How to use this checklist
Losing a certificate authority is unlike losing a database. There is no partial degradation and no read-only mode: either clients build a chain to something they trust or every connection fails at once, across services that have no other relationship with each other. This review runs once a year and it exists to establish whether the organisation could come back from that, with a number attached rather than an intention.
Treat it as the parent of the backup review rather than a repeat of it. That review asks whether the archive is good. This one asks whether the whole path from an intact archive to a customer whose browser is happy again can be walked, by the people who are actually on call, in the time the business believes it takes.
Where the numbers come from
The certificate inventory drives most of the arithmetic here, and it has to be built from observation as well as from the issuance database. Connect to services and read what they present. Anything issued by hand, installed by a vendor, or inherited from an acquisition exists only in that view.
Capacity figures are measured, not estimated. Time one certificate from request to a reloaded service, then multiply by the inventory and add the rate limit arithmetic for any names issued publicly. Trust anchor distribution time is measured the same way: push a harmless additional anchor and watch how long the slowest population takes to report it.
Three items are attestations. Whether the plan states honestly that revocation is not the recovery control, whether the communications plan exists with named people, and the disposition of the ceremony itself are established by reading and by asking, and are signed by whoever did the reading.
Access this needs
Read access to the disaster recovery plan and the certificate inventory, the ability to open a TLS connection to the services under review from outside the estate, read access to the publication point for revocation lists, and read access to the trust store management configuration. The drill needs far more and is scheduled separately, with the ceremony participants, a written change record, and an environment that cannot reach production.
What the review produces
A dated readiness statement carrying four numbers that the business can act on: how many certificates are in service, how long a full reissue and redeploy takes, how long a new trust anchor takes to reach the slowest client population, and how long ago the last real drill was. Findings are attached with owners and dates. It goes to the platform owner, the security owner and whoever is accountable for service continuity, because the third of those numbers is usually the one that changes a budget.
Sign-off
- Reviewer: ________________ Date: ___________
- Platform owner: ___________ Date: ___________
- Security owner: ___________ Date: ___________
Every critical item must pass. A failing critical item is a statement that the organisation does not currently know it can recover its trust infrastructure, which belongs on the risk register with a figure beside it rather than in a checklist appendix. Record the date, the reviewer, and the disposition of every item that did not pass.