Certigna: Finding #2 ETSI Audit - Risks regarding the certification of device not described
This case is an incident report from Certigna regarding Finding #2 from an ETSI audit. The auditors identified non-compliance with ETSI EN 319 401 V3.1.1 (REQ-5-01) because the business risks associated with the possible loss of certification of a cryptographic device were not sufficiently described in the risk assessment. The thread states that the non-compliance period ran from 2024-08-20 to 2025-05-27, with the lack identified on 2025-03-28 and remediation actions validated by the auditor after updates to the risk management procedure and risk assessment. Certigna updated its risk management procedure with reinforced guidelines for identifying business risks, raised staff awareness of the new guidelines, and enriched the risk assessment with more detailed business scenarios and impacts (including loss of cryptographic device certification and loss of entity certification such as ISO 27001/ETSI). The report closure summary states that no impact on certificates was identified and that no certificates were affected. Certigna requested closure after completing the disclosed action items, and the incident report was scheduled to be closed on approximately 2025-07-02; the bug is marked RESOLVED with resolution FIXED.
- Certigna’s risk assessment was updated as part of its annual update, preceding the period later identified as non-compliant.
- An ETSI auditor identified that the business risks for possible loss of cryptographic device certification were not sufficiently described.
- Certigna updated its risk management procedure and reinforced guidelines for identifying business risks, and raised staff awareness of the updates.
- Certigna performed an annual update of the risk assessment, enriching business risks with more described scenarios and impacts.
- Certigna received the audit report validating proposed actions to address the deviations.
- The auditor validated the resolution of the deviation after analysis of the updated risk assessment and associated procedure.
- Dhimyotis representative — Submitted the full incident report findings for ETSI EN 319 401: REQ-5-01, describing the non-compliance, timeline, root cause analysis, and completed action items.
- Dhimyotis representative — Posted a report closure summary stating the remediation actions (procedure update, staff awareness, and risk assessment enrichment) were completed and requested closure.
- Certigna — Confirmed the action items were completed as described and requested closure while continuing to monitor the bug.
- CCADB representative — Issued a final call for comments and stated the incident report would be closed on approximately 2025-07-02.