Firmaprofesional: Delayed publication of 2026 Audit Attestation Letters
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: clopez, Assigned: clopez)
Details
(Whiteboard: [ca-compliance] [disclosure-failure])
Preliminary Incident Report
Summary
-
Incident description:
On 2026-07-15, while submitting the 2026 Audit Attestation Letters (AALs) to the CCADB, Autoridad de Certificacion Firmaprofesional identified that the statement date of 2026-07-15 was more than 92 calendar days after the audit period end date of 2026-03-27. The deadline established by Section 5.2 of the CCADB Policy was 2026-06-27.
The affected disclosures are the Standard, TLS Baseline Requirements, and TLS Extended Validation Guidelines AALs for the audit period from 2025-03-28 through 2026-03-27. The records reviewed to date have not identified a final AAL or a signed explanatory letter that was publicly provided by the deadline.
The final AALs have now been issued and entered in CCADB Case 00003334. A signed explanatory letter from the Qualified Auditor has been published in the Bugzilla
CA Documentscomponent: Bug 2055439.At this preliminary stage, the known impact is the delayed public availability of the three audit disclosures. The CA Owner is continuing to determine the complete timeline, whether any additional impact exists, the contributing factors, and the corrective actions. The incident therefore remains ongoing.
-
Relevant policies:
- CCADB Policy version 2.1, effective 2026-03-20, Section 5.2, requires authoritative English-language public audit information to be uploaded to the CCADB no later than 92 calendar days after the end of the audit period. If the audit information cannot be provided by that deadline, the CA Owner must instead upload a signed explanatory letter from the Qualified Auditor to Bugzilla in the
CA Documentscomponent by the same deadline. - CCADB Policy version 2.1, Section 6.1, and CCADB Incident Reporting Guidelines version 3.2 govern public disclosure and follow-up of this incident.
- CCADB Policy version 2.1, effective 2026-03-20, Section 5.2, requires authoritative English-language public audit information to be uploaded to the CCADB no later than 92 calendar days after the end of the audit period. If the audit information cannot be provided by that deadline, the CA Owner must instead upload a signed explanatory letter from the Qualified Auditor to Bugzilla in the
-
Source of incident disclosure:
Self Reported.
Updated•1 month ago
|
Status Update
Our investigation and preparation of the Full Incident Report remain in progress.
Since publication of the Preliminary Incident Report, we have continued reviewing the complete incident timeline, the public availability of the three final Audit Attestation Letters, the state of CCADB Case 00003334, the Root Cause Analysis, and the remediation plan. An authenticated review of the CCADB case on 2026-07-23 confirmed that it remains in Verification By Root Store. The Standard, TLS Baseline Requirements, and TLS Extended Validation Guidelines sections each contain a public DEKRA AAL link, an audit period from 2025-03-28 through 2026-03-27, a statement date of 2026-07-15, and three selected applicable root certificates. Each displayed ALV status is FAIL; the displayed results identify DateVerified=Fail and StatementDate=Fail, and the authenticity-confirmed field is not selected. We therefore do not consider CCADB verification final. The Qualified Auditor's signed explanatory letter also remains publicly available as a non-obsolete attachment to Bug 2055439.
At this time, there is no change to the known impact described in the Preliminary Incident Report: the delayed public availability of the Standard, TLS BR, and TLS EV audit disclosures for the audit period ending 2026-03-27. The final scope and supporting evidence remain under validation, and the incident remains open.
We will publish the Full Incident Report no later than 2026-07-30 11:05:52 UTC, or earlier if the remaining investigation and review are completed sooner. We will report any material change before that time.
We request that the Bugzilla Whiteboard Next update field be set to 2026-07-30.
Updated•1 month ago
|
Full Incident Report
Summary
- CA Owner CCADB unique ID:
A000006. - Incident description: Autoridad de Certificacion Firmaprofesional did not upload its Standard, TLS Baseline Requirements, and TLS Extended Validation Guidelines Audit Attestation Letters (AALs) to CCADB, or publish an explanatory letter signed by the Qualified Auditor, by the applicable deadline. The audit period ended on
2026-03-27; the deadline under Section 5.2 of the CCADB Policy was2026-06-27. Firmaprofesional formally confirmed the non-compliance on2026-07-15 07:58:13 UTCwhile preparing the CCADB submission and reviewing the applicable policy requirements. - Timeline summary:
- Non-compliance start date:
2026-06-28 UTC, the first calendar day after the CCADB audit-disclosure deadline. - Non-compliance identified date:
2026-07-15 07:58:13 UTC, when Firmaprofesional formally confirmed that the 92-calendar-day deadline was calculated from the audit-period end date and had expired. - Non-compliance end date:
2026-07-16 10:28:14 UTC, when CCADB confirmed submission of Case00003334containing the three authoritative AAL disclosures.
- Non-compliance start date:
- Relevant policies:
- CCADB Policy version 2.1, Section 5.2.
- CCADB Policy version 2.1, Section 6.1.
- CA/Browser Forum TLS Baseline Requirements version 2.2.8, Section 8.6.
- CCADB Incident Reporting Guidelines version 3.2, section “When are reports expected?”.
- Source of incident disclosure: Self Reported.
Impact
- Total number of certificates: N/A.
- Total number of "remaining valid" certificates: N/A.
- Affected certificate types: N/A.
- Incident heuristic: N/A.
- Was issuance stopped in response to this incident, and why or why not?: No. Issuance was not stopped because the identified non-compliances concerned public disclosure timing, and the investigation did not identify an associated certificate issuance, content, or revocation non-compliance.
- Analysis: The known impact is delayed public transparency. The three authoritative AALs were submitted through CCADB Case
00003334after the2026-06-27deadline. The signed explanatory letter was published as a public attachment to Bug 2055439 at2026-07-16 10:45:15 UTC. The Preliminary Incident Report was published at2026-07-16 11:05:52 UTC, approximately 27 hours after formal confirmation of the non-compliance. - Additional considerations: The Qualified Auditor's explanatory letter states that audit activities extended through
2026-05-28and attributes the delayed issuance to the extended audit work, logistical considerations, and additional quality-assurance procedures. This describes the auditor's timing; it does not replace the CA Owner's analysis of why its own controls did not ensure that one of the two permitted audit-disclosure paths was completed by the deadline.
Timeline
All times are UTC unless otherwise stated.
2025-03-28- The audit period began.2026-03-20- CCADB Policy version 2.1 became effective. Its publication notice expressly called out clarified expectations for explanatory letters when audit statements are delayed.2026-03-27- The audit period ended.2026-04-06through2026-04-10- Remote audit activities took place.2026-04-13through2026-04-15- On-site audit activities took place.2026-04-16through2026-05-28- Further remote audit activities took place.2026-06-27- The 92-calendar-day CCADB disclosure deadline expired without the final AALs being uploaded to CCADB or a signed explanatory letter being published in the BugzillaCA Documentscomponent.2026-06-28- The audit-disclosure non-compliance began.2026-07-14 10:05:10 UTC- The Qualified Auditor provided the first set of public AAL URLs.2026-07-15 07:58:13 UTC- During preparation of the CCADB submission, Firmaprofesional formally confirmed that the 92-calendar-day deadline calculated from the audit-period end date had expired. Firmaprofesional also identified that the policy-document information in the AALs did not cover the complete audit period.2026-07-15 08:19:52 UTC- The Qualified Auditor stated that it had calculated the publication interval from completion of the audit work on2026-05-29, rather than from the audit-period end date, and agreed to correct the policy-document information.2026-07-16 06:01:27 UTC- The Qualified Auditor provided the corrected final public AAL URLs.2026-07-16 10:28:14 UTC- CCADB confirmed submission of Case00003334, containing the Standard, TLS BR, and TLS EV AAL disclosures.2026-07-16 10:45:15 UTC- Firmaprofesional published the Qualified Auditor's signed explanatory letter as a public attachment to Bug 2055439.2026-07-16 11:05:52 UTC- Firmaprofesional published the Preliminary Incident Report in Bug 2055444.
Related Incidents
| Bug | Date | Description |
|---|---|---|
| 1911335 | 2024-08-02 | PKIoverheid reported delayed availability of an S/MIME audit report. It is related because required audit evidence was not available by the applicable public-disclosure deadline. |
| 1917224 | 2024-09-06 | Chunghwa Telecom reported that annual audit reports would not be made public within the TLS Baseline Requirements Section 8.6 deadline. |
| 1945197 | 2025-01-31 | Sectigo disclosed ETSI audit letters after the applicable CCADB deadline because the audit-period end date in the letters was earlier than the date used to track the submission deadline. This is directly related to calculating and controlling the deadline from the stated audit-period end date. |
| 2008260 | 2025-12-31 | Chunghwa Telecom reported delayed CCADB disclosure of GTLSCA audit statements because the required WebTrust Seal URLs were not obtained on time. It is related to governance of auditor dependencies and timely CCADB publication of audit evidence. |
| 2011430 | 2026-01-20 | D-Trust reported that AALs were uploaded to CCADB after the 92-calendar-day deadline. It is directly related to the same CCADB Policy Section 5.2 deadline and explanatory-letter requirement. |
Root Cause Analysis
Root Cause #1 - The CA Owner's audit-disclosure process did not establish, independently verify, and enforce the CCADB Section 5.2 deadline
- Description: For the audit period ending on
2026-03-27, the applicable CCADB disclosure deadline was2026-06-27. Firmaprofesional's process did not independently calculate and verify that deadline or require evidence, by that date, of either authoritative AAL submission to CCADB or publication of a signed explanatory letter. - Timeline: The audit period ended on
2026-03-27, establishing2026-06-27as the 92-calendar-day deadline. Neither the authoritative AALs nor a signed explanatory letter were published by that date. Firmaprofesional formally confirmed the non-compliance on2026-07-15while preparing the CCADB submission, and CCADB confirmed submission of the three authoritative AALs on2026-07-16. - Detection: The process did not identify the missed deadline before or when it expired. The non-compliance was detected manually on
2026-07-15while preparing the CCADB submission and verifying the applicable policy requirement. - Interaction with other factors: The Qualified Auditor calculated the interval from completion of the audit work on
2026-05-29, rather than from the audit-period end date. Firmaprofesional's process did not identify and correct that interpretation before the policy deadline or activate the explanatory-letter alternative when the final AALs were unavailable. - Root Cause Analysis methodology used: Timeline analysis and control-gap analysis comparing the policy-defined reference date, the available task evidence, and the completed disclosure steps with the two outcomes required by CCADB Policy Section 5.2.
Lessons Learned
- What went well:
- Before final submission, the AAL content was reviewed against the complete audit period and the missing policy-document versions were corrected.
- The corrected final AALs, signed explanatory letter, CCADB case, and compliance incident were made public and cross-referenced.
- The Preliminary Incident Report was published within 72 hours after formal confirmation of the non-compliance.
- What didn’t go well:
- The tracked audit-disclosure date was three days later than the policy deadline.
- Confirmation before the deadline that the required AALs were unavailable did not activate management escalation or the explanatory-letter path.
- The workflow did not independently distinguish the audit-period end date from the later completion date of audit work.
- Where we got lucky: N/A.
- Additional: The auditor's work schedule and document-delivery date must not determine the CA Owner's regulatory disclosure deadline. The CA Owner must calculate and control that deadline independently.
Action Items
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Replace the current audit-disclosure task with a register that calculates each CCADB Section 5.2 deadline from the audit-period end date and assigns primary and backup owners | Prevent | Root Cause #1 | Every in-scope audit has a system-calculated deadline, named owners, evidence links, reminders, and management escalation; an independent reviewer validates the calculation for the complete in-scope corpus and one completed audit cycle | 2026-08-21 |
Ongong |
| Add a mandatory pre-deadline decision gate requiring either authoritative AAL publication or activation of the signed explanatory-letter path | Prevent | Root Cause #1 | The approved procedure defines the decision lead time, records the selected path, and demonstrates that missing evidence escalates automatically before the policy deadline | 2026-08-28 |
Ongoing |
We request that Mozilla update the Bugzilla Whiteboard Next update date to 2026-08-21, aligned with the earliets open Action Item due date.
Appendix
Status Update
The Full Incident Report was published in comment 2 on 2026-07-27. No material change is being reported at this time.
The two open Action Items listed in the Full Incident Report retain their published due dates:
2026-08-21— Replace the current audit-disclosure task with a register that calculates each CCADB Section 5.2 deadline from the audit-period end date and assigns primary and backup owners.2026-08-28— Add a mandatory pre-deadline decision gate requiring either authoritative AAL publication or activation of the signed explanatory-letter path.
We reiterate our request that the Bugzilla Whiteboard Next update date be set to 2026-08-21, aligned with the due date of the earliest open Action Item. We will provide an earlier update if either Action Item is changed, completed, or delayed.
Updated•1 month ago
|
Comment 4•10 days ago
|
||
Status Update
The first open Action Item in the Full Incident Report, due on 2026-08-21, has been completed.
Firmaprofesional has implemented the audit-disclosure register as the authoritative control for the audits within its approved scope. The complete in-scope corpus and one completed audit cycle have been independently validated against the evaluation criteria described in the Full Incident Report.
The second Action Item remains ongoing and retains its published due date of 2026-08-28. There is no change to the incident impact described in the Full Incident Report.
We will provide the next update by 2026-08-28, or earlier if the remaining Action Item is changed, completed, or delayed.
Updated•9 days ago
|
Status Update
The second and final Action Item in the Full Incident Report, due on 2026-08-28, has been completed.
Firmaprofesional has implemented the mandatory pre-deadline decision gate requiring either publication of the authoritative Audit Attestation Letters or activation of the signed explanatory-letter path.
All Action Items disclosed in the Full Incident Report are now complete. There is no change to the incident impact described in the Full Incident Report.
Description
•