Acquisition closed on9 September2026. The historical source family is identified; DoubleVerify's exact three years, files, filters and provider-to-domain mapping remain unestablished.
The retained13 February2025 DoubleVerify announcement says it reviewed three years of public NCMEC data as a starting point, analyzed over300 domains/electronic service providers that had received CSAM-related notices, cross-referenced existing classifications, and conducted site-by-site analysis for the remainder while excluding large, well-moderated social/search services. It does not identify those years or the files and columns used.
Those qualifications matter. This investigation has not established that DV equated every NCMEC row with illegal content, nor that it confined its inputs to the CSAM column. Its own claimed additional analysis is part of the transformation to be tested. NCMEC's publication of data does not establish endorsement of DV's category or a direct data-supply agreement.
The [2023 Reports by ESP table](http[local research file] PDF1, counts reports providers submitted to the CyberTipline about suspected exploitation/apparent CSAM on their systems. It says volume and content vary because the reporting framework did not then require proactive detection or prescribe the information to include. An incoming report count is not a count of outbound NCMEC notices, unique victims, confirmed incidents or criminal domains.
The currently hosted2023 annual report, PDF7, adds that higher reporting may reflect robust detection/removal, and that inadequate reports can add volume without helping an actionable investigation. Its current file was modified after DV's announcement, so this passage is supportive methodological explanation, not a proven byte-for-byte historical input.
The [2021 outbound table](http[local research file] and [2022 outbound table](http[local research file] each PDF1, describe NCMEC visually reviewing imagery reported by victims, caregivers and, expressly in2022, INHOPE hotlines, then notifying relevant providers. These are more specific than unreviewed incoming report totals. They still record notification activity and response, not final court findings about whole domains.
Both the [responsive](http[local research file] and [unresponsive](http[local research file] tables explain their three categories on PDF1: CSAM; exploitative content depicting identified child victims that does not meet the legal CSAM definition; and predatory text involving sexual comments or personal information about identified victims. Those categories must remain separate. A total across them cannot simply be labelled confirmed criminal CSAM.
NCMEC says staff review the imagery, notify the provider, manually track status and send additional notices until content is addressed. The responsive introduction says company terms may lead to imagery removal or user blocking. Its table reports notifications and average days to respond/takedown, by category and total. The unresponsive table reports notification counts without response-time columns. Neither introductory methodology defines the counting unit as a unique incident, file, victim or site; repeat notifications expressly prevent treating it as such.
The combined response/takedown heading should not be silently rewritten as a pure time-to-removal metric. The2021 footnote, PDF10, says some removal times are unavailable after unsuccessful notification efforts and NCMEC seeks other options such as contacting upstream providers. The2022 footnote, PDF12, makes clear that missing times can concern some notices, even where a provider has a numerical average for others. The tables do not provide a universal deadline, a causal explanation for every nonresponse, or the underlying notifications.
The same named provider can appear in both2023 tables. CloudFlare, Inc appears on responsivePDF4 with5,183 notifications across the three categories and an average of1.53 days, and on unresponsivePDF1 with7 CSAM notices. These are separate published aggregates, not a current rate or a count this inquiry independently audited. This example disproves a reading of the headings as permanently exclusive whole-company labels. Alibaba likewise appears in both (responsivePDF2, unresponsivePDF1). The notices' dates, subjects and reasons for differing outcomes were not acquired; no individual notice is inferred.
Rows mix provider names, domains and grouped services. The explicit upstream-contact route cautions against converting a hosting/infrastructure recipient directly into the offending destination site. The relevant entity-to-domain and content-location mapping has to be established separately. No listed site was visited.
The current NCMEC archive page retained in the earlier PhotoDNA wave links2021 and2022 notification tables and the2023 split tables. Those links establish the archive's present organization, not its exact state on13 February2025.
| Artifact acquired now | Date evidence in the original | What can be concluded |
|---|---|---|
| 2021 notification table | Copyright2022; PDF created/modified22 March2022 | A historical2021 table with pre-announcement file metadata; first public upload not independently established. |
| 2022 notification table | Copyright2023; PDF created/modified1 May2023 | Same limited chronology conclusion; not proof DV selected it. |
| 2023 responsive/unresponsive tables and Reports by ESP | Copyright2024; PDF created/modified12 April2024 | Plausible public-source candidates before DV's announcement; exact historical public versions/selection not established. |
| 2023 annual report currently hosted | Created15 April2024; modified3 June2025 | Current bytes cannot be assumed identical to the version available in February2025. No specific content change identified. |
| NCMEC2024-data release post | Dated8 May2025 | This acquired release is later than DV's announcement and cannot establish what DV had on13 February. |
PDF metadata is document metadata, not an authenticated publication log. This packet does not declare2021-2023 to be DV's three years, or assume all2024 annual data were unavailable in February2025.
The official 5 February2024 post.
The separate hash-sharing programme is not the same resource as these public provider/notification tables. The previously acquired15 April2024 NCMEC audit announcement concerns reviewed image/video hashes. Its assurance about that resource cannot certify a separate advertising domain list or identify DV's input files.
One reading consistent with DV's account is that it used historical outbound-notice tables, filtered relevant CSAM notices, resolved provider/domain identities and applied additional classification judgment. Another possibility is broader use of totals or provider membership across heterogeneous categories. The acquired originals establish why those choices matter, but do not establish which occurred. Nor does the existence of responsive notices erase the potential relevance of underlying harmful material; response performance and content risk are different questions.
The high-value missing record is DV's dated source inventory and transformation specification: exact NCMEC URLs/versions/years; included columns and responsive/unresponsive treatment; repeat-notice handling; provider/domain resolution; exclusions; and the provenance for final category decisions. The next archival record, if needed, is a dated public snapshot of the selected NCMEC files. Neither requires access to illegal imagery or private CyberTipline reports.
Eight new originals were acquired by ordinary unauthenticated GET, all200: six PDFs and two HTML posts. input-get.json and input-date-get.json retain transport/metadata; input-captures.json records SHA256 and reading scope. No acquisition route failed or was retried. A few focused discovery searches returned current NCMEC pages, unrelated material and public dates; no unrelated branch was opened.
Actual table scope:2021 PDF1 and final-page10 footnote/totals;2022 PDF1 and final-page12 footnote/totals;2023 responsivePDF1, selected AlibabaPDF2 and CloudFlarePDF4 rows, and final-page22 totals;2023 unresponsivePDF1 and final-page4 totals, with intervening text visible in extraction but no claimed complete row audit;2023 Reports by ESP PDF1 introduction/header only. The key2023 headers/CloudFlare rows and2021/22 footnotes were visually checked in retained PNGs. No row totals were recalculated across years or treated as a prevalence denominator.
The annual report was keyword-scanned; selected extractedPDF7,12-13,15-16 were read, with onlyPDF7 and12-13 material used for this question and the modification-date caveat retained. Both dated posts' complete substantive text was read; embedded videos/forms were not used. The prior DV announcement's whole substantive body and the prior NCMEC archive links were read locally. Acquisition now stops for combined review; no case, reader, ZIP or operational data was changed.