← Government of The Netherlands, PKIoverheid (Logius) cases
Bugzilla #1983262
Policy Compliance
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #2 – Compliance Management
RESOLVED
FIXED
Government of The Netherlands, PKIoverheid (Logius)
AI Summary
The PKIoverheid KPN TSP subCA was found to have minor non-conformities during the 2025 ETSI audit, specifically regarding compliance with ETSI EN 319 401 v3.1.1 and NIS2 requirements. The audit revealed that not all new requirements were implemented in time due to a lack of structured processes for tracking changes. KPN has since developed a corrective action plan, which has been approved, and has committed to maintaining a proactive compliance tracking approach. All action items related to the incident have been completed.
Chronology
- Effective date of ETSI EN 319 401 v3.1.1
- Non-compliance identified by CAB
- Completion of corrective action items
- Final call for comments on incident report
Participants
Policy Authority PKIoverheid
External References
Similar Local Cases
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #15 – Outdated Software
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #7 – Change Management
PKIoverheid: KPN CPS lacks CPR problem reporting instructions
PKIoverheid: Missing Intermediate CA from audit statement
PKIoverheid: No BR Audit for Intermediate CAs technically capable of issuing TLS certs
PKIoverheid: KPN CPS Lists Forbidden Domain Validation Method 3.2.2.4.6
Staat der Nederlandend / PKIoverheid: Non-BR-Compliant Certificate Issuance
PKIoverheid: Compliance issues CIBG TLS certificates