PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #2 – Compliance Management
This case is an incident report from PKIoverheid (KPN TSP subCA) regarding compliance management findings from an annual ETSI audit. PKIoverheid states that the CAB noted that full compliance with the updated ETSI EN 319 401 v3.1.1 and NIS2 requirements was not in place at the time of the audit visit, recorded as a minor non-conformity. PKIoverheid attributes the issue to compliance management not being fully effective: not all requirements were implemented in time because changes were not fully tracked or prioritized during the transition period, and responsibility for tracking/prioritizing was not clearly assigned. PKIoverheid created a Corrective Action Plan, performed additional gap analyses, and later reported that the remaining requirements were implemented and that a structured process for tracking and implementing new requirements (including roles/responsibilities and management meetings) was put in place. The thread includes a closure request stating that all disclosed action items were completed and asking for closure. The bug is marked RESOLVED with resolution FIXED.
- ETSI EN 319 401 v3.1.1 requirements became effective, marking the start of the non-compliance period described in the incident report.
- The CAB identified the ETSI audit finding (ETS I Finding #2) during the annual audit visit.
- KPN created a Corrective Action Plan to remediate the audit finding.
- The Corrective Action Plan was approved by the auditor.
- PKIoverheid reported updates that all action items were completed, including gap analysis execution, implementation of remaining requirements, and process changes.
- PKIoverheid submitted a report closure summary requesting closure after completion of all action items.
- The bug was resolved (FIXED).
- Logius representative — Opened a preliminary incident report describing a minor non-conformity in compliance management of ETSI EN 319 401 v3.1.1 and stating the source as the annual ETSI audit.
- Logius representative — Provided the full incident report for ETSI Finding #2, including the non-conformity description, timeline, root cause analysis, and action items.
- Logius representative — Stated PKIoverheid was monitoring the bug and had no updates on the action items at that time.
- Logius representative — Reported that action items 1–3 were completed, including execution of gap analysis, completion of remaining requirement implementation, and implementation of the structured tracking process and management meetings.
- Logius representative — Submitted a report closure summary stating remediation steps were implemented, all action items were completed as described, and requested closure.
- CCADB representative — Issued a final call for comments and noted the bug would be closed on approximately 2025-11-19 if no further comments were received.