A protocol developed to replace CRL. Allows systems to query a CA server directly and return a response whether it is revoked or not