
2025 is coming to an end, and we want to pause to reflect on our achievements this year as part of the NRO RPKI Program.
A significant achievement was submitting the first draft specification to address concerns about RPKI Trust Anchors (TAs) claiming resources for which they are not authoritative (read more about this milestone). After presenting this draft to the SIDROPS IETF Working Group during the IETF 124 meeting, the RPKI Steering Group received input from the technical community and engaged with various stakeholders. The group is now discussing options for the next draft version. Look for updates in the new year and join the SIDROPS mailing list to participate in the discussions.
Additionally, we published a series of joint RPKI baseline documents. The first document outlines the process of creating ROAs through each Regional Internet Registry (RIR) portal and is covered in a previous blog article. The second document provides an overview of RPKI services and features currently offered by each RIR.
Following up on the core RPKI services and features shared in a previous blog article, we have now published a roadmap for these services to be offered by all RIRs. Notably, all RIRs are committed to supporting Autonomous System Provider Authorizations (ASPAs) by the end of 2026. RIPE NCC has released a new version of their RPKI system supporting ASPAs, and ARIN has activated ASPA functionality in their Operational Test and Evaluation Environment for testing. As part of the RPKI Program, RIRs will continue coordinating on ASPA support implementation.
Other useful documents published this year include the RPKI Content Repository and a summary of RPKI best practices and lessons learned.
From the NRO RPKI Program, we express our gratitude to all members of the Internet community who shared their thoughts, ideas, and feedback, either proactively or in response to requests. This input helps us ensure that the resources we produce and the work that we do are comprehensive and useful for all RPKI implementers.
Why this matters for routing security
RPKI is a critical building block for improving the security and resilience of the Internet routing system. It helps prevent route hijacking and misorigination, situations where Internet traffic is accidentally (or intentionally) routed through the wrong network.
ROAs are a key component of RPKI. A ROA is a digitally signed statement that authorizes a specific Autonomous System Number (ASN) to originate routes for a given set of IP prefixes. When network operators create ROAs for their prefixes, other networks can validate the corresponding Border Gateway Protocol (BGP) routes and make better decisions about which ones to accept.
Despite RPKI’s importance, adoption is still a work in progress. A common challenge for operators who interact with multiple RIRs is navigating operational differences. Each RIR has its own member portal, terminology, and process for creating and managing ROAs. These differences can be confusing and time-consuming for newcomers and multi-region operators. That’s where the NRO reference page helps.
Beyond convenience, this initiative supports a broader goal: enhancing consistency in RPKI service provision across the RIR system. The five RIRs collaborate closely on RPKI, yet natural variations exist, shaped by regional policies, historical systems, and member needs.
A single reference point for all RIRs
The new NRO page doesn’t attempt to replace or rewrite any of the RIRs’ existing documentation. Instead, it acts as a trusted index, providing direct pointers to where each process is explained in detail by the RIR itself.
This approach keeps each RIR’s website as the source of truth, while reducing friction for anyone asking, “Where do I go to create a ROA?”
The page includes links to:
- Official ROA creation documentation for AFRINIC, APNIC, ARIN, LACNIC, and RIPE NCC.
- Contact or support pages where operators can reach their RIR for help.
- A high-level summary of process differences across RIRs.
By consolidating these resources, the NRO aims to make it easier to get started, simpler to compare processes, and quicker to take action to secure your routes.
What comes next
This page is part of a broader effort under the NRO RPKI Program to document, analyse, and improve consistency in RPKI implementations across the RIRs. Additional documents and comparative analyses are planned to give the community a clearer, data-driven view of how RPKI services are operated and where alignment could bring the most benefit.
As with all work in this space, community feedback is essential. The NRO encourages network operators, researchers, and security experts to explore the page and share thoughts on how it could be made more useful. If you have suggestions, questions, or ideas for improvement, please reach out to [email protected].
Sofia Silva Berenguer is the RPKI Program Manager for the NRO.
This post was originally published by MANRS.

Sofia Silva Berenguer
Author • RPKI Program Manager, NRO

