We should add clarifying language to section 7.1 of the MRSP along these lines:
“Evidence of such continuous compliance consists of (1) existing period-of-time audit reports covering the CA operator’s systems, processes, and controls; and (2) an auditor-witnessed key generation ceremony report for the new root CA key pair, provided that the CA key pair was generated within the scope of the audited environment, under the same controls, and that no material changes to the relevant controls occurred. In such cases, an additional or separate audit is not required prior to submission of a Root Inclusion Request because the subsequent audit report covering the applicable audit period will include the new root CA certificate within the audit scope."
We should add clarifying language to section 7.1 of the MRSP along these lines:
“Evidence of such continuous compliance consists of (1) existing period-of-time audit reports covering the CA operator’s systems, processes, and controls; and (2) an auditor-witnessed key generation ceremony report for the new root CA key pair, provided that the CA key pair was generated within the scope of the audited environment, under the same controls, and that no material changes to the relevant controls occurred. In such cases, an additional or separate audit is not required prior to submission of a Root Inclusion Request because the subsequent audit report covering the applicable audit period will include the new root CA certificate within the audit scope."