Certification is only credible when it is time-bound and revocable.
CTR-ACB defines baseline expectations for renewal cadence and revocation signaling. Ecosystems can tighten these rules.
A Certification Attestation includes a validity window (not_before, not_after).
Recommended defaults:
Renewal SHOULD:
Revocation MUST be supported at AL4, and SHOULD be supported from AL3 upward.
A revocation event SHOULD:
id)CTR-ACB does not mandate a transport for revocation notices; it requires that revocation is discoverable and actionable for relying parties at the target tier.
See: docs/guides/revocation-semantics.md.