@jschauma I am a complete layman, but it even explicitly states that it will also apply for internal certs: "However, if you were making use of policies to exempt certain internal certificates or domains from CT, you will need to apply those policies to Firefox as well. See https://wiki.mozilla.org/SecurityEngineering/Certificate_Transparency#Enterprise_Policies"