Accredited Certification Authority: how to verify if a CA is valid in the ICP-Brasil (Brazilian Public Key Infrastructure).

Table of Contents

In the chain described in digital certificate, One Accredited Certification Authority It is the authorized entity within the ICP-Brasil (Brazilian Public Key Infrastructure) to issue, renew, revoke, and manage digital certificates, following its own technical, operational, and legal rules. Verifying the validity of the CA reduces operational risk, strengthens the security of digital identity, helps preserve the legal validity of electronic acts, and prevents a company from using certificates issued outside the official chain.

This validation makes a difference for legal, commercial, and compliance areas because a certificate issued by an entity outside the official chain creates documentary noise, increases internal review time, and can generate rework in audits, integrations, and formalizations. In operations with a high volume of contracts, choosing a legitimate Certification Authority (CA) also helps reduce inconsistencies in onboarding, support, and archiving of digital documents.

Summary

  • A valid CA (Certification Authority) must be accredited and linked to the official ICP-Brasil chain.
  • The verification process involves ITI sources, hierarchical tree, issuing chain, LCR, and DPC.
  • The Digital Certification Map helps locate entities that are truly accredited.
  • Signs of inconsistent documentation or lack of official ties increase the risk of fraud.

Quick facts

How to identify an accredited Certification Authority in practice.

The safest approach is to start with what is public, official, and verifiable. The most common mistake is relying solely on the company's trade name or website appearance. A legitimate Certification Authority (CA) needs to be present in the ITI ecosystem, be linked to the ICP-Brasil hierarchy, publish its technical artifacts, and maintain consistent information across the issuing certificate, chain, revocation, and operational documentation.

Step 1: Confirm that the entity appears among the entities of ICP-Brasil.

The first filter is the formal identification of the role played by the entity. According to ITIIn Brazil, an ICP-Brasil Certification Authority (CA) is the entity responsible for issuing, distributing, renewing, revoking, and managing digital certificates, as well as issuing Certificate Registration Letters (CRLs) and maintaining operational records. If a company does not appear within this official ecosystem, the validation process is compromised from the start.

This step avoids confusion between AC, AR, support provider, and commercial reseller. Not every well-known brand in the market necessarily operates at the same level of the chain. Therefore, before evaluating price, service channel, or type of certificate, the company needs to check what function that entity actually performs and in which chain it is positioned.

Step 2: Consult the hierarchical tree and the link to the chain.

After the initial identification, it's worth opening the official ICP-Brasil structure. The ITI's CA page links to the hierarchical tree with 1st and 2nd level Certification Authorities and Registration Authorities. This step helps verify if the entity is in the position it claims to occupy and if there is a clear link between the root, intermediate, and associated structures.

When the chain is clear, the analysis is less prone to operational error. In corporate environments, this reduces time spent on manual validations, avoids accepting certificates of dubious origin, and improves the predictability of the signing process, especially when there are integrations with platforms, internal compliance policies, and audit routines.

Step 3: Use the official map to locate truly accredited entities.

In situations involving in-person issuance, hybrid service, or searching for a service point, the geographic filter must also be official. According to ITI, the Digital Certification Map It was created to help citizens locate entities properly accredited to issue invoices under the ICP-Brasil standard. This reduces the risk of being referred to an unaccredited or poorly presented commercial entity.

In daily operations, the map also serves as quick evidence for internal teams. A legal department can validate the point of service before approving a supplier, while purchasing and IT can record the check in the approval workflow. This type of routine usually shortens validation time and reduces doubts among areas involved in the contracting process.

Step 4: Verify the issuing certificate, status, and chain in the repository.

The official ITI repository is one of the most useful layers of verification. There, you can find specific CA pages with data such as chain version, issue date, expiration date, type of certificate issued, and status (valid or expired). This detail is crucial because a well-known brand may have older, expired chains and another chain that is still valid.

What to check outWhere to lookWhat should appearWarning sign
AC NameITI RepositoryCorrespondence with the disclosed entityDifferent or ambiguous nomenclature
JailAC page and ICP-Brasil treeConsistent hierarchical linkAbsence of chain or incomplete information.
SituationRepositoryValid statusStatus expired or revoked
DatesAC Repository and Root ACCompatible emission and expiration datesConflicting dates

A practical example helps. On CA pages in the repository, ITI indicates whether a given chain is valid or expired, in addition to providing the download link for the certificate.

Step 5: Confirm LCR and DPC before trusting the operation.

It's not enough to find the CA's name. It's necessary to check if the organization publishes the documentation that supports its operation. The CRL shows revoked certificates, and the DPC describes certification practices and procedures. When these elements are missing, outdated, or inconsistent with the reported chain of conduct, the compliance analysis loses consistency.

The legal basis for this is explicit. According to Provisional Measure 2.200-2Certification Authorities (CAs) are responsible for issuing, distributing, revoking, and managing certificates, as well as providing lists of revoked certificates. In other words, compliance is not just about the company's marketing, but about the documentary and operational proof that it fulfills the functions of a CA within the ICP-Brasil framework.

If your company has already structured a policy for signing or reviewing contracts, you can integrate this check with your existing routines. digital signature compliance, legal risk e document securityso that the process does not depend solely on a one-off check made at the time of purchase.

Signs of compliance and signs of fraud.

A legitimate certification authority (CA) tends to show consistency between its institutional name, presence in the ITI (National Institute of Information Technology), hierarchical chain, technical documentation, and information on revocation. Signs of fraud or low reliability, on the other hand, usually appear as commercial shortcuts, generic promises, lack of official references, non-technical language regarding accreditation, and inconsistencies between what the company says and what the ITI publishes.

  • There is a match between the entity's name and the official record.
  • The certification chain is identifiable and compatible with the public hierarchy.
  • LCR and DPC exist and make sense for that operation.
  • The service point appears on the official map when applicable.
  • The status in the repository is not expired, revoked, or obscured.

For corporate users, the greatest risk is not just technical. It is also financial and procedural. Weak validation can lengthen the signing cycle, generate document rework, increase support calls, and compromise the customer experience.

Useful KPIs for monitoring AC validation

By transforming the verification process into a formal one, the company moves away from validating suppliers based solely on perception. Several indicators help track the quality and efficiency of the analysis, especially in operations with multiple issuances, many users, or reliance on certification for recurring subscriptions.

KPIHow to measureWhy observe
Validation timeTime between request and document confirmation.It demonstrates the efficiency of the internal process.
Inconsistency ratePercentage of registrations or suppliers with discrepancies.It helps detect weaknesses in the screening process.
Incidents avoidedCases blocked before hiring or issuance.It translates prevention into reduced risk.
Document reworkReissues, corrections, or rejections due to originating error.It points to the real operational impact.

These indicators can be combined with broader digital flows, such as document management, the digital and sustainable transformation e process optimizationThus, the company not only validates whether the CA exists, but also creates a replicable standard for new contracts, new areas, and new integrations.

Check out these related articles as well:

Verifying the accredited certification authority reduces risk and improves operations.

Validate a Certificate Authority accredited It's not a bureaucratic detail. It's a procedure that protects the company against supply chain inconsistencies, reduces exposure to fraud, improves legal predictability, and organizes digital operations more securely. When the verification process goes through ITI, hierarchical tree, repository, CRL, and DPC, the process ceases to be based on commercial promises and becomes supported by evidence.

In scalable contexts, this attention to detail also contributes to lower costs, less rework, and a better subscription experience. To understand how this connects to a more fluid operation, Check out how ZapSign works as a Certification Authority. within a business routine that demands agility, compliance, and control.

Frequently Asked Questions (FAQ)

What is an accredited certification authority?

It is the authorized entity within the ICP-Brasil chain to issue, renew, revoke, and manage digital certificates, as well as maintain records and revocation lists in accordance with applicable regulations. Accreditation formally connects it to the official hierarchy overseen by the ITI, allowing its compliance to be verified through public sources.

How can you tell if a certification is actually valid?

The safest approach is to consult the official ITI pages, the ICP-Brasil hierarchical tree, the CA repository, and the status of the corresponding chain. The company should check the entity's name, certificate status, validity dates, link to the chain, and availability of technical documentation such as CRL and DPC.

What is the difference between AC and AR?

The Certification Authority (CA) issues and manages digital certificates within the chain of trust. The Registration Authority (RA) acts as an affiliated structure that performs applicant service and identification activities, according to the rules of the CA to which it is linked. Confusing the two roles can lead a company to believe that a service point performs a certification function that, in practice, belongs to another entity.

Why is LCR relevant in verification?

The Certificate Revocation List shows which certificates have expired before their natural expiration date. It helps confirm whether a given certificate can still be safely accepted in a transaction. Without this consultation, the company risks relying on revoked credentials, which compromises internal controls, auditing, and document validation.

Does the choice of AC affect costs and operational efficiency?

Yes. A poor verification process can lead to rework, delays in approval, support issues, and compliance failures. Conversely, choosing a standardized and well-documented structure tends to shorten validation time, reduce inconsistencies, and facilitate the integration of the certificate into signature routines, document management, and customer service.

Leave a comment

20 - five =

zapsign

Start your free trial today!

Try our digital signature tool for free.
The first 5 documents
are free!

Share this article

Do you want to stay informed?

Subscribe to our blog

Related articles