CA/Browser Forum
Home » Working Groups » NetSec WG

Network Security Working Group

Background

In January 2013 the CA/Browser Forum’s “Network and Certificate System Security Requirements” (NCSSRs) became effective. In June 2017, the Forum chartered a Network Security Working Group to re-work the NCSSRs. That charter expired on June 19, 2018, and in October 2018, the Server Certificate Working Group (SCWG) established a Network Security Subcommittee (NetSec Subcommittee) to continue work on the NCSSRs. Since then, the Network Security Working Group (NetSec WG) has replaced the NetSec Subcommittee. The NetSec WG was created in December 2021 by Ballot Forum-17. Existing members of the CA/Browser Forum are eligible to participate in the NetSec WG.

Scope of Work

The NetSec WG was chartered to continue work on the NCSSRs, and to conduct any and all business related to improving the security of Certification Authorities. The NetSec WG makes security-related recommendations to other Forum WGs for requirements or guidelines that are within their purview, i.e. the Baseline Requirements/Extended Validation Guidelines of the Server Certificate WG, the Baseline Requirements for Code Signing Certificates of the Code Signing Certificate Working Group or guidelines adopted by the S/MIME Certificate Working Group.

The primary deliverable of the NetSec WG is the NCSSRs. Other work includes performing risk analyses, security analyses, and other types of reviews of threats and vulnerabilities applicable to CA operations involved in the issuance and maintenance of publicly trusted certificates (e.g. server certificates, code signing certificates, or SMIME certificates).

Charter

Charter of the Network Security Working Group

Officers

Chair: Clint Wilson (Apple)

Vice Chair: David Kluge (Google Trust Services)

Ballots

Network Security Working Group Ballots

Participation

The CA/Browser Forum welcomes existing members with an interest in system security to join the NetSec WG. There is no cost to join. Existing CABF Members should provide their declaration of intent to participate in the NetSec WG and the following information by email to questions@cabforum.org:

  • statement of the Voting Class by which they qualify;
  • names/email addresses of their designated representatives who will participate; and
  • names/email addresses of their designated representatives who will vote.

Mailing List

The NetSec WG provides a public mailing list. See https://groups.google.com/a/groups.cabforum.org/g/netsec

To subscribe, see: https://groups.google.com/a/groups.cabforum.org/g/netsec/about.

Members

Certification Authorities

Certificate Consumers

  • Apple
  • Google
  • Microsoft
  • Mozilla
  • Opera Software AS

Associates

  • CPA Canada/WebTrust
  • ETSI
  • Keyfactor
  • US Federal PKI Management Authority

Interested Parties

Latest releases
Server Certificate Requirements
SC098: Process RFC 8657 CAA Parameters - Jun 16, 2026

Code Signing Requirements
v3.8 - Aug 5, 2024

What’s Changed CSC-25: Import EV Guidelines to CS Baseline Requirements by @dzacharo in https://github.com/cabforum/code-signing/pull/38 Full Changelog: https://github.com/cabforum/code-signing/compare/v3.7...v3.8

S/MIME Requirements
v1.0.15 - Ballot SMC017v2 - Jul 30, 2026

This ballot increases the minimum RSA key size for Root and Subordinate CA certificates in the S/MIME BRs from 2048 to 4096 bits for keys created after September 15, 2026, while retaining the 2048-bit minimum for Subscriber certificates. The ballot further requires that by September 15, 2027, CAs SHALL NOT issue Subscriber certificates from any Sub-CA whose RSA key modulus is less than 3072 bits, effectively sunsetting issuance from legacy 2048-bit Sub-CAs. The ballot also includes minor typographic corrections. This ballot is proposed by Martijn Katerbarg (Sectigo) and endorsed by Ben Wilson (Mozilla) and Stephen Davidson (DigiCert)

Network and Certificate System Security Requirements
Version 2.0.5 (Ballot NS-008) - Jul 9, 2025

Edit this page
The Certification Authority Browser Forum (CA/Browser Forum) is a voluntary gathering of Certificate Issuers and suppliers of Internet browser software and other applications that use certificates (Certificate Consumers).