SwissSign: recommendation on risk assessment
This case documents an ETSI audit report for SwissSign that included a recommendation to improve SwissSign’s risk assessment processes and the structured tracking of countermeasures in alignment with ETSI EN 319 401 §5-04 (REQ 5-04). SwissSign stated that certificate issuance was not affected at any time because the audit recommendation was not a certificate-issuance impact. SwissSign opened the bug as an audit-disclosed incident report and provided a root cause analysis describing a gap between performing risk assessments and having documentation and structured countermeasure tracking that fully match current best practices. An action item was set to update the risk assessment process to match ETSI EN 319 401 §5-04, with a due date initially listed as 2026-04-30. On 2026-04-27, SwissSign reported that the action item was completed, reviewed by its auditors, and that the remediation included improved documentation standards and a structured approach for tracking identified risks and associated countermeasures. The incident report was then subject to a final call for comments and was scheduled to be closed on approximately 2026-05-04; the bug status is RESOLVED with resolution FIXED.
- An ETSI audit report containing a recommendation on SwissSign’s risk assessment and countermeasure tracking was published.
- SwissSign opened the Bugzilla incident report based on the ETSI audit recommendation.
- SwissSign completed the remediation to align its risk assessment process and countermeasure tracking with ETSI EN 319 401 §5-04 and reported closure readiness.
- The bug was expected to be closed after the final call for comments.
- SwissSign AG — SwissSign submitted a preliminary incident report stating the ETSI audit recommended improving risk assessment processes and tracking of countermeasures, referencing ETSI EN319 401 and REQ 5-04.
- SwissSign AG — SwissSign provided the full incident report, stating certificate issuance was not impacted and describing the root cause as documentation and structured tracking not fully matching ETSI EN 319 401 §5-04.
- SwissSign AG — SwissSign said it was monitoring the Bugzilla for community feedback.
- SwissSign AG — SwissSign again stated it was monitoring the Bugzilla for community feedback.
- Internet Security Research Group — Jacob requested that the Next Update field for this and other SwissSign incident reports be set to the Due Date to reduce weekly update burden.
- CCADB representative — CCADB staff agreed it was reasonable and noted an issue was recorded to encourage CA Owners to make nextUpdate recommendations going forward.
- SwissSign AG — SwissSign reported completion of the action item, auditor review, and remediation details, and stated it would continue monitoring the Bugzilla for community feedback.
- CCADB representative — CCADB staff issued a final call for comments and stated the incident report would be closed on approximately 2026-05-04.