ETSI EN 319 401 TSP Requirements
Use this ETSI EN 319 401 edition guide to scope the common governance and security baseline for a that provides one or more trust services.
Follow the guides from scope to controls, evidence and claims; do not treat the general baseline as a complete service-specific or legal checklist.
is a European standard edition, not a law, certificate, or current-edition claim. ETSI published V3.2.1 in January 2026. Confirm the edition required by the applicable trust-service policy, service-specific standard, assessment scheme, contract, and current law before using this map.
Choose the next trust-service decision
New to the standard? Establish the service and provider boundary first. If scope is already documented, jump to common controls, operating evidence, assessment boundaries, or a focused comparison.
Start here: service, provider, and policy scope
Decide whether the organization is providing a trust service, identify components and external parties, and record the trust-service policy and service-specific standards that complete the baseline.
Common governance and operating controls
Translate clauses 5 to 7 into risk, personnel, asset, access, operational, incident, continuity, termination, compliance, and supplier responsibilities.
Evidence, assessment, and assurance workflows
Build traceable evidence without confusing an internal evidence pack with independent conformity assessment, qualified status, or legal compliance.
Compare sources or answer a focused question
Separate the standard from eIDAS law and conformity-assessment-body requirements, or use the FAQ for a specific scope, policy, incident, supplier, or role question.
Turn ETSI EN 319 401 requirements into accountable TSP control work
Use the EN 319 401 pages as the shared entry point for risk assessment, practice statements, policy controls, incident response, evidence records, continuity planning, and supplier oversight. Route execution into Assessment Autopilot for task ownership and into SSOT for governed evidence records.
- Assign owners for risk assessment approval, the , terms and conditions, information security policy, and supply chain reviews.
- Use Assessment Autopilot to request evidence for access reviews, vulnerability scans, incident records, audit logs, backup tests, and termination-plan checks.
- Use SSOT to keep policies, service agreements, supplier registers, continuity records, and control evidence in one governed system.
- Keep the work aligned to the EN 319 401 clause structure so auditors and reviewers can trace each record back to the relevant requirement.