Regulations on Required Information for Certification Practice Statements
1.中華民國九十三年七月七日經濟部經商字第 09302102450 號令訂定發 布全文 36 條;並自發布日施行 中華民國一百十一年八月二十四日行政院院臺規字第 1110184307 號公 告第 3 條第 1 款所列屬「經濟部」之權責事項,自一百十一年八月 二十七日起改由「數位發展部」管轄 2.中華民國一百十三年十一月十四日數位發展部數授產經字第 113400089 2 號令發布廢止
資料來源:全國法規資料庫(ChOrder.json,版本 2026/7/24 上午 12:00:00)・政府資料開放授權
These Regulations are enacted pursuant to Paragraph 2, Article 11 of the Electronic Signatures Act.
1These Regulations make use of the following defined terms:
21.“Assurance” means a basis that the trusted entity has complied with certain security requirements.
32.“Assurance level” means a certain level in a relative assurance tier.
43.“Certificate policy (CP)” means a named set of rules that indicates the applicability of a certificate to a particular community or class of application with common security requirements.
54.“Object identifier (OID)” means a unique alphanumeric/numeric identifier registered under the International Standard Organization registration standard, and which could be used to identify the uniquely corresponding CP; where the CP is modified, the OID is not changed accordingly.
65.“Subscriber” means a subject named or identified in a certificate that holds the private key which corresponds to the public key listed in the certificate.
76.“Relying party” means a recipient of a certificate who acts in reliance on that certificate.
87.“Repository” means a system for storing and retrieving certificates or other information relevant to certificates.
1A certification service provider shall specify the following significant particulars in the first page of the certification practice statement (CPS):
21.The approval number issued by the competent authority
32.Types of certificate
43.Assurance levels of certificates
54.Applicability and restrictions on certificate usage
65.Limitations of liability, and allocation of liability within the application period for certificate revocation
76.Whether the certificate services are audited by a third party or have been granted any seal
A certification service provider shall specify the supported CPs, provide the OIDs of the CPs, and specify other significant documents supporting the CPS.
A certification service provider shall specify the identity or types of entity that fill the roles of participants operating and maintaining the certification service. In the event that an entity participates in the certification service by outsourcing, the certification service provider shall also specify the name and qualification of the entity.
A certification service provider shall specify the telephone number, mailing address and electronic mail address of a contact person to subscribers or relying parties to report the loss of private key and to consult matters of the CPS.
1A certification service provider shall specify the following subscriber obligations:
21.Ensuring accuracy of representations in certificate application
32.Safely generating and guarding the private key where the private key is generated by the subscriber
43.Complying with the restrictions on private key and certificate usage
54.Notifying the matters of private key compromise or loss
1A certification service provider shall specify the following replying party obligations:
21.Taking responsibilities to verify digital signatures
32.Placing reliance on the certificate within the purposes of certificate usage
43.Inspecting the certificate status
54.Acknowledging the liability provisions on certification service providers
1A certification service provider shall specify the following particulars in respect of the publication of information and the operation and maintenance of repositories:
21.The methods it publishes information such as certificates, certificate status, CPS and CP
32.When information must be published and the frequency of publication
43.Access control on repositories
A certification service provider shall specify a notification mechanism in the case of CPS modification.
1A certification service provider shall specify the following particulars in respect of financial responsibility:
21.Amount of insurance coverage provided for liability for potential and actual damages
32.Whether the operation of the certification service provider is covered by insurance
43.Whether financial audit of the certification service provider is implemented by a third party
A certification service provider shall specify the dispute resolution procedures and governing and applicable laws to resolve disputes arising out of the certification service or certificate usage.
A certification service provider shall specify whether subscribers can request for refund. If applicable, it shall also specify the procedures for refund.
1A certification service provider shall specify the following particulars in respect of compliance audit or other assessment:
21.Frequency of compliance audit or other assessment
32.The qualifications of the personnel performing the audit or other assessment
43.Assurance of the independence of the personnel performing the audit or other assessment
54.The scope of the compliance audit or other assessment
65.Actions taken as a result of deficiencies found during the compliance audit or other assessment
76.The parts and methods to disclose the reports of compliance audit or other assessment
1A certification service provider shall specify the types of personal information of subscribers to be protected and methods to keep the information confidential:
21.Types of information to be kept confidential
32.Relevant particulars concerning personal information protection
A certification service provider shall specify the rules of naming it adopts.
A certification service provider shall specify the methods to prove the applicant’s possession of private key that corresponds to the registered public key.
A certification service provider shall specify the identification and authentication requirements and procedures for applicants.
A certification service provider shall specify a secure identification and authentication procedure for a revocation or suspension request.
A certification service provider shall specify the procedures to process applications for various certificates.
A certification service provider shall specify conduct of subscribers constituting acceptance of the certificate in respect of certificate issuance, renewal, and modification.
1A certification service provider that provides certificate suspension service shall specify the following particulars:
21.Circumstances under which a certificate may be suspended upon request
32.Circumstances under which a certificate may be suspended by certification service provider
43.Who can request the suspension of a certificate
54.Procedures to request certificate suspension
65.How long the suspension may last
76.The time within which certification service provider must process the suspension request
87.Procedures to restore certificate usage
1A certification service provider shall specify the following particulars in respect of certificate revocation:
21.Circumstances under which a certificate may be revoked upon request
32.Circumstances under which a certificate shall be revoked by certification service provider
43.Who can request the revocation of the certificate
54.Procedures used for certificate revocation request
65.The time within which certification service provider must process the revocation request
76.Issuance frequency of a CRL made by the certification service provider
87.On-line revocation/status checking availability
A certification service provider shall specify the physical, procedural, and personnel security controls it adopts.
1A certification service provider shall specify the following particulars in respect of archival records:
21.Types of records that are archived, which shall include all data information necessary for certificate verification
32.Retention period for an archive
43.Protection of an archive
54.Archive backup procedures
65.Requirements for time-stamping of records
76.Management frequency of archived record
1A certification service provider shall specify the following procedures for key changeover:
21.For certificate verification, the procedures of certifying the new public key with the old public key
32.The methods to provide a new public key
A certification service provider shall specify the plan relating to the recovery procedures in the event of compromise or disaster.
1A certification service provider shall specify the following procedures for termination of any certification service:
21.Procedures for notification and publication
32.Arrangements for the currently valid certificates
43.The transfer of archival records or the retention period
1A certification service provider shall specify the following particulars in respect of key pair generation and installation:
21.Who generates the public, private key pair of subscribers
32.Where the private key is not generated by the subscriber, how is it provided securely to the subscriber
43.How is the certification service provider’s public key provided securely to subscribers or relying parties
54.Key sizes
65.Key parameters generation and the parameter quality checking
76.Keys usage purposes
1A certification service provider shall specify the following particulars in respect of private key protection:
21.Whether cryptographic module meets certain standards
32.Whether the private key is under n out of m multi-person control
43.Whether the private key is escrowed, backed up, archived, or transferred and stored in a cryptographic module; if applicable, what methods and procedures are
54.Methods of activating, deactivating, and destroying the private key
A certification service provider shall specify the operational period of the certificates, whether the public key is archived, and the usage periods for the key pair.
A certification service provider shall specify the protection mechanism of activation data.
A certification service provider shall specify measures for software system and network security controls.
1A certification service provider shall specify the following particulars in respect of certificate profile:
21.Version numbers
32.Certificate extensions
43.Algorithm object identifiers
54.Name forms
65.Name constraints
76.CP OIDs
87.Usage of policy constraints extension
98.Processing semantics for the critical CP extension
1A certification service provider shall specify the following particulars in respect of CRL profile:
21.Version numbers
32.CRL and CRL entry extensions
These Regulations shall come into force from the date of their promulgation.
98.“Certificate revocation list (CRL)” means a list of revoked certificates digitally signed by a certification service provider.
109.“Activation data” means data values other than keys, thArticleArticlet are required to operate cryptographic modules and that need to be protected.