This paper extends the work described in “An Approach to the Formalisation of a Certification Policy”, 7th International Symposium on System and Information Security (SSI 2005) by developing the preliminary formalisation process. It addresses the issue of rating the trustworthiness level of entities holding certificates issued by otherwise unconnected Certification Authorities by defining a set of criteria that have to apply to the Certificate Policy (CP) that rules their certificates. A semantic meaning of these criteria is given in this paper.