Microsoft PKI Services self-reported CPS annual review lapse and omission of four Issuing CAs; one remediation action remains open
Microsoft PKI Services self-reported that its third-party code signing CPS missed its annual review/update deadline and failed to list four Issuing CAs. The company said it became aware of the issue on 2026-07-30 and that the two omissions had separate causes: a monitoring gap for the annual review and a workflow gap for the missing Issuing CAs. Microsoft stated that no end-entity certificate was misissued and that no revocation is required. It published CPS v1.0.6 on 2026-08-05, which closed the document publication issue. The thread is now tracking remediation actions, and as of the latest update only one action item remains open: replacing the stop-gap annual-review monitoring script.
- Microsoft_PKI_ThirdParty_CPS v1.0.5 was last published.
- Four subordinate Issuing CAs under Microsoft ID Verified Code Signing PCA 2021 were created.
- The CPS annual review deadline passed without an updated publication.
- Microsoft published CPS v1.0.6.
- Microsoft Corporation — Microsoft filed a preliminary incident report describing the missed annual CPS republication and the omission of four Issuing CAs, and said a full incident report would follow within 14 days.
- Microsoft Corporation — Microsoft filed the full incident report, explained the separate causes for the two omissions, and said the non-compliance ended with publication of v1.0.6.
- Microsoft Corporation — Microsoft posted a weekly status update saying one remediation action item was closed and two remained open.
- Microsoft Corporation — Microsoft posted another status update saying two of the three action items were completed and one remained open.
- Microsoft Corporation — Microsoft asked for the next update date to be set to 2026-10-05 to match the due date of the remaining action item.