← Certigna cases
Bugzilla #1973032 Self Reported Incident

Certigna: Finding #2 ETSI Audit - Risks regarding the certification of device not described

RESOLVED FIXED Certigna
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is an incident report from Certigna regarding Finding #2 from an ETSI audit. The auditors identified non-compliance with ETSI EN 319 401 V3.1.1 (REQ-5-01) because the business risks associated with the possible loss of certification of a cryptographic device were not sufficiently described in the risk assessment. The thread states that the non-compliance period ran from 2024-08-20 to 2025-05-27, with the lack identified on 2025-03-28 and remediation actions validated by the auditor after updates to the risk management procedure and risk assessment. Certigna updated its risk management procedure with reinforced guidelines for identifying business risks, raised staff awareness of the new guidelines, and enriched the risk assessment with more detailed business scenarios and impacts (including loss of cryptographic device certification and loss of entity certification such as ISO 27001/ETSI). The report closure summary states that no impact on certificates was identified and that no certificates were affected. Certigna requested closure after completing the disclosed action items, and the incident report was scheduled to be closed on approximately 2025-07-02; the bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:30 UTC Revised: 2026-06-16 18:23 UTC Confidence: 0.88 4 comments
Chronology
  1. Certigna’s risk assessment was updated as part of its annual update, preceding the period later identified as non-compliant.
  2. An ETSI auditor identified that the business risks for possible loss of cryptographic device certification were not sufficiently described.
  3. Certigna updated its risk management procedure and reinforced guidelines for identifying business risks, and raised staff awareness of the updates.
  4. Certigna performed an annual update of the risk assessment, enriching business risks with more described scenarios and impacts.
  5. Certigna received the audit report validating proposed actions to address the deviations.
  6. The auditor validated the resolution of the deviation after analysis of the updated risk assessment and associated procedure.
Thread Activity
  1. Dhimyotis representative — Submitted the full incident report findings for ETSI EN 319 401: REQ-5-01, describing the non-compliance, timeline, root cause analysis, and completed action items.
  2. Dhimyotis representative — Posted a report closure summary stating the remediation actions (procedure update, staff awareness, and risk assessment enrichment) were completed and requested closure.
  3. Certigna — Confirmed the action items were completed as described and requested closure while continuing to monitor the bug.
  4. CCADB representative — Issued a final call for comments and stated the incident report would be closed on approximately 2025-07-02.
Participants
Dhimyotis representative Certigna CCADB representative
External References
Similar Local Cases
#1973034 RESOLVED Self Reported Incident Opened 2025-06-19 · Closed 2025-07-02 · 100% similar
Certigna: Finding #3 ETSI Audit – Event log protection beyond seven years shall be improved
#2041368 RESOLVED Self Reported Incident Opened 2026-05-21 · Closed 2026-06-02 · 100% similar
Certigna: Finding #1 ETSI Audit – Missing system configuration information in the CP/CPS
#2043140 RESOLVED Self Reported Incident Opened 2026-05-28 · Closed 2026-06-16 · 100% similar
Certigna: Delay in reporting an audit finding
#1667744 RESOLVED Self Reported Incident Opened 2020-09-28 · Closed 2023-02-22 · 94% similar
Dhimyotis / Certigna: Certificates issued with validity periods greater than 398-days
#1973027 RESOLVED Self Reported Incident Opened 2025-06-19 · Closed 2025-07-02 · 92% similar
Certigna: Finding #1 ETSI Audit – French translation missing from S/MIME CP/CPS
#2025595 RESOLVED Self Reported Incident Incident Opened 2026-03-23 · Closed 2026-05-18 · 72% similar
IdenTrust: Delay in updating a Bug 2014609 - Next update
#2004845 RESOLVED Self Reported Incident Opened 2025-12-09 · Closed 2026-02-11 · 71% similar
GoDaddy: CA Certificates Published in PEM format
#2008029 RESOLVED Self Reported Incident Opened 2025-12-30 · Closed 2026-02-09 · 71% similar
PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #8 – Human Resources Management

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action