Revocation evidence workflow for CAs
Treat revocation evidence as operational proof that the CA followed the CPS procedures required by EN 319 411-1. The CPS needs to state who may submit revocation requests or event reports, how requests are submitted, what confirmation is required, when certificates may be revoked or suspended, how status is distributed, and the maximum delays before relying parties can see the changed status.
For each revocation case, preserve enough evidence to show that the request or report was processed on receipt, authenticated, checked as coming from an authorized source, and converted into updated certificate status within the EN 319 411-1 timing rules.
- Keep the CPS revocation procedure, submission channels, authorized requester list, confirmation rules, and allowed revocation or suspension reasons together.
- Record the received request or event report, intake timestamp, authentication check, authorization basis, decision, reason, approver or trusted role, and any subscriber or subject notification attempt.
- If confirmation cannot be completed within 24 hours, retain the exception procedure used, the actions taken, and the justification recorded for the case.
Clauses 6.2.4 and 6.3.9 ground the CPS revocation procedure, authorized request checks, 24-hour status availability rule, and certificate revocation duties.
Clause 7.10 supports retaining accessible, confidential, integrity-protected operational records for evidence and service continuity.