Ballot SC-089: Mass Revocation Planning is under discussion in CA/B Forum, currently under discussion in the CA/B Forum, proposes adding a new section to the TLS Baseline Requirements to mandate that Certification Authorities (CAs) create, maintain, and annually test a Mass Revocation Plan. This aligns with existing Mozilla Root Program requirements and outlines minimum standards, such as activation triggers, defined responsibilities, communication strategies, and continuous improvement based on testing. CAs must include this plan in their CPS by December 1, 2025. The ballot was proposed by Mozilla and supported by D-Trust (CAs) and OISTE (CAs).Â
Â
Current Status: Discussion Period Ongoing Â
Â
What’s Being ProposedÂ
The current Baseline Requirements (Version 2.1.5), section 5.7.1, require CAs to have an Incident Response Plan and a Disaster Recovery Plan.Â
A new proposal introduces section 5.7.1.2 – Mass Revocation Plans, requiring CAs to prepare for large-scale certificate revocation events.Â
Â
CAs must:
- Develop and maintain a mass revocation plan.
- State in their CPS that the plan exists and complies with the requirements as of December 1, 2025
- Test the plan yearly and improve it based on lessons learned.
- Share the plan with auditors if requested (not public disclosure).
- Ensure the plan can be part of existing incident or recovery plans, but mass revocation procedures must be clearly identified.
Mass revocation provisions MUST include:Â
- Activation criteriaÂ
- Customer contact informationÂ
- Automation pointsÂ
- Targets and timelinesÂ
- Subscriber notification methodsÂ
- Role assignmentsÂ
- Training and educationÂ
- Plan testingÂ
- Post-test analysis and update scheduleÂ
Â
TuringSign’s CertifyID TLS Manager features a powerful Certificate Revocation Scheduling Tool that helps you stay in control:Â
- Schedule revocations in advance by setting the exact date and time,Â
- Keep your subscribers informed with automatic revocation notifications,Â
- Enhance transparency by displaying the revocation schedule directly on the order detail page.Â
- Easily cancel scheduled revocations if plans changeÂ
Smart, secure, and subscriber-friendly — simplify your certificate lifecycle management today.Â
Â




