← Government of The Netherlands, PKIoverheid (Logius) cases
Bugzilla #2008023 Incident

PKIoverheid: TSP CIBG supply chain management findings in 2025 ETSI audit (Incident Report #2)

RESOLVED FIXED Government of The Netherlands, PKIoverheid (Logius)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case documents an incident report by PKIoverheid (CA Owner CCADB unique ID A000068) related to supply chain management findings from a 2025 ETSI audit. The preliminary and full incident reports state that not all ETSI EN 319 401 (Clause 7.14) supply chain management requirements were found to be part of contracts with suppliers, and that no general supply chain management policy was found. The report also notes there was no reference to possible use of time stamping, a delay in analysis of an SLA report, limited details in pentest and vulnerability test requirements, and limited visibility and management of sub-contractors and their non-conformities. PKIoverheid described contributing factors including that the ETSI supply chain management requirements did not exist when supplier contracts were formalized and that CIBG does not have an organization-wide supply chain management policy. Corrective actions included drawing up an organization-wide supply chain management policy, documenting time-stamping service usage in formal supply chain documentation and the next CPS, expanding the Service Level Management process for timestamp administration and delays, and formalizing agreements with suppliers on reporting follow-up of findings at sub-suppliers and the level of detail for pentest and vulnerability reporting. The thread states that the first four action items were closed, the last two were in progress, and the report closure summary requests closure after completion of all disclosed action items as described. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 21:18 UTC Revised: 2026-06-16 19:25 UTC Confidence: 0.86 9 comments
Chronology
  1. An ETSI auditor identified a supply chain management non-conformity during the annual audit.
  2. A corrective action plan was created in response to the audit finding.
  3. The corrective action plan was approved by the auditor.
  4. The incident report was scheduled to be closed (and the bug is now resolved).
Thread Activity
  1. Logius representative — Opened a preliminary incident report describing a minor non-conformity in supply chain management and citing ETSI EN 319 401 (Clause 7.14) as the relevant policy, with disclosure sourced from the annual ETSI audit.
  2. Logius representative — Said the full incident report was in final review stage and would be posted shortly.
  3. Logius representative — Posted the full incident report, including the finding details, timeline, contributing factors, and detection as an audit finding by the CAB.
  4. Logius representative — Reported that the first four action items were closed and that the last two were still in progress, listing updated action items and statuses.
  5. Logius representative — Stated implementation was on schedule and that there were no further updates.
  6. Logius representative — Provided a report closure summary describing remediation steps and commitment, requesting closure after completion of all action items as described.
  7. Apple representative — Asked PKIoverheid to confirm whether the incident was evaluated against all applicable requirements, including the S/MIME Baseline Requirements and Network Security Requirements.
  8. Logius representative — Explained that ETSI EN 319 401 v3.1.1 clause 7.14 introduced specific NIS2-related requirements that could not be mapped to SBR or NetSec specifically, and that the auditor’s concern was alignment with Clause 7.14.
  9. CCADB representative — Issued a final call for comments or questions and stated the incident report would be closed on approximately 2026-02-19.
Participants
Logius representative Apple representative CCADB representative
External References
Similar Local Cases
#1983267 RESOLVED Incident Opened 2025-08-15 · Closed 2026-03-30 · 100% similar
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #7 – Change Management
#1983269 RESOLVED Incident Opened 2025-08-15 · Closed 2026-01-28 · 100% similar
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #9 – Lifecycle Management
#1983270 RESOLVED Incident Opened 2025-08-15 · Closed 2026-01-13 · 100% similar
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #10 – Firewall Rules and Review
#1983271 RESOLVED Incident Opened 2025-08-15 · Closed 2026-01-28 · 100% similar
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #11 – Anti-Malware Software
#1983275 RESOLVED Incident Opened 2025-08-15 · Closed 2025-12-24 · 100% similar
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #15 – Outdated Software
#1985816 RESOLVED Incident Opened 2025-08-28 · Closed 2026-05-26 · 100% similar
PKIoverheid: TSP Cleverbase Findings in 2025 ETSI Audit - Incident Report #1 – Incorrect issuer CA listed in CPS
#2008021 RESOLVED Incident Opened 2025-12-30 · Closed 2026-02-09 · 100% similar
PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #1 – Document Management
#2008024 RESOLVED Incident Opened 2025-12-30 · Closed 2026-02-09 · 100% similar
PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #3 – Asset Management

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action