ANF AC : Delayed Reporting of 2026 Audit Findings
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: pablo, Assigned: pablo)
Details
(Whiteboard: [ca-compliance] [disclosure-failure])
Preliminary Incident Report
Summary
Incident description: ANF AC identified that the audit findings from the 2026 ETSI audit were not reported within the timeframes defined by the CCADB Incident Reporting Guidelines.
The delayed reporting resulted from an incorrect assessment of the reportability of the audit findings. The findings themselves are being addressed in their respective incident reports.
- 2047579 - ANF AC: 2026 Audit Report Finding 1 out of 3
- 2047580 - ANF AC: 2026 Audit Report Finding 2 out of 3
- 2047581 - ANF AC: 2026 Audit Report Finding 3 out of 3
Relevant policies: CCADB Incident Reporting Guidelines v3.2
Source of incident disclosure: A comment from the Chrome Root Program in the following Bugzilla incident:
https://bugzilla.mozilla.org/show_bug.cgi?id=2047579#c4
Updated•2 months ago
|
| Assignee | ||
Comment 1•1 month ago
|
||
Full Incident Report
Summary
Incident description:
ANF AC did not report the audit findings within the reporting timelines defined by the CCADB Incident Reporting Guidelines.
Timeline summary
- Non-compliance start date: 2026-02-20
- Non-compliance identified date: 2026-06-29
- Non-compliance end date: 2026-06-15
Relevant policies: - CCADB Incident Reporting Guidelines v3.2
Source of incident disclosure:
Comment from the Chrome Root Program in Bug https://bugzilla.mozilla.org/show_bug.cgi?id=2047579#c4
Impact
No impact identified on certificates.
Timeline
| Fecha | Evento |
|---|---|
| 2026-02-20 | ANF AC became aware of the first audit finding identified during the ETSI audit. |
| 2026-03-30 | ANF AC became aware of the remaining audit findings identified during the ETSI audit. |
| 2026-06-15 | ANF AC received the Audit Attestation Letter (AATL) and published it in CCADB. Based on the understanding at that time that audit findings should be reported once the AATL was publicly available, ANF AC created the three corresponding Bugzilla incident reports (Bugs 2047579, 2047580 and 2047581). |
| 2026-06-29 | Chrome Root Program noted that the audit findings should have been reported within the CCADB Incident Reporting Guidelines timelines. |
| 2026-06-29 | ANF AC acknowledged the delayed reporting and initiated a separate incident report for this issue. |
| 2026-06-29 | Incident reporting procedure updated to clarify the reporting timeline for audit findings. |
|
Root Cause Analysis
Root Cause #1
The reportability assessment was based on an incorrect interpretation of the CCADB Incident Reporting Guidelines. ANF AC understood that audit findings requiring public disclosure should be associated with a published Audit Letter in CCADB and therefore postponed the incident reporting until the Audit Letter became publicly available.
This interpretation was influenced by the fact that the audit findings were documentary in nature and did not affect certificate issuance, validation, revocation.
This interpretation was incorrect. The incident should have been reported when ANF AC became aware of the audit findings, independently of the publication status of the Audit Letter.
Contributing Factor #1
ANF AC did not identify a recent public incident report from another CA addressing the same interpretation of the CCADB Incident Reporting Guidelines. As a result, the opportunity to correct the interpretation before publishing the audit finding incident reports was missed.
Detection
The issue was identified following a comment from the Chrome Root Program referencing the applicable public precedent.
Interaction with other factors
None.
Lessons Learned
What went well
The underlying audit findings were corrected promptly.
What didn't go well
Documentary audit findings with no operational impact were incorrectly assessed as reportable only after publication of the AATL, resulting in delayed incident reporting.
The process used to determine whether an incident was reportable did not systematically incorporate relevant public precedents or Root Program guidance.
Where we got lucky
The delay concerned reporting obligations only. No certificates or subscribers were affected.
Action Items
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Update the incident assessment procedure to explicitly state that reportability of audit findings shall be assessed independently of the publication status of the Audit Attestation Letter. | Prevent | Root Cause #1 | The incident assessment procedure explicitly defines the reporting trigger for audit findings and requires documenting the reportability assessment. | 2026-07-03 | Complete |
| Implement an automated weekly Bugzilla monitoring process using the Bugzilla REST API to identify new or updated CA Certificate Compliance bugs and generate concise summaries of changes. | Prevent | Root Cause #1 | A weekly summary of relevant Bugzilla updates is automatically generated and reviewed as part of the incident assessment process. | 2026-07-31 | Planned |
| Raising awareness among the Compliance team regarding the reporting timelines for audit findings and the updates made to our incident reporting procedures. | Prevent | Root Cause #1, Contributing Factor #1 | The updated incident reporting criteria and procedures have been communicated to all members of the Compliance team. | 2026-07-03 | Complete |
| Assignee | ||
Comment 2•1 month ago
|
||
As a follow-up to Comment 1, implementation of the Action Item 2 is currently in progress and remains on schedule, due date (2026-07-31).
Comment 3•1 month ago
|
||
This report has gone stale. As a reminder, CA Owners may request the “Next update” Whiteboard field be set by a Root Store Operator to align with a specific date related to an open Action Item.
If a "Next update" date has not been requested, updates are expected weekly.
| Assignee | ||
Comment 4•1 month ago
|
||
Action Item 2 has been completed.
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Implement an automated weekly Bugzilla monitoring process using the Bugzilla REST API to identify new or updated CA Certificate Compliance bugs and generate concise summaries of changes. | Prevent | Root Cause #1 | A weekly summary of relevant Bugzilla updates is automatically generated and reviewed as part of the incident assessment process. | 2026-07-31 | Complete |
The automated monitoring process has been implemented. New and updated CA Certificate Compliance bugs are gathered through the Bugzilla API, and a weekly summary is generated for our review.
All Action Items associated with this incident have now been completed.
Report Closure Summary
-
Incident description: We did not report three findings from the 2026 ETSI audit within the timelines defined by the CCADB Incident Reporting Guidelines. The findings were reported on 2026-06-15, after publication of the corresponding Audit Attestation Letter. The delayed reporting did not affect certificates or subscribers.
-
Incident Root Cause(s): We incorrectly understood that documentary audit findings requiring public disclosure should be reported after the corresponding Audit Attestation Letter became publicly available. In addition, we did not identify a recent public incident report from another CA that addressed the same interpretation as ours.
-
Remediation description: We updated our incident assessment procedure to state explicitly that the reportability and reporting timelines of audit findings must be assessed inmediately and independently of the publication status of the Audit Attestation Letter. The updated criteria was communicated to the Compliance team. We also implemented an automated weekly Bugzilla monitoring process to identify relevant incidents.
-
Commitment summary:
N/A. No ongoing commitments remain beyond the completed Action Items.
All Action Items disclosed in this report have been completed as described, and we request its closure.
Comment 5•1 month ago
|
||
This is a final call for comments or questions on this Incident Report.
Otherwise, it will be closed on approximately 2026-08-07.
Updated•22 days ago
|
Description
•