Recent instances of mis-issued certificates have raised concerns about certification authorities. We propose a PKI monitoring framework to classify certificates based on their issuance template and evaluate adherence to the CA/Browser Forum requirements. We run our analysis on a large sample of recently issued certificates.