SECOND MEASUREMENT SM-012
Certificate authorities get 92 days to file their audits. Most file in the last week, one in eleven files late, and Windows still trusts a root whose last audit ended in 2019
Every certificate authority a browser trusts has to be audited once a year, and the four root programs that run the shared database of trusted CAs, the CCADB, give each CA 92 days after the audit period ends to file the auditor’s report. We read the deadline off the CCADB’s own export of 10,317 certificate records. Of 119 current audit statements for trusted CAs, 108 are dated inside the window, but 34 of them on days 80 to 89 and 10 on the last three days; the 90th percentile lands on day 92 itself. Eleven are dated past the deadline. Two came with an auditor’s letter, one of Thailand’s three and Firmaprofesional’s; two more, D-TRUST and PKIoverheid, opened incident reports instead; seven, Thailand’s other two, MULTICERT, Entrust, Catalonia’s CATCert and Brazil’s ITI twice, have nothing on file at all. Then the other direction: Mozilla and Chrome trust no root whose newest audit is more than 15 months old. Apple trusts six. Microsoft trusts 24, from 15 CAs, and the oldest, Certinomis, was last audited in December 2019.
- CCADB policy 5.2: audit information “MUST be uploaded to the CCADB no later than 92 calendar days” after the audit period ends, or an auditor-signed letter explaining the delay goes to Bugzilla by the same day.
- 119 standard audit statements on trusted records: 108 inside 92 days, 11 past. Median lag 76 days. 34 dated on days 80 to 89, 10 on days 90 to 92. The 90th percentile is day 92.
- Of the 11 late: Firmaprofesional filed the letter the policy asks for, and Thailand’s national CA filed one covering one of its three; D-TRUST (100 days, trusted by all four programs) and PKIoverheid (102) opened incident reports instead. Seven have nothing on file: Thailand’s other two (239 and 153), MULTICERT (108), Entrust (119), Catalonia’s CATCert (123), Brazil’s ITI (144 and 169).
- Roots whose newest audit ended more than 15 months ago: Mozilla 0 of 172, Chrome 0 of 101, Apple 6 of 144, Microsoft 24 of 331. Microsoft’s own rule says audits “thereafter on an annual basis”.
- The oldest audit on a root Microsoft includes today ended on 13 December 2019; Mozilla and Apple removed that root. Four Entrust roots that Mozilla and Chrome removed sit in Apple’s and Microsoft’s stores with audits 19 months old.
- The statement date is the earliest an upload could happen, so these counts are floors. The upload date itself is not public.
Disclosure: Markovian Protocol holds no financial position in any organisation named here, was paid by no one for this work, and showed it to no one before publication except the organisations measured. How we work.
The CCADB is the Common CA Database, run jointly by Mozilla, Google, Apple and Microsoft. Every CA in their root stores keeps its records there: each root and intermediate certificate, which programs include it, and for each kind of audit (WebTrust or ETSI “standard” audits, the TLS Baseline Requirements audit, and others) the period covered, the date on the auditor’s statement, the firm, and a link to the report. The CCADB publishes the whole thing as a CSV. We took the 3 October export, kept records that are not revoked, carry their own audit rather than inheriting a parent’s, and are included or trusted by at least one program, and counted each distinct audit statement once. Lateness is the statement date minus the period end. A statement cannot be uploaded before it is dated, so a statement dated past day 92 was uploaded past day 92; statements dated inside the window may still have been uploaded late, which we can’t see. For the second table we took every root each program marks as included and looked at the newest audit period on its record: if that ended more than 365 plus 92 days ago, the next annual statement is overdue by the program’s own rule, unless the CA filed a letter.
What they said, what we found
| The rule | We found |
|---|---|
| CCADB policy 5.2: “An authoritative English language version of publicly available audit information MUST be uploaded to the CCADB no later than 92 calendar days from the point-in-time date or the end date of the period of time. If the audit information cannot be provided by this deadline, the CA Owner MUST instead upload an explanatory letter signed by the Qualified Auditor to Bugzilla.”1 | 108 of 119 standard statements dated inside the window; 11 dated after it: 2 with a letter, 2 with an incident report, 7 with nothing. TLS audits: 92 of 98 inside, 6 past. |
| Microsoft Trusted Root Program: participants “must provide to Microsoft evidence of a Qualifying Audit … before conducting commercial operations and thereafter on an annual basis.”3 | 24 roots Microsoft includes today carry a newest audit older than 15 months on their CCADB record; one ended in 2019, one in 2022, eight in the first half of 2024. |
| Mozilla Root Store Policy 3.4: the annual self-assessment “MUST be completed and submitted to the CCADB within 92 calendar days” of the BR audit period end.2 | Mozilla’s own store is clean on the measure we could take: 0 of 172 included roots have an audit older than 15 months. Chrome: 0 of 101. |
Auditing to the deadline
The distribution says more than the pass rate. CAs don’t file when the audit is done; they file when the clock is about to run out.
| Days from period end to the auditor’s statement | Statements | Share |
|---|---|---|
| 0 to 30 | 15 | 13% |
| 31 to 60 | 24 | 20% |
| 61 to 79 | 25 | 21% |
| 80 to 89 | 34 | 29% |
| 90 to 92 | 10 | 8% |
| 93 to 120 | 5 | 4% |
| over 120 | 6 | 5% |
119 standard audit statements (WebTrust or ETSI) on trusted, non-revoked records with their own audits, period end at least 92 days before 3 October 2026. Median 76 days, 75th percentile 87, 90th percentile 92.
The 11 past the line, and what is on file for them:
| CA | Period end | Statement dated | Days | Auditor | Trusted by | Letter? |
|---|---|---|---|---|---|---|
| Thailand National Root Certificate Authority (Electronic Transactions Development Agency) | 2025-07-30 | 2026-03-26 | 239 | BDO International Limited | Microsoft | letter filed 14 Apr 2026 (bug 2031562), 5½ months after the first deadline |
| Thailand National Root Certificate Authority (Electronic Transactions Development Agency) | 2025-08-31 | 2026-04-07 | 219 | BDO Consulting Sdn. Bhd. | Microsoft | letter filed 14 Apr 2026 (bug 2031562), 5½ months after the first deadline |
| Government of Brazil, Instituto Nacional de Tecnologia da Informação (ITI) | 2021-11-30 | 2022-05-18 | 169 | Ernst & Young, LLP | Microsoft | no letter on file |
| Thailand National Root Certificate Authority (Electronic Transactions Development Agency) | 2026-02-28 | 2026-07-31 | 153 | BDO International Limited | Microsoft | letter filed 14 Apr 2026 (bug 2031562), 5½ months after the first deadline |
| Government of Brazil, Instituto Nacional de Tecnologia da Informação (ITI) | 2022-09-08 | 2023-01-30 | 144 | Ernst & Young, LLP | Microsoft | no letter on file |
| Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) | 2024-03-28 | 2024-07-29 | 123 | DEKRA Testing and Certification, S.A.U. | Microsoft | no letter on file |
| Entrust | 2025-02-28 | 2025-06-27 | 119 | Deloitte | Apple, Microsoft | no letter; Sectigo posted draft reports to Bugzilla in Nov 2025 (bug 1999214) |
| Autoridad de Certificacion Firmaprofesional | 2026-03-27 | 2026-07-15 | 110 | DEKRA Testing and Certification, S.A.U. | Apple, Chrome, Microsoft, Mozilla | letter filed 16 Jul 2026 (bug 2055439), 19 days after the deadline |
| MULTICERT | 2026-03-31 | 2026-07-17 | 108 | BSI | Microsoft | no letter on file |
| Government of The Netherlands, PKIoverheid (Logius) | 2026-05-31 | 2026-09-10 | 102 | TÜV Austria | Microsoft, Mozilla | incident report 21 Sep 2026 (bug 2074032, tagged audit-delay) |
| D-TRUST | 2025-10-07 | 2026-01-15 | 100 | TÜV NORD CERT GmbH | Apple, Chrome, Microsoft, Mozilla | incident report 20 Jan 2026 (bug 2011430, tagged audit-delay) |
Thailand filed one auditor’s letter on 14 April 2026 (bug 2031562), for the statement whose period ended 31 August 2025; its other two late statements have none, itself five and a half months after the first of those deadlines. D-TRUST and PKIoverheid opened compliance incidents tagged audit-delay (bugs 2011430 and 2074032) rather than the auditor letter the policy names; both are public, and we count them as disclosed. Entrust’s statement covers the period before its TLS business passed to Sectigo; Sectigo posted draft reports for the following period to Bugzilla in November 2025 and the CCADB record has not moved since.
How old an audit can be and still be trusted
Four root programs, one database, the same records. For each root a program includes today, the age of the newest audit period on file:
| Root program | Roots included | Newest audit, median age | 90th percentile | Oldest | Roots over 15 months | From CAs |
|---|---|---|---|---|---|---|
| Mozilla | 172 | 197 d | 398 d | 437 d | 0 | 0 |
| Chrome | 101 | 217 d | 398 d | 429 d | 0 | 0 |
| Apple | 144 | 188 d | 398 d | 841 d | 6 | 3 |
| Microsoft | 331 | 217 d | 406 d | 2,486 d | 24 | 15 |
“Over 15 months” is 365 + 92 days: a year since the last period ended plus the filing window, so the next annual statement is past due. Five Microsoft roots carry no standard audit date at all and are not counted.
Apple’s six: SwissSign Silver CA G2 (841 days, removed by Mozilla and Chrome), DigiCert’s Verified Mark root (763 days, a mail-logo root no other program carries), and four Entrust AffirmTrust roots at 582 days, which Mozilla and Chrome removed in 2024 and Microsoft also keeps. Microsoft’s twelve oldest:
| CA | Root | Newest audit period ended | Years ago | Status elsewhere |
|---|---|---|---|---|
| Docaposte Certinomis SAS | Certinomis - Root CA | 2019-12-13 | 6.8 | Mozilla: Removed, Apple: Removed |
| Government of Brazil, Instituto Nacional de Tecnologia da Informação (ITI) | Autoridade Certificadora Raiz Brasileira v10 | 2022-09-08 | 4.1 | not included elsewhere |
| Netrust Pte Ltd | Netrust Root CA 2 | 2024-02-19 | 2.6 | not included elsewhere |
| AC Camerfirma, S.A. | Global Chambersign Root - 2008 | 2024-03-01 | 2.6 | Mozilla: Removed, Apple: Blocked |
| Zetes | ZETES TSP ROOT CA 001 | 2024-03-10 | 2.6 | not included elsewhere |
| Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) | CCA India 2022 | 2024-03-20 | 2.5 | not included elsewhere |
| Government of India, Ministry of Communications & Information Technology, Controller of Certifying Authorities (CCA) | CCA India 2022 SPL | 2024-03-20 | 2.5 | not included elsewhere |
| Consorci Administració Oberta de Catalunya (Consorci AOC, CATCert) | EC-ACC | 2024-03-28 | 2.5 | Mozilla: Removed |
| Consejo General de la Abogacía Española | ACA ROOT | 2024-03-31 | 2.5 | not included elsewhere |
| První certifikační autorita, a.s. | I.CA Root CA/ECC 12/2016 | 2024-05-09 | 2.4 | not included elsewhere |
| SI-TRUST | SI-TRUST Root | 2024-12-15 | 1.8 | not included elsewhere |
| Carillon Information Security Inc. | Carillon PKI Services G2 Root CA 1 | 2025-02-09 | 1.6 | not included elsewhere |
Most of these roots are trusted by Microsoft alone. That is the pattern: the two programs that distrust publicly and quickly, Mozilla and Chrome, have no stale audits; the two that don’t have 30 between them, and the longest-standing ones are roots the others already dropped.
How this ends
It ends per CA and per program: a late statement gets its letter or its upload, the daily recheck of the CCADB export drops it from the eleven; a root with a stale audit gets a new one or leaves the store, and the 24 falls. The CCADB could end the ambiguity for good by publishing the upload date, which is the first question on the page.
The evidence
Every quote below was copied from the source and checked against a saved copy, fetched 2026-10-03. The CCADB export, the policy pages, the Bugzilla threads and the scripts are published next to this page (SHA256SUMS).
Exhibit 1 · The rule
“An authoritative English language version of publicly available audit information MUST be uploaded to the CCADB no later than 92 calendar days from the point-in-time date or the end date of the period of time. If the audit information cannot be provided by this deadline, the CA Owner MUST instead upload an explanatory letter signed by the Qualified Auditor to Bugzilla in the ‘CA Documents’ component no later than 92 calendar days from the point-in-time date or the end date of the period of time.”
ccadb.org/policy, section 5.2 · saved copy ccadb_policy.html
Exhibit 2 · The data
CCADB AllCertificateRecordsCSVFormatV5, 2026-10-03: 10,317 records, 89 columns Standard Audit Period End Date Standard Audit Statement Date Standard Audit URL Audit Firm Mozilla Status / Chrome Status / Apple Status / Microsoft Status Revocation Status Audits Same as Parent D-TRUST period end 2025-10-07 statement 2026-01-15 100 days TÜV NORD CERT Apple, Chrome, Microsoft, Mozilla Entrust period end 2025-02-28 statement 2025-06-27 119 days Deloitte Apple, Microsoft Certinomis newest period end 2019-12-13 Microsoft: Included Mozilla: Removed Apple: Removed
export ccadb_AllCertificateRecordsCSVFormatV5.csv.gz · computed tables audit_compliance.json, per_program_roots.json, lag_histogram.json
Exhibit 3 · Where the letters go
Bugzilla, product "CA Program", component "CA Documents", opened since 2025-01-01: 35 bugs 2031562 2026-04-14 Thailand NRCA - Explanation for delay in WebTrust Assurance report 2055439 2026-07-16 Firmaprofesional: 2026 audit-delay explanatory letter 2051532 2026-06-30 SHECA - Explanatory Letter for Delay of WebTrust Seal 2067507 2026-08-29 Chunghwa Telecom - Explanatory Letter for delay WebTrust for CA seals 2031062 2026-04-11 Sri Lanka CERT - Audit Statement Delay Explanation Letter 2076925 2026-09-30 Documents for SSL.com (period ended 2026-06-30; filed on day 92)
bugzilla_ca_documents.json · threads 2031562, 2055439, 1999214 (Entrust), 2076925 (SSL.com) · all 23 bugs tagged audit-delay: audit_delay_bugs.txt
Exhibit 4 · Microsoft’s own rule
“Program Participants must provide to Microsoft evidence of a Qualifying Audit … for each root, unconstrained subordinate CA, and cross-signed certificate, before conducting commercial operations and thereafter on an annual basis.”
learn.microsoft.com/en-us/security/trusted-root/program-requirements · saved copy microsoft_root_program.html
Our questions
Sent on 3 October 2026 to the CCADB steering committee, which represents all four root programs, and to Microsoft’s Trusted Root Program. Answers will be printed here as written.
- Does the CCADB record the date an audit statement was uploaded? If so, can it be added to the public export, so compliance with 5.2 can be checked by anyone rather than bounded from the statement date?
- For the seven late statements with no letter and no incident report (Thailand’s July 2025 and February 2026 periods, MULTICERT, Entrust, CATCert, Brazil’s ITI), was a letter received by another route?
- Microsoft: the Certinomis root’s newest audit on its CCADB record ended on 13 December 2019. Is a newer audit on file with Microsoft, and if so, why isn’t it in the CCADB?
- Microsoft and Apple: the four Entrust AffirmTrust roots show a newest period end of 28 February 2025, and Sectigo’s drafts for the following period sit in Bugzilla. What is the current audit status of those roots in your stores?
- Is “15 months without a current audit” a condition any of the four programs treats as grounds for removal, and if so, how are the 30 roots here still included?
Their reply, scored
Disclosure timeline
| 3 Oct | Published; sent to the CCADB steering committee and Microsoft’s root program with the five questions above. |
Waiting since 3 Oct.
What we can’t be sure of
- The CCADB export carries the auditor’s statement date, not the upload date. A statement dated on day 60 and uploaded on day 150 looks compliant here. Our 108 of 119 is therefore a ceiling on compliance, and the 11 a floor on lateness.
- A root program may hold a newer audit than its CCADB record shows. The CCADB is the place the programs say the record lives; if it’s out of date, that is itself the finding, but it is a different one.
- Microsoft’s store includes roots for purposes other than the web, with their own audit regimes. The 24 are measured against Microsoft’s own “annual basis” wording, which doesn’t distinguish.
- We matched letters and incident reports by CA name in Bugzilla summaries and the [audit-delay] tag. A filing under another title would be missed; the question above asks.
- One export, one day. The CSV changes daily as CAs file; the recheck will show whether the late ones catch up and whether the next filing season clusters the same way.
Run it yourself
Python 3 standard library. One 11 MB download from the CCADB and a few Bugzilla API calls; under a minute.
curl -sL https://ccadb.my.salesforce-sites.com/ccadb/AllCertificateRecordsCSVFormatV5 -o ccadb_v5.csv python3 audit_deadlines.py # statements, lateness by statement date, overdue CA owners, per audit type python3 per_program.py # per root program: age of the newest audit on each included root
Reproduced from the public repository on 3 October 2026 on a clean machine: exact (119 statements, 11 late, 90th percentile day 92; Mozilla 0 of 172, Chrome 0 of 101, Apple 6 of 144, Microsoft 24 of 331). Full table on the track record.
What you can do with this
- If you rely on the Microsoft root store, know that 24 of its roots carry audits more than 15 months old on the shared record; the list is in the exhibits.
- If you are a CA, the deadline is 92 days and the statement date is public; filing on day 92 is visible.
References
- CCADB. CCADB Policy, section 5.2 Audit Statement Content. ccadb.org/policy.
- Mozilla. Mozilla Root Store Policy, section 3.4 Compliance Self-Assessments. mozilla.org.
- Microsoft. Program Requirements, Microsoft Trusted Root Program, section 2 Audit Requirements. learn.microsoft.com.
- CCADB. All Certificate Records (CSV, V5). ccadb.my.salesforce-sites.com.
- Bugzilla, product CA Program, component CA Documents.
Cite as
@misc{markovian-sm012,
author = {{Markovian Protocol}},
title = {Audit filing deadlines in the CCADB, October 2026},
number = {SM-012},
doi = {10.5281/zenodo.23123265},
year = {2026},
month = oct,
url = {https://markovianprotocol.com/measurements/sm-012.html}
}