TL;DR: CNA authorization means vulnerabilities in its own offerings can be assigned CVE IDs, which improves disclosure consistency and makes it easier for security teams to correlate advisories with the CVE List and the NVD, according to SailPoint. The change matters because vulnerability governance is now a more explicit part of identity programme operations, not a side process.
Editorial analysis by NHI Mgmt Group, based on content published by SailPoint: “SailPoint Authorized as a CVE Numbering Authority (CNA)”.
Key questions
Q: How should IAM teams handle vulnerabilities once a vendor can assign CVEs to its own products?
A: IAM teams should treat vendor-assigned CVEs as the starting point for triage, ownership, and remediation tracking.
Q: Why does a CVE record matter more than a vendor advisory email for IAM governance?
A: A CVE record gives every team the same reference for the same issue, which reduces ambiguity in triage and prevents duplicate handling.
Q: What signs show that identity product vulnerability handling is not working well?
A: Common signs include duplicate tickets for the same issue, unclear ownership, inconsistent severity ratings, and advisories that never reach asset inventory or reporting systems.
Practitioner guidance
- Formalise CVE intake for IAM products Route every identity-platform advisory into the same vulnerability register used for other control-plane systems, and require a CVE ID before triage closes.
- Correlate advisories to internal ownership Map each CVE to an asset owner, service owner, and remediation deadline so identity tooling issues do not stall between security and operations.
- Update third-party risk reviews Add vendor CVE publication practices to supplier assessments for identity platforms, especially where the product supports authentication or provisioning.
Bottom line: CVE numbering authority status makes vulnerability disclosure more structured for IAM vendors and easier for practitioners to track.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
CVE assignment is now part of identity governance, not just disclosure hygiene: When an IAM vendor can assign CVEs to its own vulnerabilities, the product security process becomes directly relevant to identity operations. That shifts vulnerability tracking from a vendor-side communications task into a governance input for access platforms, governance teams, and security operations. The practical conclusion is that IAM programmes need intake paths that treat CVE records as operational identity risk signals.
A question worth separating out:
Q: How do the CVE List and NVD fit into identity security operations?
A: They provide the canonical reference and enrichment layer for vulnerability tracking. IAM teams can use them to normalise issue names, enrich severity context, and connect external disclosures to internal reporting and compliance evidence. That reduces manual translation and helps keep remediation workflows consistent.
👉 Read our full editorial: CVE Numbering Authority status and what it changes for IAM