← SwissSign AG cases
Bugzilla #1990254
Policy Compliance
SwissSign: recommendation on risk assessment
RESOLVED
FIXED
SwissSign AG
AI Summary
The Bugzilla case addresses an audit report recommendation for SwissSign to enhance its risk assessment processes and improve the tracking of countermeasures in accordance with ETSI EN 319 401. The incident was disclosed following an audit, and while it highlighted areas for improvement, it did not indicate any non-compliance or impact on certificate issuance. SwissSign has since updated its risk assessment process to align with best practices and completed all action items from the audit.
Chronology
- Audit report containing recommendations published
- Action item completed and report closure summary provided
Participants
Sandy Balzer
Jacob Hoffman-Andrews
External References
Similar Local Cases
SwissSign: recommendation on evaluation of cloud service providers
SwissSign: Attribute Change process did not revoke single-domain certificates
SwissSign: BRs require full annual audits
SwissSign: Missed deadline of publication of 6 CPs and 1 CP/CPS
SwissSign: Non-BR-Compliant Certificate Issuance
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #2 – Compliance Management
QuoVadis: Unconstrained CAs missing audits
Amazon Trust Services - BR Self Assessment and CP/CPS Updates