TLS Certificate Evidence Auditors Actually Want
SOC 2, PCI, ISO, HIPAA - the controls converge on the same set of questions about cert inventory, lifecycle, and alerting. What continuous evidence collection looks like.
SOC 2, PCI, ISO, HIPAA - the controls converge on the same set of questions about cert inventory, lifecycle, and alerting. What continuous evidence collection looks like.
An annual WebTrust audit found four sampled certificates with no evidence that multi-perspective domain validation was performed. The full investigation found 2,700, and SSL.com revoked them all within a day. What MPIC is, why you could not have seen this one coming, the second SSL.com incident you can check for yourself, and what TLS Radar's new revocation checking does about it.
In the two weeks ending August 27, 2026, more than 30 public CAs logged 69 compliance incidents in Mozilla's tracker - delayed revocations, country-field and clientAuth misissuance, and the process failures that precede distrust. Every incident sourced to its Bugzilla bug, grouped by what it means for the certificates your business depends on.
One CA revoked 1.7 million certificates in 24 hours on April 3, 2026, following a compliance-driven mandatory revocation event. Five categories of mass revocation triggers, the timeline between revocation and customer impact, and why internal monitoring misses all of them.
A mid-sized public CA's internal compliance documentation fell out of sync with its issuance system, forcing two separate mass revocations in July 2026. What happened, why it isn't a HARICA-specific problem, and how to check whether you're exposed to the next one.
Subscribe via RSS.