Summary
- SSAC members are screened by an SSAC Membership Committee, approved by full SSAC and formally appointed by the ICANN Board. Members participate as individuals, but the public procedure deliberately manages conflicts through disclosure rather than exclusion.
- SSAC advice is not a command. Its rules deny regulatory, enforcement and adjudicatory authority. The practical power lies earlier: selecting experts, defining a security problem and producing the first complete evidence frame that a Board or operator must later accept, qualify or reject.
- Confidential deliberation can protect vulnerability and proprietary evidence. The present public record does not routinely show issue-level participation decisions, reasons for withdrawal, abandoned work or draft-to-final changes. That is an audit gap, not proof of misconduct.
The appointment record is unusually clear
The ICANN Board resolution of 25 January 2026 records the route by which Wes Hardaker, Sourena Maroofi and Raffaele Sommese joined the Security and Stability Advisory Committee. The Membership Committee recommended them to full SSAC on 25 November 2025. SSAC approved the recommendations by consensus on 10 December. The Board then appointed all three through 31 December 2028.
The resolution supplied biographies and affiliations. It also called the appointment an organizational administrative function for which public comment was not required. The Board said the additions would take SSAC from 37 to 40 members at that time. The current public roster displayed 41 results when captured for this article. Those figures are dated institutional counts. They do not measure who actively drafted a report or influenced a particular recommendation.
The sequence matters because it separates three forms of authority. The Membership Committee controls the first evidentiary screen. Full SSAC decides whether a candidate should carry its recommendation. The Board performs the formal appointment under the Bylaws. None is an election by Internet users, number-resource holders, registries, registrars or network operators as a class.
The Bylaws reinforce the structure. Members receive three-year terms. They may be reappointed without a limit on the number of terms, and roughly one-third should be considered each year. The Board may remove an appointee as recommended by, or in consultation with, SSAC. The design preserves specialist knowledge. It also permits a small appointment system to reproduce itself over long periods.
That is not evidence of capture. It is evidence of a lock-in mechanism worth auditing.
The candidate gate is more closed than the final resolution
SSAC Operational Procedures version 12 describes what precedes the Board record. The Membership Committee contains the SSAC Chair, Vice Chair and Board liaison as non-voting members, plus five volunteering SSAC members who vote. Four voting members form a quorum. The committee generally seeks unanimity, while voting details other than the outcome remain inside the committee.
Applicants provide a curriculum vitae, a statement, a skills questionnaire, a disclosure of interests and links to relevant work. The committee asks whether a candidate understands SSAC, can devote time and supplies a needed skill. It also considers relationships inside and outside ICANN and geographic, gender and other diversity.
If the committee does not recommend a candidate, the name is not disclosed beyond the committee. An appeal is handled case by case by the Chair and Vice Chair, whose decision is final. The candidate must wait at least twelve months before applying again.
A recommended candidate faces a second gate. Full SSAC receives the supporting material and at least one week to object. An objection must state grounds and interrupts the ordinary path. The Chair moderates the review and declares the SSAC consensus position. Before the Board acts, the candidate participates as an Invited Guest.
Nothing in the captured material shows that a candidate was excluded for an improper reason. Nothing supplies current totals for applicants, committee rejections, full-SSAC objections, appeals or reversed decisions either. The defensible finding is narrow: outsiders can read the criteria, but they cannot test the distribution or consistency of outcomes.
This distinction is essential. Secrecy is not proof of abuse. A process that does not publish outcome data is still harder to evaluate than one that does.
Individual capacity does not remove institutional relationships
The procedures say members participate as individuals, not as representatives of their employers or other organizations. That is a formal boundary. It means a biography listing Google, a university, a root server, RSSAC, the IETF or another technical body does not establish delegated representation.
The same procedures acknowledge that members' views will be influenced by organizations with which they interact. Their conflict control is explicit and unusual: the ICANN Board conflict-of-interest policy is described as inappropriate for SSAC members. The primary responsibility is not to eliminate conflicts or exclude people from discussion. It is to disclose interests and be transparent about relationships that might be perceived as influencing a view. Advocacy for a specific interest or position is acceptable if the interest has been disclosed.
That is not a loophole hidden in small print. It is the committee's chosen theory of specialist governance. Scarce technical knowledge often arrives with operational, commercial or institutional ties. Excluding everyone with relevant experience could empty the room. Disclosure is meant to let the room retain expertise while exposing the relationship.
The adequacy of that choice depends on the record it produces. Each member must file or update a disclosure at least annually and after a material change. Members must highlight relevant interests during discussion. A verbal disclosure during a meeting should be recorded in the meeting record. Each report must link to the member disclosures current when it was published.
Public biographies and dated archives are useful. They do not, by themselves, show whether a member raised a particular interest on a particular report, whether participation was limited, who decided, or what non-sensitive reason supported that decision. An affiliation list describes the potential surface. It is not an issue-level decision log.
Confidentiality protects evidence and hides the test
Most SSAC deliberations are confidential unless explicitly opened. The procedure gives a serious reason: members may share security-sensitive or proprietary information. A public meeting can deter the owner of a vulnerability from speaking or expose a system before a mitigation exists.
Confidentiality therefore cannot be assessed as though it were merely institutional convenience. It is part of the committee's ability to obtain evidence.
It also changes what can be tested. A work-party chair coordinates the draft and declares consensus. Staff may research, prepare a concept paper, edit, or be credited as a contributing author or researcher. If participants cannot agree on one view, the discussion should present multiple perspectives and should not attach a recommendation to a position lacking consensus.
A dissatisfied member may accept the work-party consensus call or withdraw. The public document need not state or discuss the reason. Full SSAC later reviews the draft. If final consensus fails, the work stops and is recorded internally as abandoned. If consensus succeeds, staff formats the report. A member may again withdraw for an unspecified reason and appear only in the withdrawals section.
This is a functioning decision rule, not evidence that dissent is suppressed. The audit limitation is visible: a reader may learn that someone withdrew, yet not whether the reason was technical disagreement, an interest, a procedural objection or something else. A reader may never see a project that was abandoned before publication. Confidentiality preserves the evidence room while concealing part of the path by which the institution chose its final claim.
Two reports show what the public layer can and cannot do
SAC125, on registrar nameserver management, and SAC132, on the dependence of the DNS on free and open-source software, supply worked cases. Both identify contributors and support staff. Both contain dissent and withdrawal fields. Neither lists a withdrawal.
SAC125 links to the live member biography and disclosure page. SAC132 uses a dated 16 May 2025 archive, which is better evidence of what affiliations were published when that report appeared. Neither report presents a versioned history of consequential claims, a table of issue-specific disclosures, or the handling of participation decisions inside confidential deliberation.
The difference matters. Public attribution is not empty. It lets readers see who contributed and inspect published relationships. It is still a different instrument from a conflict disposition record.
The historical review record reaches a similarly bounded conclusion. In 2018, an independent examiner reported that conflicts were unavoidable in a specialist body, described formal and informal disclosure and recusal practices and found no undue external influence in that assessment. Its conflict chart drew on fifteen SSAC respondents. Recommendation 29 called for preserving disclosure practice and publishing the date of each member's latest statement.
SSAC later reported that biographies and individual disclosure dates had been updated and that accepted recommendations were completed or integrated into its procedures. The Board accepted the final implementation report in 2021 and encouraged continued impact monitoring. That proves the review and implementation sequence. It does not turn a historical survey or a project-completion label into a current outcome test.
The third organizational review was deferred in 2022. ICANN's status page says the Board confirmed in May 2025 that organizational reviews would remain deferred until the first Continuous Improvement Program cycle is complete. There is therefore a current gap in independent outcome testing. A gap is not a failure finding. It is a reason to avoid using the 2018 conclusion as a 2026 warranty.
Advice ends before implementation
The Bylaws authorize SSAC to advise, communicate, assess risk and make policy recommendations. The Operational Procedures state more bluntly that SSAC cannot regulate, enforce or adjudicate. The effect of its work depends on the quality of the advice and whether others accept and follow it.
This formal limit should not obscure the practical influence of first framing. A specialist committee can decide which risk receives institutional attention, assemble evidence unavailable elsewhere and produce the first complete account a later decision-maker must rebut. Security language can raise the reputational cost of delay. Direct Board access can shorten the route from warning to agenda.
But those mechanisms are not command. An ICANN page describes five phases for receiving, understanding, considering, implementing and closing advisory-committee recommendations through a central repository. A status in that system proves processing. It does not prove acceptance, causal effect or who absorbed implementation cost.
For number-resource holders, the relevance is indirect. SSAC cannot issue an ASN or prefix and cannot set RIR policy. Its advice can still affect the assumptions under which registries, registrars, DNS operators and the ICANN Board treat system risk. The evidence must be traced across four separate transitions: who entered the committee, who framed the claim, what SSAC approved, and what downstream actor chose to implement.
Sources
- ICANN Bylaws
- SSAC Operational Procedures version 12
- Current SSAC page and application process
- Current SSAC member roster
- ICANN Board appointments of 25 January 2026
- SAC125: SSAC Report on Registrar Nameserver Management
- SAC132: The Domain Name System Runs on Free and Open Source Software
- 2018 independent SSAC review
- SSAC2 final implementation report
- ICANN Board acceptance of the final implementation report
- Current SSAC review status
- ICANN recommendations-to-the-Board workflow
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
