ETSI EN 319 401 Audit and conformity assessment evidence
A cited guide to preparing EN 319 401 policies, practice statements, terms, records, and evidence for audit or assessor review.
EN 319 401 defines general TSP policy requirements; it does not define the independent assessment method, so assessor scope and scheme claims need separate support.
Use this page to prepare ETSI EN 319 401 V3.1.1 evidence for internal audit, customer review, or a . V3.2.1, published in January 2026, is the current ETSI edition; use this V3.1.1 clause map only when that earlier edition is expressly in scope, and otherwise map the engagement to V3.2.1. Start by naming the trust service, policy, service-specific standards, assessment scheme, period, and operating boundary. EN 319 401 sets general operation and management requirements; it does not define the independent assessment method or grant qualified status.
1
Section 1
Start with the assessment boundary
ETSI EN 319 401 defines general policy requirements for operation and management independent of the specific trust service type. Other specifications refine and extend those requirements for particular forms of TSP.
The standard explicitly excludes the independent-party assessment method, information to be made available to independent assessors, and assessor requirements from its scope. Its note points to ETSI EN 319 403-1 for body requirements. Keep three records separate: the EN 319 401 clause-to-evidence index, the service-specific requirement set, and the applicable assessment scheme or legal process.
Open the engagement only when the boundary is reviewable. The intake should identify the legal entity, trust service and policy, qualified or non-qualified claim, edition and service-specific standards, systems, facilities, suppliers, exclusions, assessment period, assessment criteria, assessor or customer, evidence-sharing controls, and intended output. If any of those inputs is disputed or missing, record it as a scope issue before testing controls.
Name the trust service, operating boundary, and applicable trust service policy before mapping EN 319 401 clauses.
Separate EN 319 401 requirement evidence from assessment-scheme evidence, assessor rules, certificates, trust-list entries, or regulator-specific submissions.
Use EN 319 401 as the baseline for operation and management controls, then add service-specific ETSI standards where the trust service type requires them.
Avoid public claims such as certified, qualified, assessed, or conformant unless the scheme, body or other assessor, service boundary, policy, assessment period, result, and current status are independently documented.
Define the output before collection: internal finding, customer response, evidence pack, report, supervisory submission, or qualified-status record. One output does not automatically stand in for another.
This guide helps connect EN 319 401 clauses to owners, records, terms, practice statements, and assessment-scope decisions before evidence requests fragment across teams.
Make policy, terms, and approval evidence traceable
A reviewable EN 319 401 audit file connects policies, practice statements, terms, records, and decisions to requirement identifiers. Clause 6 requires the to specify policies and practices for the trust services it provides, obtain management approval, publish and communicate them as relevant, and maintain a review process for the practice statement.
The terms and conditions are especially important because EN 319 401 requires them to identify the trust service policy, limitations on use, subscriber obligations, relying-party information, event-log retention, liability limitations, applicable legal system, complaints and dispute procedures, conformity-assessment status and scheme where applicable, and contact information.
Keep the trust service practice statement mapped to each applicable trust service policy and to the obligations of external organizations supporting the service.
Preserve management approval evidence for the policy set, practice statement, and information security policy.
Show how revised practice statements are reviewed, approved, made available, and notified when changes may affect subscribers, subjects, or relying parties.
Treat the terms and conditions as audit evidence because EN 319 401 uses them to disclose retention, liability, complaints, and assessment status.
Do not treat the X suffix on a requirement identifier as optional. Clause 3.4 says it marks a requirement added, changed, renumbered, or moved since V2.3.1.
A clause-to-evidence index should let a reviewer inspect the controls without undocumented internal context. At minimum, map risk assessment, information security policy, management and operations, incident management, continuity, termination planning, legal compliance, and supply-chain controls to owners and current evidence.
Clause 7.10 is central for audit readiness because it requires relevant information concerning data issued and received by the to be recorded and kept accessible for an appropriate period, including after TSP activities have ceased, for legal evidence and service continuity purposes. It also requires confidentiality and integrity of current and archived records, disclosed archival practices, availability for evidence of correct operation in legal proceedings, precise timing of significant events, and UTC synchronization for audit-log event times at least once a day.
Map each EN 319 401 requirement ID to the control owner, evidence artifact, evidence location, review date, and exception status.
Include records showing risk assessment approval, residual-risk acceptance, information security policy approval, and regular review.
Index event logs, incident classifications, post-incident reviews, continuity tests, backup recovery tests, and termination-plan evidence where they support the relevant clauses.
Record the disclosed retention period used for service records and ensure it matches the public terms and conditions.
Apply current eIDAS assessment rules only when EU qualified status is in scope
EN 319 401 Annex B is an informative mapping to selected eIDAS provisions, not a legal conformity decision. The standard was published in June 2024 and retains references to the earlier eIDAS numbering in places. Use the amended consolidated regulation for current legal claims.
For qualified trust services, current eIDAS Article 20 requires an audit at the provider's expense at least every 24 months by a body and submission of the resulting report to the supervisory body within three working days of receipt. The provider must inform the supervisory body no later than one month before a planned audit and allow it to observe on request. The supervisory body may also audit or request a conformity assessment at any time. Article 21 governs initiation of a qualified trust service, and qualified status is tied to the supervisory process and trusted list. These legal steps are separate from preparing EN 319 401 evidence.
Use EN 319 401 Annex B only as an informative crosswalk for risk, incident, continuity, records, and terms-and-conditions evidence.
Keep qualified-service claims separate from general EN 319 401 controls and require service-specific support before publishing them.
When certificate services are in scope, add EN 319 411-1 or EN 319 411-2 evidence instead of relying on EN 319 401 alone.
Document the difference between internal audit readiness, customer evidence, a report, the supervisory decision, and trusted-list status.
Track four distinct dates for a planned qualified-provider audit: the advance notice to the supervisory body, the audit period, receipt of the report, and submission of that report within three working days.
Audit files fail when the evidence is too broad or detached from the service being assessed. A generic security policy is not enough if it cannot be traced to the trust service practice statement, applicable policy, service records, and disclosed terms.
EN 319 401 supports an evidence model for operation and management. details, conformity assessment body competence, scheme rules, service-specific policies, and qualified-service status must come from the applicable scheme, service-specific standard, and legal or supervisory evidence.
Does an EN 319 401 evidence review grant qualified status under eIDAS?
No. EN 319 401 does not grant qualified status. For an EU qualified trust service, the provider needs the applicable report and supervisory process under eIDAS, and qualified status is reflected in the relevant trusted list. The service-specific standards and assessment scheme also need to be identified.
How often must a qualified trust service provider be audited under current eIDAS?
Article 20 of the amended consolidated eIDAS Regulation requires qualified trust service providers to be audited at their own expense at least every 24 months by a body. The provider must notify the supervisory body no later than one month before a planned audit and allow it to observe on request. The resulting conformity assessment report must be submitted to the supervisory body within three working days of receipt. The supervisory body may also audit or request an assessment at any time. These are eIDAS duties, not frequencies or procedures set by EN 319 401 itself.
What happens if a qualified provider does not meet an eIDAS requirement?
Under current eIDAS Article 20, the supervisory body requires a remedy within a set time limit where applicable. If the provider does not remedy the failure, the supervisory body shall withdraw the qualified status of the provider or the affected service when justified by the extent, duration, and consequences of the failure. An EN 319 401 evidence pack can support the review and remedy, but it does not determine the supervisory outcome.
Do not describe EN 319 401 as a complete audit methodology or scheme.
Do not treat service-specific certificate, time-stamp, validation, preservation, or registered delivery requirements as covered unless the applicable service standard is mapped.
Do not publish an assessment claim without naming the trust service, policy, scheme, assessment period, and evidence boundary.
Do not keep retention, complaint, liability, or assessment-status facts only in private spreadsheets when EN 319 401 expects them in subscriber and relying-party terms.
Current legal source for recurring qualified-provider audits, report submission, initiation of a qualified trust service, supervisory verification, and trusted lists.