← Buypass cases
Bugzilla #2005196
Audit Related
Buypass: Findings in 2025 ETSI Audit - Audit Incident Report #2 - Supply chain policy
RESOLVED
FIXED
Buypass
AI Summary
Buypass reported a minor nonconformity during the 2025 ETSI audit, indicating that new requirements from ETSI EN 319 401, paragraph 7.14, were not adequately implemented in their Supply Chain policy. The audit revealed that while Buypass had policies for Supplier Management, specific ETSI requirements were insufficiently covered. The root causes included prioritization of a new version of their Information Security Management System (ISMS) and a change in leadership. Buypass has since completed all action items to address these issues and committed to ongoing compliance monitoring.
Chronology
- Non-compliance identified during ETSI Audit
- All action items completed
Participants
Mads Henriksveen
External References
Similar Local Cases
Buypass: Findings in 2025 ETSI Audit - Audit Incident Report #1 - Compliance auditing on support processes
Buypass: Findings in 2023 audit
Audit infor for Buypass
SwissSign: recommendation on document release dual control
PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #8 – Human Resources Management
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #1 - mass certificate revocation plan
NETLOCK: Findings in 2024 Audit
PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #3 – Asset Management