All, Version 3.1 of the Mozilla Root Store Policy <https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/policy/> (MRSP) is now published. It has an effective date of July 1, 2026.
This policy update focuses primarily on improving the transparency, clarity, and auditability of CA operations through enhanced CP/CPS Documentation requirements and the introduction of a Detailed Controls Report (DCR) audit requirement, both starting July 1, 2027. Additional background is available in the accompanying Mozilla Security Blog post - Improving Transparency and Assurance in the Web PKI <https://blog.mozilla.org/security/2026/06/29/improving-transparency-and-assurance-in-the-web-pki-mozilla-root-store-policy-v3-1/> *.* Mozilla has also published the following four new guidance documents under a new Documentation <https://wiki.mozilla.org/CA#Documentation> section of the CA wiki. - CP/CPS Documentation Guidance https://wiki.mozilla.org/CA/CP-CPS_Guidance - CP/CPS Documentation FAQ https://wiki.mozilla.org/CA/CPS-FAQs - DCR Guidance https://wiki.mozilla.org/CA/DCRs - DCR FAQ https://wiki.mozilla.org/CA/DCR-FAQs These guidance documents are intended to help CA operators understand Mozilla's expectations regarding CP/CPS documentation and DCRs. They provide explanatory material, examples, and frequently asked questions to support consistent implementation of the new policy requirements. We are also preparing a white paper that will provide additional background and implementation guidance regarding DCRs. We expect to publish it separately once it is complete. Mozilla encourages CA operators to begin reviewing the new policy (tracked changes <https://github.com/mozilla/pkipolicy/pull/302/changes>) and accompanying guidance. As always, questions and feedback are welcome. Thanks again to everyone who provided comments to help improve MRSP v3.1 during this process. Ben Wilson Mozilla Root Store Program -- You received this message because you are subscribed to the Google Groups "[email protected]" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion visit https://groups.google.com/a/mozilla.org/d/msgid/dev-security-policy/CA%2B1gtaZu-nASMrD2T%3D0Hi%2BxQSi1nmfYiO%3Da%2BHZdW6w9j9ihB_A%40mail.gmail.com.
