- Supports the need for protected, complete, retrievable records and monitoring or regular review of audit logs.
"REQ-7.9.1-05X"
A focused evidence-file guide for certification authorities preparing ETSI EN 319 411-1 audit logging, registration, revocation, CA key lifecycle, and archival records.
Use this as implementation support for audit preparation and evidence collection. Confirm final audit scope with the applicable scheme, assessor, and CP/CPS commitments.
Structured answer sets in this page tree.
Cited legal and guidance references.
An ETSI EN 319 411-1 audit file should let an assessor trace certificate-service operation from policy commitments to actual records. For this topic, the core file is not a generic compliance binder: it is the set of logs, registration records, revocation records, CA key lifecycle evidence, archival controls, and CP/CPS references that show how the certification authority operated during the assessment period.
Define which certification authority service, certificate policies, certificate profiles, registration authority arrangements, revocation services, repositories, and assessment period the file covers. ETSI EN 319 411-1 separates requirements by functions such as registration, certificate lifecycle operations, revocation, CA key management, audit logging, and records archival, so the file should make those boundaries explicit before evidence is collected.
The scope page should link the CP, CPS, subscriber-facing terms, repository locations, applicable certificate policy identifiers, and any RA delegation or outsourced service evidence that affects the records under review. Keep unsupported assumptions out of the public claim: if an item is included because a customer contract, browser root program, or national scheme requires it, name that separate trigger instead of attributing it to ETSI EN 319 411-1.
Build the file around the records ETSI EN 319 411-1 calls out for audit logging and archival review. The strongest audit file shows both the event record and the control that made the record reliable: the procedure, owner, timestamp source, log protection, access control, archive location, and review history.
For registration evidence, include the records needed to show how applicant information was received and validated, where supporting documents and subscriber agreements are stored, which entity accepted the application, and which TSP or RA submitted it. For operational evidence, include security-event logs, PKI access attempts, CA key lifecycle logs, certificate lifecycle events, revocation requests and resulting actions, and any subject-device preparation evidence that applies to NCP+ services.
Use this ETSI EN 319 411-1 page to organize registration records, CA key lifecycle logs, certificate lifecycle evidence, revocation records, and archive controls before assessor review.
Convert audit evidence gaps into assigned evidence requests and review-ready CA records.
Resolve clause, scope, archive, and evidence questions against the cited ETSI source material.
Review CA audit-file scope, missing records, archive controls, and assessor handoff steps with Sorena.
ETSI EN 319 411-1 gives a concrete retention rule for the records named in clause 6.4.6: retain them for at least seven years after any certificate based on those records ceases to be valid. The audit file should therefore show both the rule and the mechanism: where the records are archived, how they are protected, who can retrieve them, and how the CA prevents easy deletion or destruction during the required retention period.
ETSI EN 319 401 adds general evidence controls that matter when the audit file is challenged later. Current and archived service-operation records need confidentiality and integrity protection, records should be archived according to disclosed business practices, event times should be recorded precisely for significant environmental, key management, and clock synchronization events, and audit-log time should be synchronized with UTC at least once a day.
Before handing the file to an assessor, test whether a reviewer can move from each CP/CPS commitment to the operational record without asking the CA team to reconstruct context. The file should be readable as evidence of actual operation, not just a list of policies.
Use this checklist for the evidence pack only; it does not supersede the applicable assessment scheme, ETSI TR audit checklist, browser-program criteria, or legal obligations that may apply outside EN 319 411-1.
Most audit-file problems are traceability problems. A CA may have logs, policy documents, and tickets, but still fail to show which record proves which EN 319 411-1 requirement for the assessed service and period. Close those gaps before the formal evidence request starts.
Narrow claims when the grounding or evidence is narrow. For example, a revocation log for one CA hierarchy does not prove revocation operation for another hierarchy, and a registration sample does not prove every RA arrangement unless the audit file explains why the same controlled process applies.
"REQ-7.9.1-05X"
"GEN-6.4.5-06"