Hello everyone,
Following the discussion draft shared in July, version 1.0 of the Detailed Controls Reports (DCR) whitepaper is now available in the Mozilla pkipolicy GitHub repository:
https://github.com/mozilla/pkipolicy/blob/master/dcrs/dcr-whitepaper.md
The paper explains the purpose and anticipated benefits of DCRs and offers guidance on their structure and content. In particular, it discusses the information prepared by the CA Operator, including the system description and controls matrix, and the auditor’s examination and reporting. It is intended to help CA operators, auditors, and other interested readers understand how a DCR can provide greater visibility into the controls supporting compliance with the applicable requirements.
The white paper supplements the Mozilla Root Store Policy, DCR guidance, and FAQ. It does not establish new requirements or prescribe a single report format or audit methodology. Under MRSP section 3.1.5, the DCR requirement applies to relevant audit periods beginning on or after July 1, 2027.
I welcome further feedback, particularly on whether the paper is clear and workable under both WebTrust and ETSI approaches; whether it appropriately distinguishes CA-prepared information from the auditor’s work; and whether any examples or explanations need improvement.
Please reply to this thread with questions or comments so others can participate in the discussion. For a specific correction or suggested change, you may also open an issue or submit a pull request in GitHub. Identifying the section and proposing alternative wording, where possible, would be especially helpful.
Thank you to everyone who reviewed the earlier draft and contributed suggestions.
Ben Wilson
Mozilla Root Program