Microsoft PKI Services self-reported CPS annual update lapse and missing Issuing CAs
Microsoft PKI Services self-reported that its third-party code signing CPS was not republished by the annual deadline and that four Issuing CAs were omitted from the CPS. The company said it became aware of the issue on 2026-07-30. It stated that no end-entity certificate is known to have been misissued as a result of either omission, and that no certificate content, validation, or key management deficiency was identified. Microsoft said an updated CPS including all four Issuing CAs had been drafted and was in approval, and that a full incident report would follow within 14 days. The thread cites CSBR publication requirements and Microsoft Trusted Root Program policy-document currency and accuracy requirements as the relevant obligations.
- Microsoft_PKI_ThirdParty_CPS v1.0.5 was last published.
- Four subordinate Issuing CAs under Microsoft ID Verified Code Signing PCA 2021 were created.
- The CPS annual republication deadline passed without an updated version or dated changelog entry.
- Microsoft became aware of the CPS update omissions.
- Microsoft Corporation — Microsoft filed a preliminary incident report describing the missed annual CPS republication and the omission of four Issuing CAs, and said a full incident report would follow within 14 days.