CA/DCR-FAQs
Detailed Controls Reports (DCR) Frequently Asked Questions
General
What is a Detailed Controls Report (DCR)?
As the name implies, a Detailed Controls Report (DCR) is detailed report issued by an external auditor that provides additional information regarding a CA operator's controls (design-related, implementation, operating effectiveness, etc.) supporting compliance with the CA/Browser Forum's TLS Baseline Requirements (TLS BRs) and the Network and Certificate System Security Requirements (NCSSRs).
The DCR supplements existing WebTrust or ETSI audit reports by providing management with greater visibility into how critical controls operate in practice.
Why is Mozilla requiring DCRs?
Traditional audit opinions provide important assurance that applicable requirements were met, but they generally provide limited documentation of the controls that produced those conclusions.
Mozilla believes that additional documentation benefits:
- CA management
- auditors
- Mozilla's oversight activities
by providing a better understanding of how important security and compliance controls are designed, implemented, tested, and maintained.
What is Mozilla hoping to achieve?
Mozilla expects DCRs to:
- improve transparency;
- strengthen governance and accountability;
- encourage stronger internal compliance programs;
- improve understanding of operational controls;
- facilitate more informed trust decisions; and
- encourage continuous improvement throughout CA operations.
Are DCRs replacing WebTrust or ETSI audits?
No. The DCR is an additional report. Existing audit reports remain required.
Why don't existing ETSI audit reports automatically satisfy Mozilla's DCR requirement?
Mozilla recognizes that many ETSI-accredited conformity assessment bodies already produce detailed audit reports that include descriptions of the controls evaluated, the audit procedures performed, and the results of testing. Such reports may already satisfy some or all of the Mozilla DCR requirements. However, Mozilla does not presume that every existing ETSI report automatically satisfies the DCR requirement. Regardless of the audit framework or report title, each report must contain the minimum information required by the Mozilla Root Store Policy.
Where an existing ETSI report does not include all required information, the CA operator and its conformity assessment body should determine the most appropriate way to obtain and document whatever may be missing. This may involve expanding an existing report, supplementing it with additional material, or using another approach that satisfies the Mozilla Root Store Policy.
Scope
Which CAs are required to obtain a DCR?
At this time, Mozilla requires DCRs only for CA operators whose root certificate hierarchies are enabled for TLS website authentication.
Why aren't S/MIME root CA hierarchies required to obtain DCRs?
Mozilla considers TLS certificates to present the greatest ecosystem risk due to the public nature of their use, issuance volume, and the general security impact on web browsing. Mozilla may evaluate whether similar reporting would be beneficial for other PKI ecosystems like S/MIME in the future.
Does every intermediate CA require a separate DCR?
Not necessarily. A single DCR may cover multiple root and intermediate CA hierarchies, provided they are operated by the same CA operator (or otherwise fall within the scope of the same audit engagement) and the report clearly identifies:
- the CA hierarchies;
- the systems covered;
- the services provided;
- the controls evaluated; and
- the scope of testing.
However, externally operated intermediate CAs, such as those managed by a different organization under a delegated or subordinate CA arrangement, will generally require their own DCR because they have separate systems, personnel, controls, and audit scope. Each DCR should clearly define the operational boundaries and identify the systems and controls that are included within the engagement.
Report Contents
What information must be included?
The Mozilla Root Store Policy specifies the minimum required contents. A typical table of contents of a DCR would include:
- system descriptions;
- scope boundaries;
- applicable audit criteria;
- control descriptions;
- testing procedures;
- testing results;
- control exceptions; and
- management responses, where appropriate.
Does Mozilla prescribe a specific report format?
No. Mozilla intentionally allows flexibility. Different audit firms may organize reports differently, provided the required information is present.
Does Mozilla require a standardized DCR template?
No. Mozilla recognizes that audit firms use different reporting formats based on their audit methodologies, accreditation requirements, and applicable audit frameworks. Mozilla does not prescribe a standardized report template. Instead, the Mozilla Root Store Policy specifies the minimum information that a DCR must contain. Audit firms may organize and present that information in a manner consistent with their existing reporting practices.
Does Mozilla require a specific control framework?
No. Mozilla expects the controls to demonstrate compliance with the TLS BRs and NCSSRs but does not require any particular control taxonomy or framework.
Must every Baseline Requirement have a separate control?
Not necessarily.
A single control may satisfy multiple requirements, and some requirements may require multiple controls. The report should clearly identify how each applicable requirement is addressed by one or more controls. When a single control satisfies multiple requirements, the report should document that relationship and the auditor's evaluation of the control's design and operating effectiveness.
Does Mozilla provide a control matrix?
Mozilla may publish example templates and additional guidance documents to assist CA operators and their auditors.
These examples are informative rather than normative.
Can a DCR identify control deficiencies that do not rise to the level of a qualified audit opinion?
Yes. The purpose of a DCR is to provide greater visibility into the design and operating effectiveness of controls that support compliance with the applicable audit criteria. A DCR is intended to provide more than a simple pass/fail conclusion and may identify control deficiencies, observations, opportunities for improvement, or other matters that, in the auditor's professional judgment, are useful for understanding the CA's control environment. Such matters do not necessarily require a qualified audit opinion.
How much detail is enough?
A DCR should contain sufficient information for a knowledgeable reader to understand:
- the controls in place;
- risks or requirements that those controls are intended to address;
- how the controls operate;
- how the auditor evaluated them; and
- whether the controls operated effectively during the audit period.
Mozilla does not expect reports to disclose information that would materially increase the security risk of CA systems. For example, reports generally do not need to include implementation details such as IP addresses, firewall rules, VLAN assignments, router configurations, switch topology, server names, load balancer configurations, or similar infrastructure-specific information.
Auditors
Does Mozilla specify how auditors perform the engagement?
No. Auditors retain professional responsibility for:
- planning the engagement;
- determining testing methods;
- selecting samples;
- evaluating evidence; and
- forming their conclusions.
Mozilla's policy specifies the information expected in the report rather than the audit methodology.
Must auditors follow Mozilla's DCR examples?
No. Examples published by Mozilla are intended solely as guidance.
Auditors may organize reports differently when appropriate.
May DCRs differ between audit firms?
Yes. Mozilla recognizes that audit firms may use different report structures, terminology, and presentation styles based on their audit methodologies, accreditation requirements, and applicable audit frameworks.
The objective is not to achieve uniform formatting, but rather that each DCR provides the information required by the Mozilla Root Store Policy.
Does Mozilla expect auditors to answer follow-up questions?
Generally, no.
Mozilla generally directs questions regarding a DCR to the CA operator rather than the auditor. If clarification is needed, Mozilla expects the CA operator to coordinate with its auditor, as appropriate, and provide any necessary responses or supporting information.
In unusual circumstances, Mozilla may communicate directly with the auditor when necessary to resolve significant questions regarding the report or the audit engagement. However, Mozilla does not expect auditors to provide ongoing consultation or support beyond the services they have agreed to provide to their client.
What if the auditor is not immediately available to answer follow-up questions?
Mozilla recognizes that auditors may not always be immediately available to respond to requests for clarification due to audit schedules, travel, or other professional commitments. Mozilla does not expect such delays, by themselves, to be treated as an audit finding or a policy violation. Rather, Mozilla expects the CA operator to make reasonable efforts to obtain any necessary clarification within a reasonable period of time.
Is Mozilla an intended user of the report?
Mozilla requires the CA operator to obtain a DCR and, upon request, provide it to Mozilla for root store oversight purposes.
The Mozilla Root Store Policy also requires that CA operators not enter into audit or other agreements that would prevent or materially restrict the provision of a DCR to Mozilla when requested.
However, the DCR requirement does not create a contractual relationship between the auditor and Mozilla, nor does it impose duties on the auditor beyond those associated with performing the engagement and permitting the CA operator to provide the completed report to Mozilla. Mozilla ordinarily directs questions regarding a DCR to the CA operator rather than the auditor.
Confidentiality
Will DCRs become public?
No. Mozilla expects DCRs to be treated as confidential reports shared with the CA operator, its auditor, and Mozilla.
Mozilla does not intend to publish DCRs.
Can sensitive information be redacted?
Yes.
Mozilla recognizes that DCRs may contain information that could materially increase security risks if publicly disclosed. Limited redactions are acceptable where necessary to protect CA system security, provided the report remains sufficiently informative to satisfy Mozilla's objectives.
Does Mozilla expect network diagrams or infrastructure details?
No. DCRs should contain only sufficient information to understand:
- the major systems;
- the role each system performs;
- how the systems interact; and
- where controls operate.
Detailed infrastructure information, such as IP addresses, firewall rules, VLAN assignments, router configurations, switch topology, server names, load balancer configurations, or similar implementation details, is generally unnecessary.
Submission to Mozilla
When must the DCR be submitted?
The CA operator is required to obtain a DCR for each applicable audit period.
Before the DCR requirement becomes effective, Mozilla intends to add DCR-related questions to the CCADB. Rather than requiring routine submission of the report itself, Mozilla expects that CA operators will attest that they have obtained the required DCR and that they will provide the report to Mozilla upon request.
Mozilla does not ordinarily require DCRs to be submitted as part of the annual audit package. However, Mozilla may request a copy of a DCR at any time as part of its root store oversight activities, including during the root inclusion process, when reviewing audit reports, or when investigating compliance concerns.
CA operators should retain their DCRs and be prepared to provide them to Mozilla upon request.
Why does Mozilla require CA operators to be able to provide the DCR upon request?
Mozilla expects CA operators to retain their DCRs as part of their compliance documentation and to make them available when needed for root store oversight.
Accordingly, the Mozilla Root Store Policy requires that CA operators not enter into contractual or other arrangements that would prevent or materially restrict disclosure of the DCR to Mozilla upon request. This requirement helps ensure that Mozilla can obtain the information necessary to evaluate compliance issues when circumstances warrant.
Must a DCR be provided in English?
Not necessarily.
Mozilla recognizes that many audit reports are prepared in the official language of the jurisdiction in which the audit is performed. Mozilla does not require every DCR to be prepared in English. If Mozilla requests a DCR, the CA operator should ordinarily provide the report promptly in the language in which it was issued rather than delaying its delivery while an English translation is prepared.
Regardless of the language used, the report should be provided in a readily machine-readable electronic format that permits searching, copying, and electronic translation of the text. Documents that consist primarily of scanned images or otherwise prevent searching, copying, OCR, or electronic translation are not suitable for Mozilla's review.
If Mozilla determines that an English version is reasonably necessary to facilitate its review, the CA operator should cooperate in providing an English translation or other suitable English-language explanation of the relevant portions of the report.
Who receives the report?
The DCR is primarily prepared for the CA operator's management as part of its annual audit engagement.
Mozilla ordinarily does not require routine submission of DCRs. However, Mozilla may request a copy from the CA operator when needed for root store oversight purposes.
The Mozilla Root Store Policy requires that the CA operator be able to provide the DCR to Mozilla upon request.
Will Mozilla review every control?
Mozilla may review any portion of the report as part of its ongoing root store oversight activities.
The depth of Mozilla's review will depend upon the circumstances and available resources.
Implementation
What if my organization already produces a detailed controls report?
Mozilla recognizes that some audit engagements (e.g. some ETSI audits) may already produce detailed reports describing the controls evaluated and the results of their testing. Existing reports may satisfy Mozilla's DCR requirement provided they contain the information required by the Mozilla Root Store Policy. Mozilla does not require organizations to obtain a separate report solely because a different name, reporting format, or terminology is used.
See above 'Why don't existing ETSI audit reports automatically satisfy Mozilla's DCR requirement?'
What if our report is called something other than a DCR?
That is acceptable.
Mozilla recognizes reports issued under various audit frameworks, including WebTrust Detailed Controls Reports, ISAE 3000 reports, ETSI-based reports, or other auditor-issued reports that satisfy the required contents.
Where can I find additional guidance?
Besides this FAQ and the DCRs wiki page, Mozilla expects to publish supporting guidance, including a DCR White Paper.