SwissSign: BRs require full annual audits
The case addresses SwissSign AG's compliance with Mozilla's Baseline Requirements (BRs) for annual audits. SwissSign submitted an audit statement that raised concerns regarding its adequacy, particularly regarding the terminology used and the scope of the audit. Issues included the use of 'point-in-time' audits, which do not meet the BRs' requirement for full annual audits. After discussions, SwissSign provided updated audit statements, but complications arose regarding the coverage of all included roots. The case was ultimately resolved with the acceptance of the updated audits, although concerns about continuity and compliance with Mozilla's policies were highlighted.
- Initial audit statement submitted by SwissSign.
- SwissSign responds to concerns about audit terminology.
- New audit reports submitted for review.
- Bug reopened due to concerns about audit compliance.