SwissSign: recommendation on evaluation of cloud service providers
This case is based on an ETSI audit report for SwissSign that included a recommendation to strengthen SwissSign’s internal questionnaire used to evaluate cloud service providers. The recommendation was to align the questionnaire more explicitly with applicable CA/B Forum requirements. SwissSign stated that it uses cloud services (including AWS for MPIC and other listed cloud services) and that cloud services in scope of CA/B regulation are included in its regular audit scope. SwissSign reported that certificate issuance was not halted because the audit recommendation did not impact issuance. As remediation, SwissSign reviewed and updated the cloud service provider questionnaire to systematically check it against applicable CA/B Forum requirements and improve traceability. The action item to check the questionnaire against CA/B regulations was marked done, and the incident report was set up for closure after a final call for comments.
- SwissSign opened a CA Program bug with a preliminary incident report about an audit recommendation for improving its cloud service provider questionnaire.
- SwissSign published the full incident report describing the audit recommendation and planned remediation.
- An ETSI audit report containing the recommendation was published.
- SwissSign completed the remediation by updating the cloud service provider questionnaire and marked the action item as done.
- The incident report was scheduled to be closed after a final call for comments.
- SwissSign AG — SwissSign provided a preliminary incident report stating the audit report recommended improving its internal questionnaire for evaluating cloud service providers.
- SwissSign AG — SwissSign posted the full incident report, including that issuance was not halted and that the questionnaire is based on the CSA Cloud Control Matrix.
- SwissSign AG — SwissSign said it was monitoring the Bugzilla for community feedback.
- SwissSign AG — SwissSign again stated it was monitoring the Bugzilla for community feedback.
- SwissSign AG — SwissSign reported completion of the action item by checking and updating the cloud questionnaire against CA/B regulations and requested continued monitoring for feedback.
- CCADB representative — CCADB posted a final call for comments and noted the incident report would be closed around 2026-05-07.