Chunghwa Telecom (GTLSCA): 2025 WebTrust audit finding—missing objective evidence for third-party evaluation (Criterion 3.1.11)
This case concerns Chunghwa Telecom’s GTLSCA WebTrust audit finding that, during the 2025 audit period, no objective evidence was found regarding GTLSCA’s audit and evaluation of third parties with access to CA facilities and systems. The finding was tied to WebTrust for CA V2.2.2 Criterion 3.1.11, which requires that arrangements involving third-party access be based on a formal contract containing necessary security requirements, and that the CA maintain adequate evaluation evidence. Chunghwa Telecom stated that the issue originated from an auditor-identified problem during GTLSCA’s 2025 audit period, with the non-compliance period described as starting 2024-10-01 and ending 2025-12-23. Chunghwa Telecom reported that no certificates were misissued and noted that GTLSCA had already ceased TLS certificate issuance in early March 2025, so issuance was not suspended as part of this incident. Remediation actions included completing a retrospective third-party evaluation with contract validation and evidence collection (completed 2025-12-23), integrating vendor evaluation and risk assessment into an internal quarterly audit plan and checklist (completed 2025-12-23), and revising internal control assessment processes with follow-up procedures for non-compliant items (completed 2026-01-08). Mozilla’s incident-reporting comment indicated the remediation appeared responsive and that the deficiency reflected a governance integration gap, and Chunghwa Telecom agreed and committed to strengthening continuous compliance assurance and cross-functional coupling. The bug is marked RESOLVED with resolution FIXED, and the report closure summary requested closure after completion of the disclosed action items.
- Non-compliance period began for third-party evaluation evidence and framework gaps identified during the annual maintenance/procurement cycle.
- The auditor identified and formally identified the non-compliance during the GTLSCA auditing close meeting.
- GTLSCA completed a comprehensive retrospective third-party risk assessment and evidence collection, ending the described non-compliance period.
- GTLSCA completed revisions to internal control assessment processes and follow-up procedures for non-compliant items.
- The incident report was closed in the bug as RESOLVED (FIXED).
- Cht representative — Submitted a preliminary incident report stating no objective evidence was found for GTLSCA’s audit and evaluation of third parties with access to CA facilities/systems, citing WebTrust for CA V2.2.2 Criterion 3.1.11.
- Cht representative — Submitted a full incident report with the CA CCADB unique ID, described the non-compliance timeline (2024-10-01 to 2025-12-23), and detailed root causes and impact (including that no certificates were misissued).
- Cht representative — Noted Chunghwa Telecom was monitoring the bug and had no new information.
- Cht representative — Noted Chunghwa Telecom was monitoring the bug and had no new information.
- Cht representative — Provided a report closure summary describing remediation completion dates and requesting closure, stating there were no remaining open deliverables.
- CCADB representative — Posted a final call for comments and indicated the incident report would be closed approximately 2026-02-12 if no questions were raised.
- Mozilla representative — Shared observations that CHT failed to maintain a comprehensive, fully documented third-party evaluation framework per Criterion 3.1.11, and that remediation appeared responsive.
- Cht representative — Agreed with Mozilla’s characterization and committed to strengthening continuous compliance assurance, tighter coupling between functions, and clearer ownership/accountability for third-party trust-boundary oversight.