- Supports protected, complete, retrievable records and regular review of logs for unusual or unwanted trends.
"The logs shall be regularly reviewed"
A focused evidence-file guide for certification authorities preparing ETSI EN 319 411-1 audit logging, registration, revocation, CA key lifecycle, and archival records.
This serves as implementation support for audit preparation and evidence collection. Confirm final audit scope with the applicable scheme, assessor, and CP/CPS commitments.
Structured answer sets in this page tree.
Cited legal and guidance references.
An assessor should be able to start with one CP/CPS commitment and use the to reach the corresponding event record, system control, owner, and retention rule without relying on oral context. For ETSI EN 319 411-1 V1.5.1 (2025-04), organize the file around the assessed CA service and period, then separate registration, certificate and key lifecycle, revocation, security-event, archive, continuity, and termination evidence. The standard defines requirements for the service; the applicable assessment scheme and assessor determine the final evidence request.
Define which certification authority service, certificate policies, certificate profiles, registration authority arrangements, revocation services, repositories, and assessment period the file covers. ETSI EN 319 411-1 separates requirements by functions such as registration, certificate lifecycle operations, revocation, CA key management, audit logging, and records archival, so the record should make those boundaries explicit before evidence is collected.
The scope page should link the CP, CPS, subscriber-facing terms, repository locations, applicable certificate policy identifiers, and any RA delegation or outsourced service evidence that affects the records under review. Keep unsupported assumptions out of the public claim: if an item is included because a customer contract, browser root program, or national scheme requires it, name that separate trigger instead of attributing it to ETSI EN 319 411-1.
Build the file around the records ETSI EN 319 411-1 calls out for audit logging and archival review. For each event record, include the control that makes it reliable: the procedure, owner, timestamp source, log protection, access control, archive location, and review history.
For registration evidence, include the records needed to show how applicant information was received and validated, where supporting documents and subscriber agreements are stored, which entity accepted the application, and which TSP or RA submitted it. For operational evidence, include security-event logs, PKI access attempts, CA key lifecycle logs, certificate lifecycle events, revocation requests and resulting actions, and any subject-device preparation evidence that applies to NCP+ services.
This ETSI EN 319 411-1 page helps organize registration records, CA key lifecycle logs, certificate lifecycle evidence, revocation records, and archive controls before assessor review.
Convert audit evidence gaps into assigned evidence requests and review-ready CA records.
Resolve clause, scope, archive, and evidence questions against the cited ETSI source material.
Review CA audit-file scope, missing records, archive controls, and assessor handoff steps with Sorena.
Apply the clause 6.4.6 seven-year minimum only to the records it names: logs for the lifecycle of keys managed by the CA, including subject key pairs generated by the CA, and the documentation identified in clause 6.3.4. The period runs until at least seven years after any certificate based on those records ceases to be valid. For registration, revocation, certificate-lifecycle, and other service records, document the retention period in the practice statement and apply the period notified in the terms and conditions, together with any longer legal, scheme, policy, or contractual rule.
Current ETSI EN 319 401 adds general controls for all relevant service-operation evidence. Keep records accessible for an appropriate period, protect the confidentiality and integrity of current and archived records, archive them completely under disclosed practices, synchronize audit-log time with UTC at least daily, and prevent easy deletion or destruction during the required holding period.
Before handing the file to an assessor, test whether a reviewer can move from each CP/CPS commitment to the operational record without asking the CA team to reconstruct context. The record should be readable as evidence of actual operation, not just a list of policies.
This checklist covers the evidence pack only; it does not supersede the applicable assessment scheme, ETSI TR audit checklist, browser-program criteria, or legal obligations that may apply outside EN 319 411-1.
A CA may have logs, policy documents, and tickets but still fail to show which record proves which EN 319 411-1 requirement for the assessed service and period. Close those traceability gaps before the formal evidence request starts.
Narrow claims when the cited requirement or operational evidence is narrow. For example, a revocation log for one CA hierarchy does not prove revocation operation for another hierarchy, and a registration sample does not prove every RA arrangement unless the explains why the same controlled process applies.
"The logs shall be regularly reviewed"
"GEN-6.4.5-06"