Let's Encrypt self-reported CP/CPS compliance gap for missing root program and CCADB attestation
This case is a self-reported compliance incident from Internet Security Research Group / Let's Encrypt. The issue was that the ISRG CP/CPS did not explicitly state adherence to the Chrome Root Program Policy and the CCADB Policy by the required effective date. Let’s Encrypt said it had tracked the requirement in its public CP/CPS repository, but failed to make the necessary updates in time. The full incident report states the non-compliance period ran from 2026-06-15 to 2026-08-13 and that zero certificates were affected. Let’s Encrypt published ISRG CP/CPS v6.2 on 2026-08-13 with the required attestation language added. As of the latest thread activity, the remediation items are still in progress, one follow-up item has been completed, and Let’s Encrypt requested the next update date of 2026-11-20.
- Chrome Root Program Policy v1.8 requirement for explicit CP/CPS adherence statements became effective.
- Let's Encrypt disclosed that its CP/CPS lacked the required root program and CCADB adherence statements.
- Let's Encrypt published ISRG CP/CPS v6.2 with the required attestation language added.
- Let's Encrypt published a full incident report.
- Let's Encrypt said review steps for CCADB and root program policies had been added to the PMA quarterly meeting template and requested a next update date of 2026-11-20.
- Internet Security Research Group — Opened a preliminary incident report and said the CP/CPS lacked explicit adherence statements required by Chrome Root Program Policy v1.8 and the CCADB Policy.
- Internet Security Research Group — Stated the disclosure was self-reported and said a full incident report would follow by 2026-08-24.
- Internet Security Research Group — Said ISRG CP/CPS v6.2 had been published with an edit to Section 1.1 that brought the document into compliance with Section 1.1.3 of the Chrome Root Program Policy.
- Internet Security Research Group — Posted the full incident report, including the non-compliance dates, zero affected certificates, and confirmation that the issue was a strict policy compliance violation.
- Internet Security Research Group — Reported that remediation items remain in progress and listed action items with one complete and others ongoing.
- Internet Security Research Group — Said review steps for CCADB and root program policies had been added to the PMA quarterly meeting template and requested a next update of 2026-11-20.
- Internet Security Research Group — Said there were no significant updates and that all three remediation items due 2026-11-20 were still in progress.