Summary
- The RIPE NCC Annual Report 2025 (ripe-855, published 17 April 2026) reports 2,320 abuse-c validation investigations in 2025 — 801 LIR accounts, 764 LIR resources, 755 End Users — against 2,366 in 2024, and states that all abuse-c addresses were successfully validated to comply with RIPE-705.
- The 2025 enforcement list in the same report — 220 hijack investigations, 19 police reports, 13 due-diligence warnings, 1 disputed transfer and 3 SSA terminations for untruthful information — attributes no closure to abuse-c non-compliance.
- The Activity Plan and Budget 2026 (ripe-850, approved 11 December 2025) automates abuse-c warnings and extends monitoring to roughly 20,000 End Users without adding any enforcement mechanism.
Three recent reports on this site documented the abuse-contact regime's structural gap using 2017–2019 data: validation proves a mailbox is reachable, not that anyone answers; the escalation ladder is documented but its use uncounted; and the final sanction — member closure and resource deregistration — had never publicly fired. The 2026-dated record now lets that question be asked against current numbers rather than a seven-year-old baseline.
What the 2025 record quantifies
The Annual Report 2025 gives the regime its most complete public accounting yet. Alongside the 2,320 investigations, it records 86,959 validated abuse-c email addresses in 2025 versus 83,509 in 2024, with 899 addresses requiring manual intervention (851 in 2024); abuse-c role objects created or updated fell from 102,939 to 77,086; and the NCC completed 2,825 Assisted Registry Checks against a target of 2,400. The report's own prose says it "carried out more than 2,300 abuse-c validation investigations" — a framing that rounds over its own charted total, a small tension that matters only because it shows how much of the record is summarised rather than enumerated (ripe-855, documents/4258 copy).
The trajectory is consistent with a maturing system: investigation volume essentially flat year on year, role-object churn falling by a quarter, and a completeness claim — all addresses validated to RIPE-705 — delivered without case-level evidence. Detection is working, or at least it is reporting. What the same report's enforcement section shows is a different shape: every listed outcome — hijack investigations, police reports, due-diligence warnings, a disputed transfer, three SSA terminations for untruthful information — belongs to other misconduct. None is attributed to abuse-c non-compliance.
The ladder, unchanged
The procedure that abuse-c failures feed into was re-edited on 7 May 2026, but the edit removed postal-mail reminder steps and touched nothing else: persistent non-compliance still runs a three-month termination clock on the membership agreement, followed by deregistration of the internet number resources and revocation of RPKI certificates (ripe-858). The policy mandate itself is unchanged — at least annual validation of the abuse-mailbox attribute, with follow-up where it is deemed incorrect (ripe-705). The automated check tests syntax, domain and mail-server configuration; it sends no email and cannot observe whether a report arriving in a valid mailbox is ever read (2017-02).
The institution's own historical baseline remains what it was: the 2017-02 proposal records the RIPE NCC's statement that it had investigated and resolved more than 1,000 external reports on incorrect abuse-mailbox attributes over five years "without ever having to trigger the closure and deregistration procedure." The 2025 report does not contradict that record; it simply does not extend it. No published count of escalations opened, and no published closure, exists for the validation era as a whole.
2026: automation without enforcement
The Activity Plan and Budget 2026, approved on 11 December 2025, keeps the 2,400 Assisted Registry Check target, extends automated monitoring to around 20,000 End Users with independent resources, and has Member Services "following up on all automated warnings regarding abuse-c" (ripe-850). This is front-end investment. It makes detection cheaper and faster at precisely the stage where the record shows volume and competence — and adds nothing to the stage where the record shows nothing at all.
The 2019-era follow-up mechanics explain why the tail is structurally hard to reach: reminders run a week apart, staff take over about three weeks in, and only LIR organisation objects can escalate toward closure — for LIR resource and End User objects the written sanction is a database comment, not termination (Labs, 2019; Labs, follow-up). Whether the dormant last resort reflects genuinely compliant members, informal resolution before escalation, or pressure that is simply never counted cannot be distinguished from the public record. That is the finding, not an excuse for it: a sanction whose use is invisible cannot serve as evidence of either deterrence or health.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

