PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #14 – Back-up
This case is an ETSI audit incident report concerning KPN’s backup plans for its TSP services. PKIoverheid (Policy Authority PKIoverheid) reported that the CAB found backup plan(s) were not fully documented and that explicit testing of a backup plan was a new requirement introduced by ETSI EN 319 401 v3.1.1. The incident was disclosed as a minor non-conformity during the annual ETSI audit, with non-compliance starting 28-Feb-2025 and identified by the auditor on 11-Jul-2025. PKIoverheid documented a corrective action plan approved by the auditor on 12-Aug-2025, including improving the backup plan to conform to ETSI requirements, executing gap analyses, and improving a structured process for tracking and implementing new requirements with assigned responsibilities and escalation paths. Updates in the thread state that action items #2 and #4 were completed, and action item #1 was delayed by three weeks before being reported as completed. The closure summary states that remediation is complete, including an improved and updated backup plan complying with the updated 401 requirements, gap analysis execution, improved requirement-tracking processes, and commitments to maintain a documented and testable backup strategy with restore tests and automated backup-restore testing using Nagios. A final call for comments was issued, with closure expected around 2025-11-19 if no further questions were raised.
- Non-conformity period began for backup plan documentation/testing requirements under ETSI EN 319 401 v3.1.1.
- The auditor identified ETSI finding #14 regarding backup plan documentation/testing.
- Corrective action plan for ETSI finding #14 was approved by the auditor.
- KPN reported that the remaining action item (#1) to improve the backup plan was completed.
- PKIoverheid submitted the incident report closure summary requesting closure after remediation completion.
- CCADB issued a final call for comments before the bug would be closed.
- Logius representative — Opened a preliminary incident report describing a minor non-conformity: backup plan(s) not documented, disclosed via the annual ETSI audit.
- Logius representative — Provided the full incident report for ETSI finding #14, including the CAB’s observation, timeline, root cause analysis, and action items.
- Logius representative — Corrected an error in the pasted action-item table and re-posted the updated evaluation criteria.
- Logius representative — Reported status updates: action item #3 completed; action items #2 and #4 completed; action item #1 delayed by three weeks.
- Logius representative — Reported that action item #1 was completed and stated remediation is complete, with a closure request to follow.
- Logius representative — Submitted the report closure summary describing remediation steps and requesting closure.
- CCADB representative — Issued a final call for comments and indicated the bug would be closed around 2025-11-19 if no comments were received.