# CHQ-ED-2026-003

- **Artifact ID:** CHQ-ED-2026-003
- **Public record:** https://record.cybersecurityhq.com/evidence/chq-ed-2026-003
- **Machine-record SHA-256:** `426080ad1ec4f15247f08f448f4f4aa5ffe64e76f5f5c58881a5add929ee66e3`

## Complete structured record

```json
{
  "id": "CHQ-ED-2026-003",
  "associated_position": "CHQ-P-2026-007 v1.0",
  "relationship": "original",
  "issuance_date": "2026-03-14",
  "evidence_freeze_time": "2026-03-14T00:00:00Z",
  "total_exhibits": 2,
  "docket_status": "LOCKED",
  "docket_version": "1.0",
  "artifact_class": "EVIDENCE_DOCKET",
  "authority_level": "SUPPORTING_RECORD",
  "reliance_status": "CONTEXT_ONLY",
  "temporal_scope": "CONTEMPORANEOUS",
  "update_policy": "APPEND_ONLY",
  "exhibits": [],
  "claims": [
    {
      "claim_id": "C-01",
      "position_section": "",
      "claim_text": "Certificate lifetime compression operates exclusively within the software trust chain and does not address hardware-layer trust attestation.",
      "evidence_exhibits": [],
      "relevant_sections": "",
      "verification_type": "",
      "source_text": "CA/Browser Forum Ballot SC-081 (April 2025): governs publicly trusted TLS certificates only. Internal PKIs explicitly excluded: ‘If you are using an internal PKI for things like internal apps, dev environments, or non-public systems, you are free to set your own certificate lifespans.’ (GlobalSign FAQ, 2025).",
      "evidence_class": "E1"
    },
    {
      "claim_id": "C-02",
      "position_section": "",
      "claim_text": "Software-layer certificate rotation operates in independent validation domains from hardware-layer trust.",
      "evidence_exhibits": [],
      "relevant_sections": "",
      "verification_type": "",
      "source_text": "CA/Browser Forum Ballot SC-081: reduction schedule applies to public SSL/TLS certificates regardless of validation level (DV, OV, EV). Code signing, S/MIME, and other certificate types explicitly excluded from scope. Hardware attestation certificates not referenced in ballot text.",
      "evidence_class": "E1"
    },
    {
      "claim_id": "C-03",
      "position_section": "",
      "claim_text": "The CA/B Forum schedule compresses the window of exposure from compromised software-layer certificates; it does not alter the attestation architecture of the hardware environment.",
      "evidence_exhibits": [],
      "relevant_sections": "",
      "verification_type": "",
      "source_text": "DigiCert (2025): ‘Shorter validity periods limit how long a compromised certificate can be abused.’ Let’s Encrypt (2025): ‘Reducing how long certificates are valid for helps improve the security of the web PKI ecosystem.’ Neither source asserts hardware trust modification.",
      "evidence_class": "E1"
    },
    {
      "claim_id": "C-04",
      "position_section": "",
      "claim_text": "The implementation timeline is active as of March 15, 2026: maximum TLS lifetime reduced from 398 to 200 days. Further reductions follow in 2027 (100 days) and 2029 (47 days).",
      "evidence_exhibits": [],
      "relevant_sections": "",
      "verification_type": "",
      "source_text": "eG Innovations (Feb 2026): CA/B Forum milestone confirmed. DigiCert (2025): ‘From today until March 15, 2026, the maximum lifetime for a TLS certificate is 398 days.’ SecurityWeek (April 2025): Google, Apple, Mozilla, Microsoft, DigiCert, Amazon, GoDaddy, Sectigo all confirmed in agreement.",
      "evidence_class": "E1"
    },
    {
      "claim_id": "C-05",
      "position_section": "",
      "claim_text": "Automation becomes operationally mandatory as lifetimes compress; manual renewal is structurally untenable at 47-day cycles.",
      "evidence_exhibits": [],
      "relevant_sections": "",
      "verification_type": "",
      "source_text": "DigiCert (2025): ‘2027 changes to 100-day certificates will make manual procedures untenable.’ CA/B Forum reasoning: shorter lifetimes drive automation adoption, not merely tighter renewal schedules. DCV reuse period drops to 10 days by 2029 (GlobalSign 2026).",
      "evidence_class": "E1"
    },
    {
      "claim_id": "C-06",
      "position_section": "",
      "claim_text": "Certificate lifetime compression does not produce assurance of the hardware environment from which certificate requests originate.",
      "evidence_exhibits": [],
      "relevant_sections": "",
      "verification_type": "",
      "source_text": "GlobalSign (2026): TLS-dedicated roots are used only for publicly trusted TLS certificates, not shared with other PKI use cases. CA/B Forum scope boundary: governs CA-issued certificates, not hardware attestation infrastructure. Hardware trust attestation (TPM, TEE, Secure Enclave) operates on independent root-of-trust architectures.",
      "evidence_class": "E2"
    }
  ],
  "signals": [],
  "linked_exhibits": [
    {
      "id": "CHQ-EX-2026-002",
      "title": "Embedded Vendor Authority in Enterprise Systems",
      "temporal_tag": "HISTORICAL 2005–2024"
    },
    {
      "id": "CHQ-EX-REQUIRED",
      "title": "CA/B Forum Ballot SC-081: Certificate Lifetime Reduction Schedule",
      "temporal_tag": "EXHIBIT REQUIRED — NOT YET ISSUED"
    }
  ],
  "notice": [
    "This docket records claim-to-source mappings for CHQ-P-2026-007 v1.0.",
    "Evidence classification: E1 = primary source (standards body ballot text, CA policy documentation, browser vendor statements). E2 = inferential (architectural analysis, scope-boundary reasoning).",
    "NOTE: CHQ-EX-REQUIRED flags a missing Exhibit. CA/B Forum Ballot SC-081 should be formally entered as an operational Exhibit before this docket is closed.",
    "Docket issued under CHQ-D-2026-ESG v1.0. Reliance recognized only when registered under CHQ-R-2026-001."
  ],
  "integrity_statement": [
    "This docket records claim-to-source mappings for CHQ-P-2026-007 v1.0.",
    "Evidence classification: E1 = primary source (standards body ballot text, CA policy documentation, browser vendor statements). E2 = inferential (architectural analysis, scope-boundary reasoning).",
    "NOTE: CHQ-EX-REQUIRED flags a missing Exhibit. CA/B Forum Ballot SC-081 should be formally entered as an operational Exhibit before this docket is closed.",
    "Docket issued under CHQ-D-2026-ESG v1.0. Reliance recognized only when registered under CHQ-R-2026-001."
  ],
  "docket_hash": "ad258fe63c9fac80dc2a1913ad8ec73a47038cbf578eb916b8f31702c671c2a1",
  "immutability_layers": [
    {
      "layer": "Layer 1",
      "protects": "CHQ-ED-2026-003 Docket Hash",
      "scope": "the evidence record (claim-to-source mapping)"
    },
    {
      "layer": "Layer 2",
      "protects": "CHQ-P-2026-007 v1.0 Position Hash",
      "scope": "the position text"
    }
  ]
}
```
