- Key Takeaways
- What Is the Difference Between a CP and a CPS?
- What Does RFC 3647's Standard CP/CPS Structure Cover?
- Why Does the Certificate Policies OID Extension Matter?
- Why Should an Organization Invest in Developing Its Own CP/CPS?
- How Encryption Consulting Helps
- Frequently Asked Questions
- Get Your CP/CPS Documentation Right
A Certificate Policy (CP) is a document defining the requirements a certificate must meet for a given use case, and a Certificate Practice Statement (CPS) is the document describing how a specific Certificate Authority actually implements those requirements in its issuance and management practices.
A CP answers what requirements a certificate must satisfy for its intended purpose, while a CPS answers how a specific CA meets those requirements in practice, covering identity verification, key protection, issuance procedures, and revocation. Together, following RFC 3647’s standard structure, they form the governing documentation every publicly trusted CA must publish and operate under.
Key Takeaways
- RFC 3647 defines the standard structure both CP and CPS documents should follow, covering nine major sections from general provisions to compliance audit.
- A single CA can operate under multiple Certificate Policies (for example, one for TLS server certificates and another for code signing), each requiring its own CPS alignment.
- The Certificate Policies X.509 extension embeds an OID pointing to the governing CP, letting relying parties and software programmatically identify which policy a certificate was issued under.
- A CPS is typically far more detailed and operationally specific than a CP, since it must describe actual procedures, not just requirements.
- Public CAs must publish their CP/CPS and undergo regular independent audits (such as WebTrust or ETSI) to remain included in major browser and OS trust stores.
What Is the Difference Between a CP and a CPS?
| Document | Answers | Written by |
|---|---|---|
| Certificate Policy (CP) | What requirements must a certificate of this type meet? | Can be written independently of any specific CA, and adopted by multiple CAs |
| Certificate Practice Statement (CPS) | How does this specific CA meet those requirements in practice? | Written by the operating CA itself, describing its actual procedures |
A useful analogy: a CP is like a building code specifying required safety standards, while a CPS is like a specific contractor’s documented process for meeting that code on a particular building. Multiple contractors (CAs) can build to the same code (CP) using different, equally valid documented processes (CPS).
What Does RFC 3647’s Standard CP/CPS Structure Cover?
- Introduction: document overview, applicable OIDs, and definitions.
- Publication and repository responsibilities: where and how the CA publishes certificates and revocation information.
- Identification and authentication: how the CA verifies an applicant’s identity before issuance.
- Certificate life-cycle operational requirements: application, issuance, acceptance, renewal, and revocation procedures.
- Facility, management, and operational controls: physical security, personnel vetting, and audit logging.
- Technical security controls: key generation, protection, and cryptographic module requirements.
- Certificate, CRL, and OCSP profile: the technical format of issued certificates and revocation data.
- Compliance audit: how and how often the CA is independently audited.
- Other business and legal matters: fees, liability, confidentiality, and dispute resolution.
Why Does the Certificate Policies OID Extension Matter?
Every certificate issued under a given policy embeds that policy’s OID in its Certificate Policies extension, letting relying-party software programmatically confirm which CP governed the certificate’s issuance, without needing to manually cross-reference the CA’s published documentation. This is especially important in environments enforcing specific policy requirements, such as requiring hardware-backed key storage, since the OID lets automated validation confirm policy compliance at scale.
Why Should an Organization Invest in Developing Its Own CP/CPS?
Organizations running an internal or private CA still benefit from a well-documented CP/CPS, even without the public trust-store audit requirements a public CA faces. A clear CP/CPS gives internal stakeholders, auditors, and business partners a documented basis for trusting internally issued certificates, and it is frequently requested during vendor security reviews, compliance audits, and enterprise customer due diligence for any organization operating its own PKI.
How Encryption Consulting Helps
How Encryption Consulting Helps PKI Services develops CP/CPS documentation aligned to RFC 3647’s standard structure, whether for a public CA preparing for a WebTrust audit or an internal CA needing documented governance for enterprise and compliance purposes. Backed by ISO/IEC 27001:2022 and SOC 2 certified practices.
Frequently Asked Questions
Do private, internal CAs need a CP/CPS?
It is not legally required the way it is for public CAs, but a documented CP/CPS is still a strong practice for internal CAs, since it gives auditors, business partners, and internal stakeholders a clear basis for trusting internally issued certificates, and is frequently requested during security reviews.
Can one CA operate under multiple Certificate Policies?
Yes. Many CAs maintain separate Certificate Policies for different certificate types, such as one policy for TLS server certificates and another for code signing certificates, each with its own OID and corresponding CPS alignment.
What audit standards apply to a public CA’s CP/CPS?
Public CAs seeking inclusion in major browser and OS trust stores typically undergo an independent audit against WebTrust for Certification Authorities or an equivalent standard such as ETSI EN 319 411, confirming the CA’s actual practices match its published CPS.
Is a CPS the same document across all of a CA’s certificate types?
Not usually. A CPS often needs to address the specific practices for each Certificate Policy the CA operates under, since issuance and validation procedures can differ meaningfully between, for example, a TLS certificate and a code signing certificate.
Get Your CP/CPS Documentation Right
Take the next stepPKI Services develops RFC 3647-aligned CP/CPS documentation for public and private CAs alike, built for audit readiness and enterprise trust. Explore PKI Services to get started.
- Key Takeaways
- What Is the Difference Between a CP and a CPS?
- What Does RFC 3647's Standard CP/CPS Structure Cover?
- Why Does the Certificate Policies OID Extension Matter?
- Why Should an Organization Invest in Developing Its Own CP/CPS?
- How Encryption Consulting Helps
- Frequently Asked Questions
- Get Your CP/CPS Documentation Right
