According to section 3.1 of IETF RFC 6962, when a Certification Authority (CA) submits a precertificate to a Certificate Transparency log, the CA adds a critical extension with this OID to ensure that a standard Rec. ITU-T X.509v3 client cannot validate the precertificate.