PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #3 – Internal Audit
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: pkioverheid, Assigned: pkioverheid)
Details
(Whiteboard: [ca-compliance] [audit-finding])
Preliminary Incident Report
Summary
- Incident Description:
- Minor Non-conformity: Internal Audit at subcontractor
- Relevant Policies:
- ETSI 319 401 (REQ-7.1.1-01, REQ-7.13-01, REQ-7.14.3-06X)
- ETSI 319 403-1 (7.9d)
- Source of incident disclosure:
- Annual ETSI Audit
Updated•1 year ago
|
| Assignee | ||
Comment 1•1 year ago
|
||
Full Incident Report - ETSI Finding #3 – Internal Audit
Summary
-
CA Owner CCADB unique ID: A000068
-
Incident description: The CAB noted that a required internal audit had not been performed at a KPN subcontractor. This was filed a minor non-conformity.
-
Timeline summary:
-
Non-compliance start date: N/A
-
Non-compliance identified date: 11-Jul-2025
-
Non-compliance end date: Ongoing.
-
-
Relevant policies:
-
ETSI 319 401 REQ-7.1.1-01: The TSP organization shall be reliable.
-
ETSI 319 401 REQ-7.13-01: The TSP shall ensure that it operates in a legal and trustworthy manner.
-
ETSI 319 401 REQ-7.14.3-06X [CONDITIONAL]: When the TSP makes use of a trust service component provided by another party it shall ensure that the security and functionality required by the trust service component meet the appropriate requirements of the applicable policy and practices
-
ETSI 319 403-1 7.9 (..) The following activities shall be part of surveillance audit: (..) d) review of internal audits and security management systems in place;
-
-
Source of incident disclosure: Finding by CAB during annual ETSI audit.
Impact
-
Total number of certificates: N/A
-
Total number of "remaining valid" certificates: N/A
-
Affected certificate types: N/A
-
Incident heuristic: N/A
-
Was issuance stopped in response to this incident, and why or why not?: N/A (see point below).
-
Analysis: N/A
-
Additional considerations: KPN only operates legacy S/MIME-capable CAs, which have not issued any S/MIME certificates since 1 August 2023. At that time this was changed due to updated S/MIME regulations, under which email addresses and the EKU
emailProtectionwere no longer included in publicly trusted certificates.
Timeline
-
11-07-2025: CAB identifies finding
-
17-07-2025: KPN created a Corrective Action Plan to remediate the audit finding
-
12-08-2025: Corrective Action Plan Approved by auditor
Related Incidents
N/A
Root Cause Analysis
Contributing Factor 1: Agreements with subcontractor didn’t contain clauses regarding audit responsibility
-
Description: The internal audit at the supplier was not conducted due to a lack of clear agreements with the external party regarding audit responsibility.
-
Timeline: See main timeline.
-
Detection: Audit finding by CAB.
-
Interaction with other factors: No.
-
Root Cause Analysis methodology used: N/A
Contributing Factor 2: Internal audit schedule
-
Description: The audit was not included in the internal audit schedule, as supplier audits were not formally embedded in the planning process.
-
Timeline: See main timeline.
-
Detection: Audit finding by CAB.
-
Interaction with other factors: No.
-
Root Cause Analysis methodology used: N/A
Lessons Learned
-
What went well: N/A
-
What didn’t go well: N/A
-
Where we got lucky: N/A
-
Additional: N/A
Action Items
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Execute specific internal audit | Mitigate | Root Cause #1 | Check content | 2025-10-11 | Ongoing |
| Formalize agreements with external parties regarding audit responsibilities. | Prevent | Root Cause # 1 | Check | 2025-10-11 | Ongoing |
| Ensure supplier audits are explicitly included in the internal audit schedule going forward. | Prevent | Root Cause # 2 | Check | 2025-09-30 | Ongoing |
Appendix
N/A
| Assignee | ||
Comment 2•1 year ago
|
||
In the Action items above an error had occured while pasting the information from internal systems to markdown, so an updated version with the right Evaluation Criteria is provided below. In the meantime, PKIoverheid is monitoring this bug and we're open for additional questions or remarks people might have.
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Execute specific internal audit | Mitigate | Root Cause #1 | Report back when audit has been concluded | 2025-10-11 | In progress |
| Formalize agreements with external parties regarding audit responsibilities. | Prevent | Root Cause # 1 | Report back when agreements have been updated | 2025-10-11 | In progress |
| Ensure supplier audits are explicitly included in the internal audit schedule going forward. | Prevent | Root Cause # 2 | Report back when this has been implemented | 2025-09-30 | In progress |
| Assignee | ||
Comment 3•11 months ago
|
||
After discussing matters with the involved subcontractor, the decision has been made to execute a full external audit on the subcontractor in question. Since this required a longer lead time than the original plan to execute an internal audit (performed by a KPN internal auditor) the remedation will take longer. The expected due date of the external audit is now 01-01-2026. With that, the status of the action item is as follows:
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Execute specific internal audit | Mitigate | Root Cause #1 | Check content | 2025-10-11 | Won't do |
| Formalize agreements with external parties regarding audit responsibilities. | Prevent | Root Cause # 1 | Report back | 2025-10-11 | In progress |
| Ensure supplier audits are explicitly included in the internal audit schedule going forward. | Prevent | Root Cause # 2 | Report back | 2025-09-30 | Won't do |
| Execute external audit by subcontractor. Subcontractor reports results back to KPN and Logius | Prevent | Root Cause #1 | Report back results | 01-01-2026 | In progress |
| Assignee | ||
Comment 4•10 months ago
|
||
Action items 2 has been completed. We erroneously reported action item #3 as a won't do above, KPN has updated the internal audit schedule with regards to supplier audits in general.
As such, only action item #4 is still open.
This report has gone stale.
You may request a next update that's beyond the normal weekly cadence but, absent that being accepted, you are required to provide an update on a weekly basis.
Comment 6•8 months ago
|
||
The visits of the external auditor at the subcontractor now has been scheduled, but was not possible earlier than the last week of January and first week of February. The expected due date of the external audit therefore has shifted to 2026-02-09. With that, the status of the action item is as follows:
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Execute specific internal audit | Mitigate | Root Cause #1 | Check content | 2025-10-11 | Won't do |
| Formalize agreements with external parties regarding audit responsibilities. | Prevent | Root Cause # 1 | Report back | 2025-10-11 | Completed |
| Ensure supplier audits are explicitly included in the internal audit schedule going forward. | Prevent | Root Cause # 2 | Report back | 2025-09-30 | Completed |
| Execute external audit by subcontractor. Subcontractor reports results back to KPN and Logius | Prevent | Root Cause #1 & #2 | Report back results | 2026-02-09 | In progress |
Comment 7•8 months ago
|
||
This report has gone stale. As a reminder, CA Owners may request the “Next update” Whiteboard field be set by a Root Store Operator to align with a specific date related to an open Action Item.
Comment 8•8 months ago
|
||
Implementation is on schedule. No further updates.
| Assignee | ||
Updated•8 months ago
|
Comment 9•7 months ago
|
||
This report, along with another PKIoverheid report, has gone stale.
We strongly encourage you to request the "Next update" Whiteboard field be set to align with a specific date related to the soonest appearing open Action Item. Unless a "Next update" date is set, the CCADB Incident Reporting Guidelines establish an expectation of CA Owners providing weekly status updates.
| Assignee | ||
Comment 10•7 months ago
|
||
Could the "Next Update" for this bug be set to 2026-02-09? We were unsure if this was needed or not, in the past this action had been done by the triage owner based on the action items. We'll take this into account for future bugs and will update our own internal procedures for this. Thanks.
Updated•7 months ago
|
Comment 11•7 months ago
|
||
Please provide an update. Thanks.
| Assignee | ||
Comment 12•7 months ago
|
||
The audit is currently in progress, the start was slightly delayed due to the fact that the audit in this form was new for the subcontractor involved and as such required more time to set up. This has also led to a different approach compared to a normal annual audit which means a two staged audit with a gap in between for remediating non-conformities (if present). Since the audit is currently in stage 1, the end date for the whole (including certification) is currently unknown, so we can't really give a firm due date for action item #4.
Since the main root causes were already addressed by action items #2 and #3 (which have been completed) we think that this bug can be closed, since the evaluation criteria for action item #4 was always only going to be self-reporting which wouldn't add much more in this public report, looking back. The follow-up for this action item would be covered both by the KPN CAB and also by the engaged CAB for the subcontractor for which regulatory frameworks exist (like ETSI EN 319 403 etc.).
| Assignee | ||
Comment 13•6 months ago
|
||
PKIoverheid is currently monitoring this bugs for any questions and/or comments that the community or browsers might have. As stated above, we believe that the remaining action item, while still in progress, doesn't contribute to addressing the root cause(s) which caused this non-compliance (and hence this bug). If anyone has any comments, questions or objections to this approach, please feel free to state those in this bug.
| Assignee | ||
Comment 14•6 months ago
|
||
We would like to give the community the option to respond to our last statement and voice any comments and/or questions they might have about this approach. If there is no response or input, we would like to proceed by filing a closure request next week (that is, Monday March 16) unless of course there is new information, questions or objections.
| Assignee | ||
Comment 15•5 months ago
|
||
Since no objections or comments have been raised we propose to close this bug as indicated in comment #14. As such, please find the closure summary below.
Report Closure Summary
- Incident description: The CAB of TSP KPN (subCA of PKIoverheid) noted during an audit visit that no (internal) audit had been performed at one of its subcontractors
- Incident Root Cause(s): Auditing responsibility wasn't included in the contract between KPN and the involved subcontractor. It was also found that auditing at subscontractors wasn't included in the KPN internal audit schedule.
- Remediation description: Agreemeents with subcontractors have been updated to include auditing responsibilities and subcontractor/supplier audits are explicitly included in the (internal) audit schedule of KPN. An external audit of the involved subcontractor is in progress.
- Commitment summary: KPN commits itself to have a proactive approach to subcontractor compliance which include executing (internal) audits in a timely fashion and acting upon the results.
All Action Items disclosed in this report have been completed as described, and we request its closure.
Comment 16•5 months ago
|
||
This is a final call for comments or questions on this Incident Report.
Otherwise, it will be closed on approximately 2026-04-16.
Updated•4 months ago
|
Description
•