ETSI EN 319 401Free Resource

ETSI EN 319 401 TSP Requirements

Use this ETSI EN 319 401 edition guide to scope the common governance and security baseline for a that provides one or more trust services.

V3.1.1 edition map; V3.2.1 published 2026-01Type-independent TSP baselineAssessment method sits outside EN 319 401
Quick start
EN 319 401
ETSI EN 319 401 requirements
Start with the service boundary: what is provided, by whom, through which components and suppliers, under which policy.
ETSI EN 319 401 audit evidence pack
Organize proof around management approval, risk treatment, public terms, , asset and access control, operations, incidents, UTC-synchronized records, recovery tests, termination, and suppliers.
Choose the next source
Add the service-specific ETSI standard for the actual , compare with the edition required for the work, and use Annex B only as an informative historical mapping.

Follow the guides from scope to controls, evidence and claims; do not treat the general baseline as a complete service-specific or legal checklist.

Key dates
17
Topics
7
FAQs
2
Comparisons
V3.1.1
Version
Where to start
Requirements map
Confirm the , provider role, service components, external parties, policy and assessment boundary before mapping controls.
Common control baseline
Map clauses 5 to 7 across risk, policies, personnel, assets, access, operations, incidents, evidence, continuity, termination, compliance, and supply chain.
Evidence and claims
Collect traceable operating evidence, then keep EN 319 401 conformance, external assessment, qualified status, and legal compliance as separate claims.
Version and status
was adopted on 30 May 2024 and published in June 2024; ETSI published V3.2.1 in January 2026. The V3.1.1 national transposition dates were standards milestones, not universal legal deadlines.
Assess risk
Publish practices
Retain evidence
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Mar 4, 2026
Updated
Jul 16, 2026

is a European standard edition, not a law, certificate, or current-edition claim. ETSI published V3.2.1 in January 2026. Confirm the edition required by the applicable trust-service policy, service-specific standard, assessment scheme, contract, and current law before using this map.

Recommended reading path

Choose the next trust-service decision

New to the standard? Establish the service and provider boundary first. If scope is already documented, jump to common controls, operating evidence, assessment boundaries, or a focused comparison.

1

Start here: service, provider, and policy scope

Decide whether the organization is providing a trust service, identify components and external parties, and record the trust-service policy and service-specific standards that complete the baseline.

2

Common governance and operating controls

Translate clauses 5 to 7 into risk, personnel, asset, access, operational, incident, continuity, termination, compliance, and supplier responsibilities.

3

Evidence, assessment, and assurance workflows

Build traceable evidence without confusing an internal evidence pack with independent conformity assessment, qualified status, or legal compliance.

4

Compare sources or answer a focused question

Separate the standard from eIDAS law and conformity-assessment-body requirements, or use the FAQ for a specific scope, policy, incident, supplier, or role question.

Next step

Turn ETSI EN 319 401 requirements into accountable TSP control work

Use the EN 319 401 pages as the shared entry point for risk assessment, practice statements, policy controls, incident response, evidence records, continuity planning, and supplier oversight. Route execution into Assessment Autopilot for task ownership and into SSOT for governed evidence records.

What this unlocks
  • Assign owners for risk assessment approval, the , terms and conditions, information security policy, and supply chain reviews.
  • Use Assessment Autopilot to request evidence for access reviews, vulnerability scans, incident records, audit logs, backup tests, and termination-plan checks.
  • Use SSOT to keep policies, service agreements, supplier registers, continuity records, and control evidence in one governed system.
  • Keep the work aligned to the EN 319 401 clause structure so auditors and reviewers can trace each record back to the relevant requirement.