NIAP: U.S. Government Approved Protection Profile - Protection Profile for Certification Authorities Version 2.1

Short Name: pp_ca_v2.1

Technology Type: Certificate Authority

CC Version: 3.1

Date: 01 December 2017

Transition End Date: 01 June 2018

Preceded By: pp_ca_v2.0

Conformance Claim: None



Certification Authorities (CAs), and the infrastructure they support, form the basis for one of the primary mechanisms for providing strong assurance of identity in online transactions. The widely placed trust in CAs is at the heart of security mechanisms used to protect business and financial transactions online. Notably, protocols using Transport Layer Security (TLS) rely on certificates issued by CAs to identify and authenticate servers and clients in web transactions. Governments around the world rely on CAs to identify parties involved in transactions with them.
However, historical high-profile security breaches at major CAs trusted by widely used operating systems and browsers have highlighted both the critical role CAs play in securing electronic transactions, as well as the need to strongly protect them from malicious attacks. Analyses have revealed that these security breaches were often the result of insufficient security controls being in place on the computer systems and networks at these CAs, and were sometimes exacerbated by weak record keeping. Third-party auditing programs, whose role it was to verify that proper security controls were in place, were not sufficient to identify these lapses in security.

This Protection Profile (PP) describing security requirements for a Certification Authority is intended to provide a minimal, baseline set of requirements that are targeted at mitigating well defined and described threats. These requirements support CA operations performed in accordance with the National Institute of Standards and Technologies (NIST) Interagency or Internal Report (IR) 7924 (Second Draft), Reference Certificate Policy, referred to as the “NIST IR.”2

This U.S. Government Approved Protection Profile is not assigned to any Validated Products

Related Technical Decisions

  • 0278 – Clarification of Role for Managing Manual Certificate Requests
  • 0276 – X.509 Code Signing on TOE Updates

Please forward any questions or comments to

Site Map              Contact Us              Home