Current through Register Vol. 31, No. 1, January 3, 2025
Section R2-12-504 - Certification Authority Approval Application, Suspension, RevocationA. Acceptable Certification Authorities 1. The Secretary of State shall maintain an "Approved List of Certification Authorities" authorized to issue certificates for electronically signed communication with public entities in Arizona.2. Public entities shall only accept certificates from Certification Authorities that appear on the "Approved List of Certification Authorities" and are authorized to issue certificates by the Secretary of State.B. Registration of Certification Authorities 1. The Secretary of State shall place Certification Authorities on the "Approved List of Certification Authorities" after the Certification Authority provides the Secretary of State with a copy of an unqualified performance audit performed in accordance with standards set in S.A.S. 70 to ensure that the Certification Authorities practices and policies are consistent with the requirements in this Article and any requirements of the Policy Authority. a. Certification Authorities that have been in operation for one year or less shall undergo a S.A.S. 70 type 1 audit - A report of Policies and Procedures placed in operation, receiving an unqualified opinion.b. Certification Authorities that have been in operation for longer than one year shall undergo a S.A.S. 70 type 2 audit - A Report of Policies and Procedures placed in operation and test of operating effectiveness, receiving an unqualified opinion.c. To remain on the "Approved List of Certification Authorities", a Certification Authority must provide proof of compliance every two years after initially being placed on the list and meet any requirements of the Policy Authority in effect at that time.2. In lieu of completing the auditing requirement in subsection (B)(1), Certification Authorities may be placed on the "Approved List of Certification Authorities" upon providing the Secretary of State with proof acceptable to the Secretary of State that the Certification Authority meets the Policy Authority's criteria for acceptance of a Foreign License (non-Arizona license). a. Certification Authorities shall be removed from the "Approved List of Acceptable Certification Authorities" unless they provide current proof of accreditation to the Secretary of State at least once per year no later than December 31 of each year.b. If the Secretary of State is informed a Certification Authority has had its accreditation revoked, the Certification Authority shall be removed from the "Approved List of Certification Authorities" immediately. Ariz. Admin. Code § R2-12-504
Adopted by exempt rulemaking at 5 A.A.R. 742, effective February 19, 1999 (Supp. 99-1).