Purpose of Ballot
This ballot proposes the following changes to the NCSSRs:
Structural changes
- New Section 1 "CA Infrastructure Inventory": the inventory requirement ("The CA MUST define an inventory of its CA Infrastructure") is separated into its own top-level section for clarity and emphasis.
- Section renumbering - all subsequent sections bumped by one:
Section 1 to Section 2 (CA Infrastructure and Network Boundary Control Configuration)
Section 2 to Section 3 (Access Control)
Section 3 to Section 4 (Monitoring, Logging, Auditing, and Incident Response)
Section 4 to Section 5 (Vulnerability Management)
- Cross-references updated: all internal section references and anchor links updated to reflect the new numbering.
Removal of expired effective dates
- Removed "Prior to 12-Nov-2025 / Effective 12-Nov-2025" transition language (the date is now past).
- Consolidated vulnerability-management applicability: replaced the phased SHOULD/MUST language (expired 15-Apr-2026) with a single MUST statement.
External reference update
- Updated the NIST reference in Section 3.2.5 from "NIST 800-63B Revision 3 Appendix A" to "NIST SP 800-63B Revision 4 Appendix A".
Motion
The following motion has been proposed by Tim Hollebeek (DigiCert) and endorsed by Trevoli Ponds-White (Amazon) and Andrea Holland (IdenTrust).
You can view and comment on the Github pull request representing this ballot
here.
Motion begins
Motion ends
Discussion (at least 7 days)
-
Start time: Tuesday, July 14, 2026 16:00:00 UTC
-
End time: on or after Tuesday, July 21, 2026 16:00:00 UTC
Vote for approval (7 days)
If the Initial Vote passes, a 30-day IPR Review Period will follow per Bylaws Section 2.4 and the IPR Policy.