Let's Encrypt self-reported missing root program attestation in CP/CPS
This case is a self-reported compliance incident from Internet Security Research Group / Let's Encrypt. The issue was that the ISRG CP/CPS did not explicitly state adherence to the latest Chrome Root Program policy and the CCADB Policy by the policy effective date. Aaron Gable said the team knew about the upcoming requirement and had tracked it in the public CP/CPS repository, but did not make the needed update in time. Let's Encrypt later published ISRG CP/CPS v6.2 with an edit to Section 1.1 intended to bring the document into compliance. The thread says a full incident report was planned for 2026-08-24.
- Chrome Root Program Policy v1.8 effective date for explicit CP/CPS adherence statements.
- Let's Encrypt disclosed that its CP/CPS lacked the required root program attestation language.
- Let's Encrypt published ISRG CP/CPS v6.2 with an edit to Section 1.1 to address the requirement.
- Let's Encrypt planned to publish a full incident report.
- Internet Security Research Group — Opened the bug as a preliminary incident report and stated the CP/CPS lacked explicit adherence statements required by Chrome Root Program Policy v1.8 and CCADB Policy.
- Internet Security Research Group — Identified the source of incident disclosure as self-reported and said a full incident report would follow by 2026-08-24.
- Internet Security Research Group — Said ISRG CP/CPS v6.2 had been published with an edit to Section 1.1 bringing the document into compliance.