Summary
- NRS's role in this subject is advocacy, research, campaigning, convening and authorized member representation. The operational acts belong to RIRs, lawful appointing authorities, qualified operators, auditors and continuity providers; citing an NRS position is neither evidence that NRS performs them nor an endorsement by BTW.
- Every registry-service operator should complete at least one independently observed migration drill each year. The tested request should look like an ordinary holder exit to service staff, while the assessor knows the holder, credentials, resources and authority are controlled and legitimate.
- The test must cover the entire journey: request receipt, identity and authority verification, export, objection handling, dependency inventory, receiving-registrar readiness, cutover, public proof, post-transfer access and closure. A successful file delivery is not a successful migration.
- Each stage needs a binding deadline measured from a verifiable event. Clocks may pause only for published reasons tied to the affected resource, and the registrar must state what evidence is missing, who can cure it and when the pause expires.
- The test portfolio should vary annually and include difficult but plausible conditions such as stale contacts, a large mixed portfolio, hosted RPKI, reverse DNS, a lawful hold, a partial migration and a request received outside local business hours.
- Failure compensation should be automatic, funded and proportional to duration and consequence. It should pay the test holder, reimburse the receiving registrar's wasted work and finance remediation, while preserving claims for greater proven loss.
- Results should separate portability failure from unrelated routing events, publish decisive metrics without exposing security details, and require retesting. Repeated failure should narrow new-customer permissions and can ultimately end registrar qualification.
- The annual drill turns exit from a legal abstraction into observed institutional capacity. It disciplines incumbents, reveals hidden dependencies, gives members comparable evidence and makes competitive registration possible without weakening one-current-authority safeguards.
The role boundary is part of the evidence
NRS's own stated positioning supplies the first boundary for this analysis. It is a membership and advocacy organization pressing for decentralization, exit, portability, redundancy and fewer discretionary choke points. Heng Lu's note on why NRS exists says directly that NRS does not sell products or implement commercial solutions; its role is to change the direction of governance. NRS may therefore publish research, organize campaigns, convene affected operators, support members and represent an organization that has granted it authority. It may not turn that representation into registry authority over anyone else.
The implementation layer is separate. RIRs, lawful appointing authorities, qualified operators, auditors and continuity providers remain responsible for any authoritative registry record, allocation, transfer recognition, RPKI or RDAP operation, technical failover, binding review, insolvency act or legally compelled remedy relevant to this article. The NRO coordinates the five RIRs; it is not another name for NRS. IANA numbering services perform their defined coordination role; they are not an NRS department. Courts and lawful public authorities retain the powers their legal systems actually give them.
BTW's role is separate again. BTW reports the observable structure, checks primary sources and labels proposals as proposals. It does not convert NRS advocacy into fact, campaign on NRS's behalf or infer authority from alignment. That reality-not-advocacy discipline is why the institutional nouns in this article matter: a recommendation from NRS, an act by an RIR and an order from a court are three different things.
Exit is a service that can fail
Institutions usually describe exit as a right held by the customer. That is legally important but operationally incomplete. To exercise the right, the holder needs authenticated access, a complete resource list, portable records, a receiving provider, bounded objection rules, dependent-service choices and a recognized cutover event. Each element can fail even when nobody formally denies the request.
Delay is the most common form of practical refusal. A registrar can request another document, route the case to a specialist, wait for a manager, discover a billing issue or say that a security review remains open. Individually, these steps may sound reasonable. Without clocks and evidence, their accumulation can keep a holder captive for months.
Hidden coupling creates a second risk. Registration service may have been sold with managed RPKI, reverse DNS, abuse contacts, monitoring or delegated administration. The holder can transfer the base appointment and then discover that a critical dependency still points to the old registrar. Conversely, the old registrar may assume every associated service should terminate immediately, creating avoidable disruption.
The annual test treats migration as a service whose outputs and tolerances can be observed. The key question is not whether the registrar has a policy page. It is whether a legitimate request proceeds through ordinary channels, within declared times, with one current authority and no silent loss of records or dependencies. The registry operator should test that capability before a distressed holder, insolvency event or court deadline makes failure expensive.
The drill must be anonymous to ordinary service staff
Preannounced tests produce theater. Senior managers select a clean portfolio, check every dependency, warn support staff and reserve a maintenance window. The registrar demonstrates that it can move one specially prepared customer when the institution knows its qualification depends on the result. That says little about ordinary exit.
The annual drill should instead use a controlled holder whose assessment status is known only to a small independent team. It submits through the same portal, contact address or service desk used by members. Staff authenticate it under normal controls. The case receives the same queue position and escalation opportunities as a real migration. The registrar learns that the request was an assessment after decisive events are complete or a safety threshold requires disclosure.
This is not permission to deceive about authority. The test holder uses genuine identity evidence, authorized representatives and resources reserved or lawfully delegated for assessment. Documents are truthful. published contact points work. The receiving registrar knows it is participating in a qualified exercise but does not disclose that fact to the losing registrar's ordinary staff.
The independent assessor maintains a sealed test charter identifying scope, safeguards and stop conditions. If a real security incident, legal issue or risk to unrelated holders appears, the assessor can reveal the exercise and halt it. The distinction is precise: the customer is real, the request is authorized and the resources are controlled; only the fact that this migration will determine an annual score is concealed.
A test portfolio must be realistic enough to reveal dependency
A single unused prefix with one current contact is too easy. The annual portfolio should resemble the range of customers the registrar actually serves. A small registrar may receive a modest test set. A provider serving complex networks should face a mixed portfolio containing IPv4 and IPv6 resources, an autonomous system number, multiple authorized contacts and at least one dependent service.
The portfolio should include ordinary imperfections. One contact may be outdated but recoverable through a secondary channel. One resource may be excluded from the move. A reverse-DNS delegation may remain with the old provider while registration moves. Hosted RPKI may need to continue temporarily or transfer to the receiving registrar. These conditions test whether staff can distinguish a valid complication from a reason to freeze everything.
Annual variation prevents memorization. The registry operator can maintain scenario families and select a combination after reviewing each registrar's customer mix and past weaknesses. One year may emphasize holder authentication. Another may test a partial portfolio, a time-zone boundary or a lawful restriction affecting only one resource. The registrar should know the capability categories but not the selected case or start date.
The exercise must avoid contrived impossibility. It should not depend on a document that cannot legally be supplied or demand a dependent-service change outside the registrar's control. Difficulty comes from realistic coordination, not trick questions. A valid test gives the registrar every fact an ordinary competent provider would need, then observes whether it can identify and use those facts.
The annual cadence establishes a minimum, not a ceiling
One exercise each year is the qualification floor. A registrar should also test after a major service change, acquisition, platform replacement, key-custody change or merger of support teams. A provider that grows rapidly or fails a material migration may need more frequent assessment. The registry operator can select an additional drill when member complaints indicate deterioration.
Annual timing should be unpredictable within a disclosed window. A registrar knows that a drill will occur during its qualification year, but not the month, day or portfolio. This supports normal staffing and budget preparation without enabling temporary performance. The test can begin during a routine business period, an evening handoff or a regional holiday boundary, depending on the service promise the registrar sells.
The cadence should follow the registrar rather than the calendar. Qualification begins on a stated date, and a passing result must exist before renewal. A failed test does not reset the year. Remediation and retest occur within shorter deadlines, while the original failure remains in the published record for the applicable reporting period.
Repeated exercises should show learning. The assessor compares current performance with prior findings: export completeness, pause frequency, cutover accuracy, dependency continuity and compensation speed. A registrar that passes by narrowly avoiding last year's exact error but develops new systemic delays has not demonstrated mature portability. Annual evidence should reveal whether capability is stable, improving or eroding.
The test begins with an independently timestamped request
Every deadline needs a trustworthy starting event. The holder submits a signed request through an ordinary channel and receives a receipt that identifies time, resource scope and case reference. If the registrar fails to issue a receipt, the assessor's delivery evidence starts the clock. A provider cannot suspend accountability by declining to acknowledge the request.
The initial request identifies the unchanged holder, exact resources, proposed receiving registrar and desired transfer window. It distinguishes base registration from dependent services. It also identifies authorized representatives and protected notice channels. The registrar may request additional evidence only when published rules make that evidence relevant to a defined risk.
Within the first deadline, the losing registrar must confirm the current portfolio, identify active restrictions and state which services are coupled to each resource. It should not decide the receiving provider's eligibility; that belongs to the common qualification authority. Nor should it demand the holder's commercial reasons for leaving.
The receipt is more than customer support etiquette. It creates a version-bound point from which later changes can be judged. If a contact changes, a court order arrives or a resource becomes disputed, the record shows whether the event preceded or followed the request. The assessor can then distinguish genuine changed circumstances from an excuse assembled after delay began.
Identity verification must prove authority without creating captivity
Migration is high risk because an attacker could use portability to seize control. Strong authentication is therefore necessary. But security can become a pretext for captivity when only the incumbent can define what counts as proof and every failed attempt returns an unexplained rejection.
The test should require the same published assurance level used for comparable real holders. Evidence may include authenticated account access, independent confirmation through protected contacts, corporate authority documents and resource-specific approval. No single factor should be treated as conclusive for a high-impact portfolio. The registrar states which proposition each check supports.
If a check fails, the response must be actionable. “Identity mismatch” is limited public evidence. The holder needs to know whether the legal name, representative authority, resource scope, signature or contact confirmation failed, subject to security limits. A cure path and deadline follow. The clock pauses only for the affected check, not for unrelated export or dependency inventory that the registrar can continue.
The annual drill should occasionally use a legitimate recovery path rather than a perfect account. This tests whether a holder can leave after staff turnover, lost credentials or a changed legal name. The assessor ensures evidence is sufficient. A registrar passes by resolving the discrepancy safely and on time, not by weakening authentication. The objective is secure exit, not frictionless acceptance of any request.
Export quality is measured by reconstruction, not file delivery
A registrar can send a large archive that looks complete while omitting the facts needed to continue service. The migration test should therefore ask whether the receiving registrar can reconstruct the holder's recognized state, history and selected services from the delivered record plus common public evidence.
The export should include the resource list, stable holder reference, public and protected contacts as permitted, current provider appointment, relevant historic events, restrictions, pending requests, delegated administration and dependency declarations. Each record needs a version, issuer and integrity proof. Protected evidence may transfer through a controlled custody route rather than ordinary delivery.
Completeness is tested against independent reference counts and sampled events. Every resource in scope should appear once, excluded resources should remain clearly excluded, and parent-child relationships should remain intact. The receiving registrar confirms that it can interpret the record without asking the losing registrar to explain undocumented local fields.
Timeliness matters as much as format. A perfect export delivered after the cutover window can make exit impossible. The standard should set an initial delivery deadline and a shorter correction period for identified defects. If the losing registrar changes current data after export, it sends a signed delta so the receiving side does not prepare against stale state.
Delivery is complete only when the receiver acknowledges semantic usability. This does not give the receiving registrar a strategic veto. It must identify objective defects within its own deadline. The assessor resolves disagreement and prevents either provider from extending the test through vague claims of incompatibility.
Dependency discovery is a mandatory stage
Registration sits beside services that may affect operational continuity. The test must inventory RDAP publication, reverse DNS, RPKI certification or publication, abuse and emergency contacts, delegated user access, monitoring, billing-linked suspension rules and recovery channels. The holder decides whether each service moves, continues or ends, subject to technical and legal constraints.
An incumbent should not be allowed to call a dependency inseparable merely because it sells a bundle. If managed RPKI can continue under a separate agreement, that option should be visible. If it cannot, the registrar must explain the technical boundary and support a safe replacement. The same applies to reverse-DNS administration and delegated contacts.
RPKI deserves explicit testing because publication and relying-party observation have their own timing. RFC 8181 defines a publication protocol that supports publication, withdrawal and repository listing with integrity checks. A registrar migration does not automatically require a change in certificate authority or publication service, but the test must show that the selected arrangement remains valid and observable.
RDAP also requires a post-cutover check. The public record should identify the same holder and resource while showing the new registrar appointment at the accepted version. Reverse DNS should answer according to the holder's chosen plan. Routing may be monitored for unexpected change, but the registration transfer should not be declared failed solely because independent networks alter routes for unrelated reasons.
Deadlines need a hierarchy of clocks
One end-to-end target is necessary but limited public evidence. A registrar can consume almost the entire period before revealing a defect that could have been identified on the first day. Stage clocks create earlier accountability and make delay diagnosable.
The registry operator should define at least seven clocks: receipt, initial verification response, export, objection, dependency plan, readiness confirmation, and cutover proof. A standard portfolio might require receipt within minutes, initial verification within one business day, a usable export within two business days, objections within a fixed short window and final cutover within a small number of calendar days after readiness. Higher-risk portfolios can receive longer published limits without losing stage discipline.
Calendar and business time should be distinguished. Security notice may need continuous treatment. Corporate evidence review may depend on a jurisdiction's business day. The applicable clock is declared at request receipt, including time zone and holiday calendar. Providers cannot switch conventions after a deadline approaches.
Every pause must identify its legal or evidentiary basis, affected resource, start time, responsible party, required cure and expiry. Unrelated resources continue. Silence does not pause a clock. A registrar that waits for the holder without saying what it needs remains accountable for the elapsed time. These rules convert “we are reviewing” from an indefinite condition into a testable claim.
Objections must be narrow, evidenced and expiring
The losing registrar has legitimate reasons to entity: credible unauthorized instruction, resource mismatch, binding legal restriction, a pending holder dispute or evidence of fraud. It does not have a legitimate general veto because the customer owes an ordinary invoice, prefers a competitor or refuses to buy a bundled service.
The test should include at least one condition that could be mistaken for a valid objection. For example, one resource may carry a narrow stay while the rest of the portfolio is clean. A capable registrar isolates that resource, states the evidence and permits the others to proceed. A weak registrar freezes the entire account.
Objections expire unless confirmed. The registrar submits the ground, evidence class, resource scope and requested remedy before the objection deadline. An independent reviewer decides disputed grounds within a short period. Emergency protection can hold high-consequence actions, but it should not silently become permanent.
The annual score should distinguish a proper security intervention from delay. A registrar can pass despite stopping an unauthorized test request if it identifies the problem correctly, preserves service and supports review. The exercise is not designed to reward automatic approval. It rewards accurate, bounded decisions that protect both holder control and exit rights.
The receiving registrar must also be tested
Migration has two active service providers. The receiving registrar authenticates the holder, validates the export, prepares dependencies and accepts future duties. If it performs poorly, blaming the incumbent would distort the result. Every drill should therefore produce separate losing-side, receiving-side and shared-coordination findings.
The receiver must acknowledge the request, disclose requirements, test record usability and identify defects within deadlines. It must not demand that the holder recreate history already supplied in a verifiable common form. Nor can it alter holder identity, resource scope or restrictions merely because its own presentation differs.
Readiness means more than an account has been opened. Authorized users can access the proposed service. Contacts and resources match. Selected dependencies are prepared. Emergency support is available. The receiver knows the exact cutover event that will begin its authority and has not acted as current provider before that event.
Because every registrar will sometimes be the receiver, annual selection should rotate roles. A provider might face one complete outgoing test and participate in several incoming tests. Its qualification record should reflect both. Competition depends on the capacity to release customers and the capacity to receive them safely.
Cutover must preserve one current provider
The decisive event replaces the losing registrar with the receiving registrar for the listed resources at one accepted version. Before that event, the old registrar remains current. After it, the new registrar does. Preparation may overlap; authoritative control may not.
The assessor watches the preconditions: verified holder, usable export, closed objection period, approved dependency plan and receiving-side readiness. The coordinator then commits the provider change against the current version. A stale or duplicate instruction fails safely. The resulting receipt identifies prior and new providers, resources, unchanged holder and effective time.
The test checks for both gaps and overlap. There must not be a period when neither provider can handle an urgent registration matter. There must not be a period when both can submit authoritative changes. Read-only access for the old provider may continue for evidence retention, but its ability to change current state ends.
For a large portfolio, cutover can use declared batches. Each batch still has one atomic provider change and a clear outcome. A failed record should not leave half of one resource under each provider. The assessor confirms that clean batches proceed and failed batches retain their prior current state until corrected.
Proof must be independent of the provider's success message
A registrar should not grade its own migration. Completion evidence must combine the coordination receipt, before-and-after state, public observations, holder access and dependency checks. The assessor records exact times and distinguishes accepted cutover from later visibility through caches or repositories.
The holder should be able to sign in through the receiving registrar, see every migrated resource and use authorized contacts. The losing registrar should show that current authority ended and that no future recurring service charge applies unless a separate service continues. The public registration service should show the new appointment and preserve the event history.
Selected dependencies receive direct tests. RDAP is queried through recognized discovery. Reverse DNS is checked according to the declared plan. RPKI publication and relying-party visibility are observed where the exercise includes them. Emergency contacts receive a controlled challenge. Each result states whether the dependency moved, continued unchanged or ended as authorized.
The proof package should be durable enough for later review but minimize private data. Public reporting can show deadlines, pass criteria and failures without publishing authentication evidence or network details. The assessor retains protected evidence under a defined custody period. This separation lets members trust the result without turning a security exercise into a customer-data disclosure.
Failure compensation must be automatic
A failed exit creates costs even when no outage occurs. The holder spends staff time, the receiving registrar reserves capacity, and uncertainty may delay a corporate transaction or network change. If compensation requires a separate complaint and discretionary negotiation, the same institution that caused delay controls the remedy.
The registry operator should establish automatic compensation tied to observable failures. Missing receipt, late verification, unusable export, invalid broad objection, missed cutover, unauthorized overlap and dependent-service interruption each have a base amount. Duration increases payment after the applicable deadline. Higher-impact consequences receive additional amounts.
Automatic payment does not require proof of every loss. It is a minimum service remedy, much like automatic compensation arrangements used in other communications markets. Ofcom's automatic compensation framework demonstrates the consumer-protection logic: when specified service failures occur, payment should not depend on the customer starting another claim. The registry amounts and triggers would need to reflect number-resource risks rather than household broadband.
The payment goes to the test holder even though the portfolio is controlled. That prevents a free annual failure. A second amount reimburses reasonable receiving-registrar costs, and a third funds independent retesting. Compensation cannot purchase a passing result. The failure remains recorded and remediation remains mandatory.
Compensation should reflect duration, scope and consequence
A flat fee can become a cheap option to delay. The schedule should therefore combine a fixed trigger, a daily amount and consequence multipliers. A late acknowledgment receives a modest automatic sum. An invalid hold that delays an entire portfolio for weeks costs more. A service interruption, unauthorized change or security exposure attracts a higher multiplier.
Scope matters. Failure affecting one isolated low-risk resource differs from a broad portfolio freeze. The assessor counts affected resources and services without treating every address in a prefix as a separate incident. The schedule should be predictable enough to price risk while resisting artificial multiplication.
The minimum remedy should not extinguish claims for proven greater harm. If a real migration failure causes outage, contractual loss or emergency response costs, the holder retains ordinary legal rights. The automatic amount is paid promptly and set off only where law permits. It is not a liability waiver.
Repeated failure should increase both compensation and prudential requirements. A registrar with two failed annual tests may need a larger bond, more frequent exercises and supervised migrations. The escalating cost changes incentives: postponing portability investment becomes more expensive than fixing the capability. Members can see that weak exit service carries consequences before choosing a provider.
Payment security must survive registrar distress
Compensation is meaningless if the registrar fails when it is least able to pay. Qualification should require a ring-fenced reserve, bond, insurance arrangement or registry operator-backed guarantee calibrated to customer volume and service complexity. The resource should be callable on objective certification of a test failure.
The funding mechanism must avoid moral hazard. A common fund can provide automatic payment, but the failed registrar remains liable to reimburse it and pay a risk-based contribution. Strong providers should not permanently subsidize repeated failure by weak competitors. Published contribution rules and independent financial oversight are necessary.
Insolvency is the hardest case and the strongest reason to pre-fund. A distressed registrar may delay exits precisely when many holders want to leave. Compensation alone cannot solve capacity pressure, but available funds can support temporary assistance, receiving-provider costs and independent coordination while ordinary creditor claims proceed separately.
The reserve should not give registry-operator control of customer resources. Its purpose is remedy and continuity expense, not acquisition of registrars or portfolios. Release conditions, maximum uses and review rights should be set before distress. Financial preparedness then supports exit without converting the guarantor into a permanent service monopoly.
Public results should be informative without exposing attack paths
Members need more than a pass badge. The annual report should disclose test date range after completion, portfolio complexity class, total duration, stage deadlines, pauses, objections, export defects, dependency results, compensation and remediation status. It should show whether the registrar passed on the first attempt or after retest.
Security-sensitive details remain protected. Authentication factors, exact resource identifiers, staff names, recovery channels and key material do not belong in the public report. The independent assessor can provide fuller evidence to authorized reviewers. Redaction should not conceal the nature or duration of failure.
Comparability matters. Every registrar reports the same core metrics. Additional narrative can explain an unusual legal event or external dependency, but it cannot replace the score. Members should be able to compare median acknowledgment time, export defect rate, end-to-end migration time, invalid pause frequency and prior failures.
The record should persist across ownership change. A registrar cannot erase a failed test by changing its trading name or corporate parent. If service operations genuinely move to a different qualified institution, the successor receives its own assessment, while the predecessor's history remains attached to the period in which members relied on it.
Anti-gaming controls protect the value of the drill
Once annual testing becomes consequential, registrars will try to infer the test. A new holder with a small controlled portfolio, an unfamiliar receiving provider or a particular request month may attract special attention. Scenario variation and multiple eligible test holders reduce predictability.
The registry operator should also compare treatment. The assessor can sample contemporaneous real migrations, with permission and privacy safeguards, to see whether their queue times and defect rates resemble the drill. A registrar that passes the concealed test but systematically delays ordinary holders still fails the broader obligation.
Staff should not be punished for treating a test case normally. Incentives should reward reliable service across all cases, not detection of the examiner. Senior leaders receive findings after completion and are accountable for remediation. The identity of controlled holders can rotate, and receiving registrars should be selected from a qualified pool.
Collusion requires controls too. A losing and receiving registrar could stage a flawless exchange if both know the portfolio. The assessor limits advance information, monitors communications and preserves timestamps. Repeated pairings are avoided. Material undisclosed coordination invalidates the result and triggers a new test at the registrar's expense.
Proportionality should change complexity, not the right to exit
A small registrar should not face the same portfolio size as a global provider, but every registrar must demonstrate secure release, usable records, bounded objections and one-current-provider cutover. Proportionality adjusts exercise complexity and financial amounts. It does not excuse captivity.
Test classes can reflect customer count, resource volume, dependent services and criticality. A basic class uses a small portfolio and ordinary contacts. An advanced class adds mixed resources, delegated administration and selected security services. A critical class includes public-sector or infrastructure dependencies and tighter continuity observation.
Shared technical services are acceptable if responsibility remains clear. A small registrar may rely on a qualified export provider or common coordination service. The drill tests the combined service as the holder experiences it. The registrar cannot blame its contractor for a missed deadline, though contractual recovery may follow separately.
Proportionality also supports entry. A new provider can prove capability with a controlled portfolio before accepting many holders. Its limits expand after passing higher classes. This is more defensible than either excluding small competitors or allowing them to accumulate customers before anyone tests whether those customers can leave.
Public-sector and critical networks need a distinct scenario class
Some holders support hospitals, emergency communications, public administration, exchanges or essential utilities. Their migration must account for maintenance windows, procurement controls, multiple authorized officials and heightened continuity needs. A generic small-business test will not reveal whether a registrar can serve them safely.
Registrars that market to these holders should pass a critical-service scenario. The exercise can use reserved resources and simulated dependencies rather than a live essential network. It tests after-hours escalation, multi-party authority, phased cutover, rollback readiness and communication across jurisdictions.
Deadlines may be longer where public approval is genuinely required, but impact tolerances should be stricter. The Bank of England's operational-resilience approach offers a useful cross-sector principle: identify important services, set tolerable disruption and test whether severe but plausible conditions remain within that tolerance. The registry implementation would apply the principle to registration continuity rather than financial regulation.
The critical class should also test partial isolation. A lawful restriction on one resource cannot freeze every public service held by the same organization. The registrar must preserve protected authority while enabling clean resources to proceed. Success demonstrates not speed alone but disciplined continuity under constraint.
Court and dispute conditions belong in the exercise library
Legal restrictions are a predictable migration risk. An annual drill should sometimes include a valid simulated stay issued under the exercise charter. The registrar receives a document through its normal legal channel and must identify scope, effective time, duration and affected act.
A capable response does not obey the document blindly or ignore it. Legal staff authenticate the source, determine whether it binds the registrar or holder, preserve evidence and apply the narrowest warranted hold. The holder and receiving registrar receive a notice that explains the operational effect without exposing protected material.
The scenario can include a challenge or expiry. When the stay lifts, the paused resource resumes from a known state without restarting clean migrations. If review finds the hold invalid, the test measures correction time and compensation. This reveals whether legal handling is integrated with portability or exists as an indefinite side queue.
No fictional court document should resemble a real order or name a real dispute. The charter establishes its validity solely within the controlled exercise. The objective is to test recognition, isolation and continuity, not the registrar's willingness to disregard law. Published results state that a legal-condition scenario occurred but need not disclose the exact fact pattern.
Escrow is necessary but does not prove migration
Regular deposits can preserve registration information if a registrar fails. ICANN's Registrar Data Escrow Program illustrates how periodic deposits and approved custodians can support continuity. Escrow is valuable, but it answers a narrower question than the annual migration drill.
A deposit may be complete and still be difficult for a receiving registrar to use quickly. It may not include current dependency choices, recent events or the authority needed to cut over. Release may depend on a formal trigger that does not apply to an ordinary voluntary exit. The holder may have no direct way to test the deposited record.
The drill should compare the ordinary export with escrow evidence where permitted. Counts, versions and selected records should reconcile. A discrepancy becomes a remediation finding even if the live migration succeeds. The assessor also checks that escrow custody does not create an excuse to withhold portable records during ordinary service.
Escrow protects against loss of data. Migration testing protects against loss of practical exit. Both are needed. One preserves information under failure; the other demonstrates that institutions can authenticate, transfer, assume authority and continue service while the incumbent still exists.
Remediation must have deadlines and independent closure
A failed test should produce a short list of decisive findings, each tied to evidence and consequence. The registrar submits a remediation plan quickly, but a plan does not restore qualification. The assessor verifies fixes and conducts a new concealed migration within a defined period.
Some failures require immediate restriction. Unauthorized dual authority, loss of holder evidence or dangerous dependency termination may justify pausing new customer intake until corrected. Lesser delay can allow continued service under supervision. Existing holders remain protected and able to leave; restriction should not trap them.
Retesting should vary the scenario. Repeating the identical case rewards memorization. The new exercise targets the failed capability while also checking the complete path. Compensation from the first failure remains payable regardless of later success.
Independent closure prevents management from declaring its own fix complete. The assessor confirms changed behavior through evidence. The review body hears disputes over findings and sanctions, but ordinary appeal does not suspend urgent safeguards. Published status shows failed, remediation due, retest scheduled, passed on retest or qualification restricted.
Repeated failure should change market access
Qualification has little meaning if every registrar remains fully eligible after repeated failure. The registry operator should use an escalating ladder. A first failure triggers compensation, remediation and retest. A second material failure within a defined period increases financial security, supervision and test frequency. A third can restrict new customer acquisition or complex-service offerings.
Persistent inability to release holders safely should end registrar qualification through a reasoned decision. An orderly transition plan then moves remaining customers, preserves records and avoids a sudden mass outage. The registrar has review rights, but member continuity comes first.
Sanctions should focus on capability and conduct, not size or politics. A provider that reports its own defect, protects customers and fixes it promptly may receive different treatment from one that conceals delay, alters evidence or retaliates against a test holder. Automatic compensation still applies because the service failed.
Market consequences are part of accountability. Published results allow holders to choose providers with demonstrated exit performance. Insurers and guarantors can price repeated failure. Receiving registrars can prepare for weak counterparties. The annual test thus creates incentives before formal sanctions become necessary.
A sample migration shows what passing means
On the first day, the controlled holder submits a request to move two prefixes and one autonomous system number while leaving a third prefix with the incumbent. It asks to continue reverse-DNS service for a short period and move hosted RPKI publication at cutover. The request receives a version-bound receipt through the ordinary channel.
The registrar authenticates two representatives, discovers that one public contact is stale and confirms authority through the protected secondary channel. It exports the complete selected portfolio, identifies one historic restriction that has expired and states that an active billing disagreement does not block transfer. The receiving registrar finds one missing event reference; the incumbent corrects it within the defect window.
During notice, the test introduces a narrow legal hold affecting only one prefix. The registrar isolates that prefix and allows the autonomous system number and clean prefix to continue. Both providers prepare the selected dependencies. At cutover, one ordered event changes the current provider for the clean resources. The held prefix stays with the incumbent.
The assessor verifies public registration, receiving-side access, reverse-DNS continuity and RPKI observation. When the simulated hold expires, the final prefix moves through a separate event. All stage and end-to-end deadlines are met. No compensation is due. Passing means the registrar handled imperfection correctly, not that the test contained no friction.
Measurement should focus on holder outcomes
The primary measure is end-to-end time from verified request receipt to proof complete. Stage measures explain that result: acknowledgment, verification, export, defect correction, objection, readiness and cutover. The report also counts manual interventions, unexplained pauses and senior escalations.
Quality measures include export completeness, resource-scope accuracy, holder continuity, dependency outcome, absence of dual authority and public-record consistency. Security measures include correct authentication, response to suspicious changes and protection of private evidence. Remedy measures include compensation calculation and payment time.
The registry operator should record whether the migration would have succeeded without assessor intervention. A monitor may ask for evidence, but it should not manage the case. If the assessor has to tell staff which department owns export or remind them that a deadline expired, the registrar has not passed ordinary-service capability.
Member experience matters too. Notices should be understandable, requirements stable and review routes visible. A technically successful transfer can still be abusive if the holder receives contradictory instructions or is pressured to withdraw. The annual drill should score clarity and non-retaliation alongside technical continuity.
The test strengthens rather than weakens security
Registrars may argue that predictable portability helps attackers. Poorly designed portability would. A rigorous migration test does the opposite: it tests representative authority, independent confirmation, version binding, notices, narrow objections and one-current-provider cutover under observation.
Security controls become dangerous when they have never been exercised with exit. A recovery channel may work for login but fail to authorize provider change. A fraud team may know how to freeze an account but not how to isolate one resource. A legal team may impose holds without expiry. The drill reveals these mismatches before an attacker or crisis does.
Anonymity also tests whether controls apply consistently. Staff cannot weaken checks for a favored customer or strengthen them to delay a departing critic when they do not know the assessment case. Independent evidence makes both premature approval and abusive denial visible.
The correct security objective is authorized, observable and reversible handling of error, not immobility. A holder that can never leave is not secure; it is captive to the incumbent's own compromise, insolvency and mistakes. Tested exit diversifies institutional risk while preserving strict control over who may request change.
The annual drill gives members enforceable evidence
Members usually learn about exit quality only after choosing a registrar. Complaints arrive as anecdotes, often under confidentiality, and providers explain that every case was exceptional. A common annual test creates comparable evidence before the next holder makes that choice.
The evidence also improves governance. Member representatives can see whether fee income supports portable records, trained staff, dependent-service continuity and compensation reserves. They can question repeated manual intervention or poor after-hours response. Review bodies can distinguish one-off error from chronic weakness.
Courts and public authorities gain a clearer record too. When a dispute concerns delay or service continuity, stage receipts and published limits narrow the factual questions. Automatic compensation resolves a baseline remedy without requiring full litigation. Protected authentication and legal evidence remain available under proper authority.
Most importantly, the test changes the burden of proof. Holders no longer have to demonstrate after harm that exit was impractical. The registrar must demonstrate each year that ordinary service can release a realistic portfolio safely. Qualification becomes an evidence-backed privilege rather than a permanent label.
Conclusion
Exit rights become real only when institutions can perform them under ordinary conditions. A clause, policy page or data deposit cannot prove that a holder will receive a timely acknowledgment, usable record, bounded objection, safe dependency plan, one-current-provider cutover and independent proof. An annual concealed migration can.
The exercise should be legitimate, controlled and demanding. The holder and resources are real within the assessment arrangement. Authority evidence is truthful. Service staff simply do not know that this ordinary-looking request will determine the registrar's annual portability result. Scenario variation prevents theater, and safeguards prevent risk to unrelated holders.
Binding clocks turn delay into an observable failure. Automatic compensation gives failure a cost without forcing another complaint. Public metrics let members compare providers. Retesting proves remediation. Escalating restrictions prevent repeated failure from becoming an accepted business model.
The deeper purpose is institutional balance. Number-resource uniqueness requires one accepted current authority, but that requirement must not become incumbent captivity. A registrar earns trust by protecting the holder while it serves and releasing the holder safely when service ends. The migration test makes both duties visible. Every registry-service operator should have to pass it before asking members to believe that exit exists.
NRS and BTW role sources
- Number Resource Society — NRS's own public positioning as a global non-profit membership organization that campaigns, supports businesses and represents members in RIR governance.
- Heng Lu, “On Why NRS Exists — and Why Decentralization Is No Longer Optional” — the source doctrine defining NRS as an advocacy group, not a product vendor or commercial implementation body.
- Heng Lu, “On Why BTW.Media Exists — and Why Reality, Not Advocacy, Is the Product” — the editorial boundary requiring BTW to describe observable structure and proposals without campaigning for them.

