PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #7 – Change Management
This case is an incident report from PKIoverheid (CA Owner CCADB unique ID A000068) regarding a Change Management non-conformity identified during the 2025 ETSI annual audit. The finding was that the supply chain is not included in the Change Management process, and that no tracking of supply chain changes on the provision of services evidence was identified. The incident was disclosed as a CAB finding during the annual ETSI audit, with the non-conformance identified on 26-Sep-2025 and a corrective action plan created on 23-Oct-2025 and approved by the auditor on 06-11-2025. The corrective actions included triggering a pre-audit inquiry with the auditor after big standards updates or auditor changes, and formalizing agreements with suppliers on reporting change updates. In the report closure summary, PKIoverheid stated that agreements with suppliers on reporting change updates have been formalized and that CIBG commits to further expanding the change management process with supplier changes and improving oversight and consistency between related processes. The bug was resolved as FIXED, and the report was closed after a final call for comments on approximately 2026-02-19.
- An auditor identified a Change Management finding that supply chain was not included in the Change Management process.
- A corrective action plan for the Change Management finding was created.
- The corrective action plan was approved by the auditor.
- The incident report was scheduled to be closed after the final call for comments.
- Logius representative — Opened a preliminary incident report describing a minor non-conformity in Change Management and noting it was disclosed via the annual ETSI audit.
- Logius representative — Said the full incident report was in final review and would be posted shortly.
- Logius representative — Posted the full incident report stating the supply chain was not included in Change Management and describing root cause factors and action items.
- Apple representative — Asked whether publicly trusted Root CAs were in scope and questioned whether the issue also met Network Security Requirements.
- Logius representative — Responded that NetSec 1.7 was in scope and agreed to update the bug to include applicable NetSec 1.7 change management content.
- Logius representative — Updated the action item table, noting the remaining action item took longer due to legal and contractual hurdles.
- Logius representative — Posted an updated full incident report including additional relevant policies and updated action item details.
- Logius representative — Reported that implementation was on schedule and there were no further updates.
- Logius representative — Provided a report closure summary stating remediation actions were completed as described and requested closure.
- CCADB representative — Issued a final call for comments and stated the report would be closed on approximately 2026-02-19.