PKIoverheid: TSP CIBG supply chain management findings in 2025 ETSI audit (Incident Report #2)
This case documents an incident report by PKIoverheid (CA Owner CCADB unique ID A000068) related to supply chain management findings from a 2025 ETSI audit. The preliminary and full incident reports state that not all ETSI EN 319 401 (Clause 7.14) supply chain management requirements were found to be part of contracts with suppliers, and that no general supply chain management policy was found. The report also notes there was no reference to possible use of time stamping, a delay in analysis of an SLA report, limited details in pentest and vulnerability test requirements, and limited visibility and management of sub-contractors and their non-conformities. PKIoverheid described contributing factors including that the ETSI supply chain management requirements did not exist when supplier contracts were formalized and that CIBG does not have an organization-wide supply chain management policy. Corrective actions included drawing up an organization-wide supply chain management policy, documenting time-stamping service usage in formal supply chain documentation and the next CPS, expanding the Service Level Management process for timestamp administration and delays, and formalizing agreements with suppliers on reporting follow-up of findings at sub-suppliers and the level of detail for pentest and vulnerability reporting. The thread states that the first four action items were closed, the last two were in progress, and the report closure summary requests closure after completion of all disclosed action items as described. The bug is marked RESOLVED with resolution FIXED.
- An ETSI auditor identified a supply chain management non-conformity during the annual audit.
- A corrective action plan was created in response to the audit finding.
- The corrective action plan was approved by the auditor.
- The incident report was scheduled to be closed (and the bug is now resolved).
- Logius representative — Opened a preliminary incident report describing a minor non-conformity in supply chain management and citing ETSI EN 319 401 (Clause 7.14) as the relevant policy, with disclosure sourced from the annual ETSI audit.
- Logius representative — Said the full incident report was in final review stage and would be posted shortly.
- Logius representative — Posted the full incident report, including the finding details, timeline, contributing factors, and detection as an audit finding by the CAB.
- Logius representative — Reported that the first four action items were closed and that the last two were still in progress, listing updated action items and statuses.
- Logius representative — Stated implementation was on schedule and that there were no further updates.
- Logius representative — Provided a report closure summary describing remediation steps and commitment, requesting closure after completion of all action items as described.
- Apple representative — Asked PKIoverheid to confirm whether the incident was evaluated against all applicable requirements, including the S/MIME Baseline Requirements and Network Security Requirements.
- Logius representative — Explained that ETSI EN 319 401 v3.1.1 clause 7.14 introduced specific NIS2-related requirements that could not be mapped to SBR or NetSec specifically, and that the auditor’s concern was alignment with Clause 7.14.
- CCADB representative — Issued a final call for comments or questions and stated the incident report would be closed on approximately 2026-02-19.