Buypass: Findings in 2025 ETSI Audit - Audit Incident Report #2 - Supply chain policy
Buypass reported a minor nonconformity identified during the 2025 ETSI audit, where new requirements from ETSI EN 319 401, paragraph 7.14, were not implemented in their Supply Chain policy. The CA disclosed this incident proactively, detailing the lack of sufficient coverage for specific ETSI requirements in their Supplier Management documents. A corrective action plan was developed and approved by the CA's Change Advisory Board (CAB), which included updating procedures and agreements to ensure compliance. All action items have since been completed, and Buypass has committed to continuous monitoring and improvements to their processes.
- Non-compliance identified during ETSI audit.
- All action items related to the incident have been completed.
- Buypass — Registered Preliminary Incident Report regarding nonconformity in Supply Chain policy.
- Buypass — Confirmed that the incident was evaluated against Network Security Requirements and found compliant.
- Buypass — Submitted Report Closure Summary detailing root causes and remediation actions taken.