecurity audits, open-source transparency, and clear communication with our users. We look forward to contributing more\ndirectly to the CVE Program and the wider cybersecurity community.</p>","frontmatter":{"date":"September 09, 2026","slug":"esaqa-becomes-cve-numbering-authority","title":"esaqa GmbH Becomes a CVE Numbering Authority Under the ENISA Root","description":"esaqa GmbH joins the global Common Vulnerabilities and Exposures (CVE™) Program as a CVE Numbering Authority (CNA) under the ENISA Root, strengthening coordinated vulnerability disclosure and management for Psono and our other products.","author":"Sascha Pfeiffer","featuredImage":null}}},"pageContext":{"slug":"esaqa-becomes-cve-numbering-authority","lang":"en","langPathPrefix":""}},"staticQueryHashes":["2149092236","3128451518","3192060438"]}