SECOND MEASUREMENT SM-012

Certificate authorities get 92 days to file their audits. Most file in the last week, one in eleven files late, and Windows still trusts a root whose last audit ended in 2019

Markovian ProtocolMeasured 2026-10-03Status: sent to the CCADB steering committee and Microsoft’s root program 2026-10-03, responses pendingDOI: 10.5281/zenodo.23123265

Every certificate authority a browser trusts has to be audited once a year, and the four root programs that run the shared database of trusted CAs, the CCADB, give each CA 92 days after the audit period ends to file the auditor’s report. We read the deadline off the CCADB’s own export of 10,317 certificate records. Of 119 current audit statements for trusted CAs, 108 are dated inside the window, but 34 of them on days 80 to 89 and 10 on the last three days; the 90th percentile lands on day 92 itself. Eleven are dated past the deadline. Two came with an auditor’s letter, one of Thailand’s three and Firmaprofesional’s; two more, D-TRUST and PKIoverheid, opened incident reports instead; seven, Thailand’s other two, MULTICERT, Entrust, Catalonia’s CATCert and Brazil’s ITI twice, have nothing on file at all. Then the other direction: Mozilla and Chrome trust no root whose newest audit is more than 15 months old. Apple trusts six. Microsoft trusts 24, from 15 CAs, and the oldest, Certinomis, was last audited in December 2019.

The short version

Disclosure: Markovian Protocol holds no financial position in any organisation named here, was paid by no one for this work, and showed it to no one before publication except the organisations measured. How we work.

Details

The CCADB is the Common CA Database, run jointly by Mozilla, Google, Apple and Microsoft. Every CA in their root stores keeps its records there: each root and intermediate certificate, which programs include it, and for each kind of audit (WebTrust or ETSI “standard” audits, the TLS Baseline Requirements audit, and others) the period covered, the date on the auditor’s statement, the firm, and a link to the report. The CCADB publishes the whole thing as a CSV. We took the 3 October export, kept records that are not revoked, carry their own audit rather than inheriting a parent’s, and are included or trusted by at least one program, and counted each distinct audit statement once. Lateness is the statement date minus the period end. A statement cannot be uploaded before it is dated, so a statement dated past day 92 was uploaded past day 92; statements dated inside the window may still have been uploaded late, which we can’t see. For the second table we took every root each program marks as included and looked at the newest audit period on its record: if that ended more than 365 plus 92 days ago, the next annual statement is overdue by the program’s own rule, unless the CA filed a letter.

What they said, what we found

The ruleWe found
CCADB policy 5.2: “An authoritative English language version of publicly available audit information MUST be uploaded to the CCADB no later than 92 calendar days from the point-in-time date or the end date of the period of time. If the audit information cannot be provided by this deadline, the CA Owner MUST instead upload an explanatory letter signed by the Qualified Auditor to Bugzilla.”1108 of 119 standard statements dated inside the window; 11 dated after it: 2 with a letter, 2 with an incident report, 7 with nothing. TLS audits: 92 of 98 inside, 6 past.
Microsoft Trusted Root Program: participants “must provide to Microsoft evidence of a Qualifying Audit … before conducting commercial operations and thereafter on an annual basis.”324 roots Microsoft includes today carry a newest audit older than 15 months on their CCADB record; one ended in 2019, one in 2022, eight in the first half of 2024.
Mozilla Root Store Policy 3.4: the annual self-assessment “MUST be completed and submitted to the CCADB within 92 calendar days” of the BR audit period end.2Mozilla’s own store is clean on the measure we could take: 0 of 172 included roots have an audit older than 15 months. Chrome: 0 of 101.

Auditing to the deadline

The distribution says more than the pass rate. CAs don’t file when the audit is done; they file when the clock is about to run out.

Days from period end to the auditor’s statementStatementsShare
0 to 301513%
31 to 602420%
61 to 792521%
80 to 893429%
90 to 92108%
93 to 12054%
over 12065%

119 standard audit statements (WebTrust or ETSI) on trusted, non-revoked records with their own audits, period end at least 92 days before 3 October 2026. Median 76 days, 75th percentile 87, 90th percentile 92.

The 11 past the line, and what is on file for them:

CAPeriod endStatement datedDaysAuditorTrusted byLetter?
Thailand National Root Certificate Authority (Electronic Transactions Development Agency)2025-07-302026-03-26239BDO International LimitedMicrosoftletter filed 14 Apr 2026 (bug 2031562), 5½ months after the first deadline
Thailand National Root Certificate Authority (Electronic Transactions Development Agency)2025-08-312026-04-07219BDO Consulting Sdn. Bhd.Microsoftletter filed 14 Apr 2026 (bug 2031562), 5½ months after the first deadline
Government of Brazil, Instituto Nacional de Tecnologia da Informação (ITI)2021-11-302022-05-18169Ernst & Young, LLPMicrosoftno letter on file
Thailand National Root Certificate Authority (Electronic Transactions Development Agency)2026-02-282026-07-31153BDO International LimitedMicrosoftletter filed 14 Apr 2026 (bug 2031562), 5½ months after the first deadline
Government of Brazil, Instituto Nacional de Tecnologia da Informação (ITI)2022-09-082023-01-30144Ernst & Young, LLPMicrosoftno letter on file
Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert)2024-03-282024-07-29123DEKRA Testing and Certification, S.A.U.Microsoftno letter on file
Entrust2025-02-282025-06-27119DeloitteApple, Microsoftno letter; Sectigo posted draft reports to Bugzilla in Nov 2025 (bug 1999214)
Autoridad de Certificacion Firmaprofesional2026-03-272026-07-15110DEKRA Testing and Certification, S.A.U.Apple, Chrome, Microsoft, Mozillaletter filed 16 Jul 2026 (bug 2055439), 19 days after the deadline
MULTICERT2026-03-312026-07-17108BSIMicrosoftno letter on file
Government of The Netherlands, PKIoverheid (Logius)2026-05-312026-09-10102TÜV AustriaMicrosoft, Mozillaincident report 21 Sep 2026 (bug 2074032, tagged audit-delay)
D-TRUST2025-10-072026-01-15100TÜV NORD CERT GmbHApple, Chrome, Microsoft, Mozillaincident report 20 Jan 2026 (bug 2011430, tagged audit-delay)

Thailand filed one auditor’s letter on 14 April 2026 (bug 2031562), for the statement whose period ended 31 August 2025; its other two late statements have none, itself five and a half months after the first of those deadlines. D-TRUST and PKIoverheid opened compliance incidents tagged audit-delay (bugs 2011430 and 2074032) rather than the auditor letter the policy names; both are public, and we count them as disclosed. Entrust’s statement covers the period before its TLS business passed to Sectigo; Sectigo posted draft reports for the following period to Bugzilla in November 2025 and the CCADB record has not moved since.

How old an audit can be and still be trusted

Four root programs, one database, the same records. For each root a program includes today, the age of the newest audit period on file:

Root programRoots includedNewest audit, median age90th percentileOldestRoots over 15 monthsFrom CAs
Mozilla172197 d398 d437 d00
Chrome101217 d398 d429 d00
Apple144188 d398 d841 d63
Microsoft331217 d406 d2,486 d2415

“Over 15 months” is 365 + 92 days: a year since the last period ended plus the filing window, so the next annual statement is past due. Five Microsoft roots carry no standard audit date at all and are not counted.

Apple’s six: SwissSign Silver CA G2 (841 days, removed by Mozilla and Chrome), DigiCert’s Verified Mark root (763 days, a mail-logo root no other program carries), and four Entrust AffirmTrust roots at 582 days, which Mozilla and Chrome removed in 2024 and Microsoft also keeps. Microsoft’s twelve oldest:

CARootNewest audit period endedYears agoStatus elsewhere
Docaposte Certinomis SASCertinomis - Root CA2019-12-136.8Mozilla: Removed, Apple: Removed
Government of Brazil, Instituto Nacional de Tecnologia da Informação (ITI)Autoridade Certificadora Raiz Brasileira v102022-09-084.1not included elsewhere
Netrust Pte LtdNetrust Root CA 22024-02-192.6not included elsewhere
AC Camerfirma, S.A.Global Chambersign Root - 20082024-03-012.6Mozilla: Removed, Apple: Blocked
ZetesZETES TSP ROOT CA 0012024-03-102.6not included elsewhere
Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA)CCA India 20222024-03-202.5not included elsewhere
Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA)CCA India 2022 SPL2024-03-202.5not included elsewhere
Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert)EC-ACC2024-03-282.5Mozilla: Removed
Consejo General de la Abogacía EspañolaACA ROOT2024-03-312.5not included elsewhere
První certifikační autorita, a.s.I.CA Root CA/ECC 12/20162024-05-092.4not included elsewhere
SI-TRUSTSI-TRUST Root2024-12-151.8not included elsewhere
Carillon Information Security Inc.Carillon PKI Services G2 Root CA 12025-02-091.6not included elsewhere

Most of these roots are trusted by Microsoft alone. That is the pattern: the two programs that distrust publicly and quickly, Mozilla and Chrome, have no stale audits; the two that don’t have 30 between them, and the longest-standing ones are roots the others already dropped.

How this ends

It ends per CA and per program: a late statement gets its letter or its upload, the daily recheck of the CCADB export drops it from the eleven; a root with a stale audit gets a new one or leaves the store, and the 24 falls. The CCADB could end the ambiguity for good by publishing the upload date, which is the first question on the page.

The evidence

Every quote below was copied from the source and checked against a saved copy, fetched 2026-10-03. The CCADB export, the policy pages, the Bugzilla threads and the scripts are published next to this page (SHA256SUMS).

Exhibit 1 · The rule

“An authoritative English language version of publicly available audit information MUST be uploaded to the CCADB no later than 92 calendar days from the point-in-time date or the end date of the period of time. If the audit information cannot be provided by this deadline, the CA Owner MUST instead upload an explanatory letter signed by the Qualified Auditor to Bugzilla in the ‘CA Documents’ component no later than 92 calendar days from the point-in-time date or the end date of the period of time.”

ccadb.org/policy, section 5.2 · saved copy ccadb_policy.html

Exhibit 2 · The data

CCADB AllCertificateRecordsCSVFormatV5, 2026-10-03: 10,317 records, 89 columns
  Standard Audit Period End Date   Standard Audit Statement Date   Standard Audit URL   Audit Firm
  Mozilla Status / Chrome Status / Apple Status / Microsoft Status   Revocation Status   Audits Same as Parent

D-TRUST            period end 2025-10-07   statement 2026-01-15   100 days   TÜV NORD CERT   Apple, Chrome, Microsoft, Mozilla
Entrust            period end 2025-02-28   statement 2025-06-27   119 days   Deloitte        Apple, Microsoft
Certinomis         newest period end 2019-12-13   Microsoft: Included   Mozilla: Removed   Apple: Removed

export ccadb_AllCertificateRecordsCSVFormatV5.csv.gz · computed tables audit_compliance.json, per_program_roots.json, lag_histogram.json

Exhibit 3 · Where the letters go

Bugzilla, product "CA Program", component "CA Documents", opened since 2025-01-01: 35 bugs
  2031562  2026-04-14  Thailand NRCA - Explanation for delay in WebTrust Assurance report
  2055439  2026-07-16  Firmaprofesional: 2026 audit-delay explanatory letter
  2051532  2026-06-30  SHECA - Explanatory Letter for Delay of WebTrust Seal
  2067507  2026-08-29  Chunghwa Telecom - Explanatory Letter for delay WebTrust for CA seals
  2031062  2026-04-11  Sri Lanka CERT - Audit Statement Delay Explanation Letter
  2076925  2026-09-30  Documents for SSL.com   (period ended 2026-06-30; filed on day 92)

bugzilla_ca_documents.json · threads 2031562, 2055439, 1999214 (Entrust), 2076925 (SSL.com) · all 23 bugs tagged audit-delay: audit_delay_bugs.txt

Exhibit 4 · Microsoft’s own rule

“Program Participants must provide to Microsoft evidence of a Qualifying Audit … for each root, unconstrained subordinate CA, and cross-signed certificate, before conducting commercial operations and thereafter on an annual basis.”

learn.microsoft.com/en-us/security/trusted-root/program-requirements · saved copy microsoft_root_program.html

Our questions

Sent on 3 October 2026 to the CCADB steering committee, which represents all four root programs, and to Microsoft’s Trusted Root Program. Answers will be printed here as written.

  1. Does the CCADB record the date an audit statement was uploaded? If so, can it be added to the public export, so compliance with 5.2 can be checked by anyone rather than bounded from the statement date?
  2. For the seven late statements with no letter and no incident report (Thailand’s July 2025 and February 2026 periods, MULTICERT, Entrust, CATCert, Brazil’s ITI), was a letter received by another route?
  3. Microsoft: the Certinomis root’s newest audit on its CCADB record ended on 13 December 2019. Is a newer audit on file with Microsoft, and if so, why isn’t it in the CCADB?
  4. Microsoft and Apple: the four Entrust AffirmTrust roots show a newest period end of 28 February 2025, and Sectigo’s drafts for the following period sit in Bugzilla. What is the current audit status of those roots in your stores?
  5. Is “15 months without a current audit” a condition any of the four programs treats as grounds for removal, and if so, how are the 30 roots here still included?

Their reply, scored

Waiting for replies. When they come, each question gets marked answered, partly answered or not answered, and the replies go here in full.

Disclosure timeline

3 OctPublished; sent to the CCADB steering committee and Microsoft’s root program with the five questions above.

Waiting since 3 Oct.

What we can’t be sure of

Run it yourself

Python 3 standard library. One 11 MB download from the CCADB and a few Bugzilla API calls; under a minute.

curl -sL https://ccadb.my.salesforce-sites.com/ccadb/AllCertificateRecordsCSVFormatV5 -o ccadb_v5.csv
python3 audit_deadlines.py     # statements, lateness by statement date, overdue CA owners, per audit type
python3 per_program.py         # per root program: age of the newest audit on each included root

Reproduced from the public repository on 3 October 2026 on a clean machine: exact (119 statements, 11 late, 90th percentile day 92; Mozilla 0 of 172, Chrome 0 of 101, Apple 6 of 144, Microsoft 24 of 331). Full table on the track record.

What you can do with this

References

  1. CCADB. CCADB Policy, section 5.2 Audit Statement Content. ccadb.org/policy.
  2. Mozilla. Mozilla Root Store Policy, section 3.4 Compliance Self-Assessments. mozilla.org.
  3. Microsoft. Program Requirements, Microsoft Trusted Root Program, section 2 Audit Requirements. learn.microsoft.com.
  4. CCADB. All Certificate Records (CSV, V5). ccadb.my.salesforce-sites.com.
  5. Bugzilla, product CA Program, component CA Documents.

Cite as

@misc{markovian-sm012,
  author = {{Markovian Protocol}},
  title  = {Audit filing deadlines in the CCADB, October 2026},
  number = {SM-012},
  doi    = {10.5281/zenodo.23123265},
  year   = {2026},
  month  = oct,
  url    = {https://markovianprotocol.com/measurements/sm-012.html}
}