Amazon Trust Services self-reports CP/CPS policy-language gap
Amazon Trust Services reported that its CP/CPS did not explicitly state adherence to the latest published version of the Chrome Root Program Policy and the CCADB Policy, as required by Chrome Root Program Policy v1.8 Section 1.1.3. ATS said its existing CP/CPS language said it aligns with the Chrome Root Program Policy, but did not use the phrase "latest published version" and did not mention the CCADB Policy. ATS identified the issue after reviewing similar disclosures from Google Trust Services and Let's Encrypt. It said it was publishing a corrected CP/CPS section and self-reporting the incident for transparency. ATS later said it published CP/CPS v2.7 on 2026-08-19 and was preparing the final report within the stated timeframe.
- ATS identified a CP/CPS language gap regarding explicit adherence to the latest published Chrome Root Program Policy and the CCADB Policy.
- ATS published CP/CPS version 2.7 with corrected language.
- ATS said it was actively preparing the final report for the incident.
- Amazon representative — ATS opened a preliminary incident report describing the CP/CPS gap, said it was self-reporting, and said it would publish a full incident report within 14 days.
- Amazon representative — ATS said it had published CP/CPS v2.7 and was on track to publish the final report within the stipulated timeframe.