2. CNA assignment scope
Our CNA scope dictates the boundaries within which VAPT is authorized to assign CVE Identifiers (CVE IDs).
2.1 Primary regional scope (GCC)
Vulnerabilities in software, hardware, and Internet of Things (IoT/OT) products or services developed, manufactured, or headquartered within the GCC member states:
- United Arab Emirates (UAE)
- Kingdom of Saudi Arabia (KSA)
- State of Kuwait
- State of Qatar
- Sultanate of Oman
- Kingdom of Bahrain
Condition: This applies exclusively to vendors in these regions that do not maintain their own active CNA status.
2.2 Global coordination scope
Vulnerabilities in third-party products, services, and open-source projects discovered by professional security firms (for example during penetration testing or red teaming engagements) or reported by international independent researchers, provided that:
- The vulnerability is reported directly through the VAPT.com platform for coordinated disclosure.
- The affected vendor is not already an active CNA.
2.3 Out of scope (exclusions)
- Existing Vendor CNAs: If the vulnerable product belongs to a vendor that is an active CNA (for example Microsoft, Apple, Oracle), the report must be routed directly to that vendor. VAPT enforces a strict right of first refusal policy.
- Non-security issues: Bugs that do not pose a demonstrable security impact (for example UI glitches or theoretical physical attacks without bypassed controls).
- Malware: General-purpose deliberately malicious code.
- Out-of-scope platforms: Vulnerabilities that fall under the specific scope of another specialized coordinator CNA, unless coordinated jointly.