A thumbdrive in some safe, and a few printed-out copies of the key just in case the thumbdrive fails?
- https://en.wikipedia.org/wiki/Key_ceremony
- https://cryptography.fandom.com/wiki/Root_Key_Ceremony
You can even watch recordings of selected ceremonies on YouTube. Some of them are several hours long.
I'm pretty sure the CA/B Forum mandates all CA private keys to remain on HSMs (checked through audits).
The handling of key material is supposed to be checked as a part of the (required) yearly audits, which they have passed[1,2] (though the single auditor they’ve always used “does not audit any other publicly-trusted CAs”[3]). The links are in the Common CA Database (CCADB) [4], but it seems really hard to find a good publicly-accessible report page (I still haven’t found the older audits, for example).
ETA: For TrustCor specifically, Kathleen Wilson (responsible for the Mozilla root store) has collected the audit reports on Bugzilla[5].
[1] https://www.cpacanada.ca/generichandlers/CPACHandler.ashx?at...
[2] https://www.cpacanada.ca/generichandlers/CPACHandler.ashx?at...
[3] https://groups.google.com/a/mozilla.org/g/dev-security-polic...
[4] https://ccadb-public.secure.force.com/mozilla/IncludedCACert...