CA/Audit Statements: Difference between revisions

Jump to navigation Jump to search
m
formatting to clarify steps
(Replaced section with text provided by ACAB'c representatives)
m (formatting to clarify steps)
Line 178: Line 178:


==== Standard Check ====
==== Standard Check ====
# Require the ETSI auditor to provide as evidence links to their
* Require the ETSI auditor to provide as evidence links to their
## National Accreditation Body (NAB) and their
** National Accreditation Body (NAB) and their
## accreditation documentation, listed by the NAB on their webpages.
** accreditation documentation, listed by the NAB on their webpages.
# Perform confirm the following:
* Confirm the following:
## The NAB is listed as “full member” under https://european-accreditation.org/ea-members/directory-of-ea-members-and-mla-signatories/
** The NAB is listed as “full member” under https://european-accreditation.org/ea-members/directory-of-ea-members-and-mla-signatories/
## The accreditation documentation was issued by that NAB (their webpages),
** The accreditation documentation was issued by that NAB (their webpages),
## The CABs accreditation documentation explicitly refers to:
** The CABs accreditation documentation explicitly refers to all of the following:
### ETSI EN 319 403 as the relevant standard for the CAB to perform ETSI audits, allocated under ISO 17065 as framing standard. Option on top: The EU eIDAS Regulation 910/2014 can be listed to supplement that information but – alone – is not sufficient to demonstrate ETSI auditors qualification. plus
*** ETSI EN 319 403  
### ETSI EN 319 401 and ETSI EN 319 411-1, as standards to audit publicly trusted CA/Trust Service Provider against and (optional on top)
**** as the relevant standard for the CAB to perform ETSI audits, allocated under ISO 17065 as framing standard.  
### ETSI EN 319 411-2, as standard to audit publicly trusted CA/Trust Service Provider against, which issue QWACS certificates according to the EU eIDAS Regulation 910/2014.
**** The EU eIDAS Regulation 910/2014 can be listed to supplement that information but – alone – is not sufficient to demonstrate ETSI auditors qualification.  
*** ETSI EN 319 401 and ETSI EN 319 411-1
**** as standards to audit publicly trusted CA/Trust Service Provider
*** ETSI EN 319 411-2
**** as standard to audit publicly trusted CA/Trust Service Provider
**** which issue QWACS certificates according to the EU eIDAS Regulation 910/2014.


==== Comprehensive Check ====
==== Comprehensive Check ====
Confirmed users, Administrators
5,526

edits

Navigation menu