ANF AC audit finding: outdated CAB reference in continuity plan, with delayed incident-reporting follow-up handled separately
This case concerns ANF AC’s audit finding that its Business continuity plan and disaster recovery document still referenced the former conformity assessment body, CSQA Certificazioni, after ANF AC had moved to DEKRA Testing and Certification. ANF AC said the issue was identified during the annual ETSI EN 319 401 audit, was exclusively documentary, and did not affect issued certificates, OCSP responses, or CRLs. ANF AC updated the document on 2026-02-23 and later posted a full incident report on 2026-06-15. Mozilla and Google participants said the reporting timeline did not meet CCADB expectations and should have been treated as a reportable incident sooner. ANF AC responded that it had initially treated the matter as an audit-related documentary non-conformity, acknowledged the feedback on closure timing, and said the delayed-reporting issue was being handled in separate Bug 2051283. The bug was marked RESOLVED with FIXED, and CCADB posted a final call for comments with closure expected around 2026-07-27.
- ANF AC changed its CAB from CSQA Certificazioni to DEKRA Testing and Certification.
- The annual ETSI EN 319 401 audit identified the outdated CAB reference in the business continuity plan.
- ANF AC updated the business continuity plan to replace the old CAB reference.
- ANF AC posted the full incident report for the documentary non-conformity.
- ANF AC opened separate Bug 2051283 to address delayed incident reporting.
- CCADB posted a final call for comments on the incident report.
- Autoridad de Certificación (ANF AC) — Posted the full incident report describing the outdated CAB reference and stating it was exclusively documentary.
- Community commenter — Said the report timeline did not meet CCADB expectations and cited guidance about not immediately following a full report with a closure summary.
- Autoridad de Certificación (ANF AC) — Explained ANF AC had treated the issue as a documentary ETSI audit finding and disclosed it after the audit statement was published.
- Google representative — Said the non-conformance should have been treated as a reportable incident and asked how ANF AC reviews precedents and lessons learned.
- Autoridad de Certificación (ANF AC) — Said ANF AC reviews public incident reports manually, missed precedent Bug 2043140, and opened Bug 2051283 for the delayed-reporting issue.
- Autoridad de Certificación (ANF AC) — Reported that Bug 2051283 had been updated with its full incident report and that there were no further updates on this bug.
- CCADB representative — Posted a final call for comments and said the report would be closed around 2026-07-27 if there were no further questions.