← SwissSign AG cases
Bugzilla #1990276 Ca Documents Audit Finding

SwissSign: recommendation on evaluation of cloud service providers

RESOLVED FIXED SwissSign AG
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is based on an ETSI audit report for SwissSign that included a recommendation to strengthen SwissSign’s internal questionnaire used to evaluate cloud service providers. The recommendation was to align the questionnaire more explicitly with applicable CA/B Forum requirements. SwissSign stated that it uses cloud services (including AWS for MPIC and other listed cloud services) and that cloud services in scope of CA/B regulation are included in its regular audit scope. SwissSign reported that certificate issuance was not halted because the audit recommendation did not impact issuance. As remediation, SwissSign reviewed and updated the cloud service provider questionnaire to systematically check it against applicable CA/B Forum requirements and improve traceability. The action item to check the questionnaire against CA/B regulations was marked done, and the incident report was set up for closure after a final call for comments.

Model: gpt-5.4-nano Generated: 2026-06-13 20:48 UTC Revised: 2026-06-16 18:23 UTC Confidence: 0.86 6 comments
Chronology
  1. SwissSign opened a CA Program bug with a preliminary incident report about an audit recommendation for improving its cloud service provider questionnaire.
  2. SwissSign published the full incident report describing the audit recommendation and planned remediation.
  3. An ETSI audit report containing the recommendation was published.
  4. SwissSign completed the remediation by updating the cloud service provider questionnaire and marked the action item as done.
  5. The incident report was scheduled to be closed after a final call for comments.
Thread Activity
  1. SwissSign AG — SwissSign provided a preliminary incident report stating the audit report recommended improving its internal questionnaire for evaluating cloud service providers.
  2. SwissSign AG — SwissSign posted the full incident report, including that issuance was not halted and that the questionnaire is based on the CSA Cloud Control Matrix.
  3. SwissSign AG — SwissSign said it was monitoring the Bugzilla for community feedback.
  4. SwissSign AG — SwissSign again stated it was monitoring the Bugzilla for community feedback.
  5. SwissSign AG — SwissSign reported completion of the action item by checking and updating the cloud questionnaire against CA/B regulations and requested continued monitoring for feedback.
  6. CCADB representative — CCADB posted a final call for comments and noted the incident report would be closed around 2026-05-07.
Participants
SwissSign AG CCADB representative
External References
Similar Local Cases
#1990254 RESOLVED Ca Documents Audit Finding Opened 2025-09-23 · Closed 2026-05-04 · 100% similar
SwissSign: recommendation on risk assessment
#1990272 RESOLVED Ca Documents Audit Finding Opened 2025-09-23 · Closed 2026-05-04 · 100% similar
SwissSign: recommendation on backup testing
#1990274 RESOLVED Ca Documents Audit Finding Opened 2025-09-23 · Closed 2026-05-04 · 100% similar
SwissSign: recommendation on synchronization of staging and production environments
#1990275 RESOLVED Ca Documents Audit Finding Opened 2025-09-23 · Closed 2026-05-04 · 100% similar
SwissSign: recommendation on publication process for CA related data
#1990284 RESOLVED Audit Finding Self Reported Incident Opened 2025-09-23 · Closed 2026-05-04 · 81% similar
SwissSign: recommendation on review of key pair generation implementation
#1990277 RESOLVED Audit Finding Self Reported Incident Opened 2025-09-23 · Closed 2026-05-07 · 79% similar
SwissSign: recommendation on CA-specific risk assessment
#1614450 RESOLVED Audit Finding Opened 2020-02-10 · Closed 2022-11-14 · 79% similar
SwissSign: Audit Letter Validation failures on intermediate certificates
#1965804 RESOLVED Ca Documents Audit Finding Opened 2025-05-12 · Closed 2025-06-12 · 79% similar
certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report #1 – Improve clarity in CPS

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action