Artifact GuideGLOBALETSI EN 319 401

ETSI EN 319 401 Audit and conformity assessment evidence

A cited guide to preparing EN 319 401 policies, practice statements, terms, records, and evidence for audit or assessor review.

EN 319 401 defines general TSP policy requirements; it does not define the independent assessment method, so assessor scope and scheme claims need separate support.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Use this page to prepare ETSI EN 319 401 V3.1.1 evidence for internal audit, customer review, or a . V3.2.1, published in January 2026, is the current ETSI edition; use this V3.1.1 clause map only when that earlier edition is expressly in scope, and otherwise map the engagement to V3.2.1. Start by naming the trust service, policy, service-specific standards, assessment scheme, period, and operating boundary. EN 319 401 sets general operation and management requirements; it does not define the independent assessment method or grant qualified status.

Section 1

Start with the assessment boundary

ETSI EN 319 401 defines general policy requirements for operation and management independent of the specific trust service type. Other specifications refine and extend those requirements for particular forms of TSP.

The standard explicitly excludes the independent-party assessment method, information to be made available to independent assessors, and assessor requirements from its scope. Its note points to ETSI EN 319 403-1 for body requirements. Keep three records separate: the EN 319 401 clause-to-evidence index, the service-specific requirement set, and the applicable assessment scheme or legal process.

Open the engagement only when the boundary is reviewable. The intake should identify the legal entity, trust service and policy, qualified or non-qualified claim, edition and service-specific standards, systems, facilities, suppliers, exclusions, assessment period, assessment criteria, assessor or customer, evidence-sharing controls, and intended output. If any of those inputs is disputed or missing, record it as a scope issue before testing controls.

  • Name the trust service, operating boundary, and applicable trust service policy before mapping EN 319 401 clauses.
  • Separate EN 319 401 requirement evidence from assessment-scheme evidence, assessor rules, certificates, trust-list entries, or regulator-specific submissions.
  • Use EN 319 401 as the baseline for operation and management controls, then add service-specific ETSI standards where the trust service type requires them.
  • Avoid public claims such as certified, qualified, assessed, or conformant unless the scheme, body or other assessor, service boundary, policy, assessment period, result, and current status are independently documented.
  • Define the output before collection: internal finding, customer response, evidence pack, report, supervisory submission, or qualified-status record. One output does not automatically stand in for another.
Section 2

Make policy, terms, and approval evidence traceable

A reviewable EN 319 401 audit file connects policies, practice statements, terms, records, and decisions to requirement identifiers. Clause 6 requires the to specify policies and practices for the trust services it provides, obtain management approval, publish and communicate them as relevant, and maintain a review process for the practice statement.

The terms and conditions are especially important because EN 319 401 requires them to identify the trust service policy, limitations on use, subscriber obligations, relying-party information, event-log retention, liability limitations, applicable legal system, complaints and dispute procedures, conformity-assessment status and scheme where applicable, and contact information.

  • Keep the trust service practice statement mapped to each applicable trust service policy and to the obligations of external organizations supporting the service.
  • Preserve management approval evidence for the policy set, practice statement, and information security policy.
  • Show how revised practice statements are reviewed, approved, made available, and notified when changes may affect subscribers, subjects, or relying parties.
  • Treat the terms and conditions as audit evidence because EN 319 401 uses them to disclose retention, liability, complaints, and assessment status.
  • Do not treat the X suffix on a requirement identifier as optional. Clause 3.4 says it marks a requirement added, changed, renumbered, or moved since V2.3.1.
Section 3

Build a clause-to-evidence audit index

A clause-to-evidence index should let a reviewer inspect the controls without undocumented internal context. At minimum, map risk assessment, information security policy, management and operations, incident management, continuity, termination planning, legal compliance, and supply-chain controls to owners and current evidence.

Clause 7.10 is central for audit readiness because it requires relevant information concerning data issued and received by the to be recorded and kept accessible for an appropriate period, including after TSP activities have ceased, for legal evidence and service continuity purposes. It also requires confidentiality and integrity of current and archived records, disclosed archival practices, availability for evidence of correct operation in legal proceedings, precise timing of significant events, and UTC synchronization for audit-log event times at least once a day.

  • Map each EN 319 401 requirement ID to the control owner, evidence artifact, evidence location, review date, and exception status.
  • Include records showing risk assessment approval, residual-risk acceptance, information security policy approval, and regular review.
  • Index event logs, incident classifications, post-incident reviews, continuity tests, backup recovery tests, and termination-plan evidence where they support the relevant clauses.
  • Record the disclosed retention period used for service records and ensure it matches the public terms and conditions.
Section 4

Apply current eIDAS assessment rules only when EU qualified status is in scope

EN 319 401 Annex B is an informative mapping to selected eIDAS provisions, not a legal conformity decision. The standard was published in June 2024 and retains references to the earlier eIDAS numbering in places. Use the amended consolidated regulation for current legal claims.

For qualified trust services, current eIDAS Article 20 requires an audit at the provider's expense at least every 24 months by a body and submission of the resulting report to the supervisory body within three working days of receipt. The provider must inform the supervisory body no later than one month before a planned audit and allow it to observe on request. The supervisory body may also audit or request a conformity assessment at any time. Article 21 governs initiation of a qualified trust service, and qualified status is tied to the supervisory process and trusted list. These legal steps are separate from preparing EN 319 401 evidence.

  • Use EN 319 401 Annex B only as an informative crosswalk for risk, incident, continuity, records, and terms-and-conditions evidence.
  • Keep qualified-service claims separate from general EN 319 401 controls and require service-specific support before publishing them.
  • When certificate services are in scope, add EN 319 411-1 or EN 319 411-2 evidence instead of relying on EN 319 401 alone.
  • Document the difference between internal audit readiness, customer evidence, a report, the supervisory decision, and trusted-list status.
  • Track four distinct dates for a planned qualified-provider audit: the advance notice to the supervisory body, the audit period, receipt of the report, and submission of that report within three working days.
Section 5

Common audit-readiness failures

Audit files fail when the evidence is too broad or detached from the service being assessed. A generic security policy is not enough if it cannot be traced to the trust service practice statement, applicable policy, service records, and disclosed terms.

EN 319 401 supports an evidence model for operation and management. details, conformity assessment body competence, scheme rules, service-specific policies, and qualified-service status must come from the applicable scheme, service-specific standard, and legal or supervisory evidence.

Does an EN 319 401 evidence review grant qualified status under eIDAS?

No. EN 319 401 does not grant qualified status. For an EU qualified trust service, the provider needs the applicable report and supervisory process under eIDAS, and qualified status is reflected in the relevant trusted list. The service-specific standards and assessment scheme also need to be identified.

How often must a qualified trust service provider be audited under current eIDAS?

Article 20 of the amended consolidated eIDAS Regulation requires qualified trust service providers to be audited at their own expense at least every 24 months by a body. The provider must notify the supervisory body no later than one month before a planned audit and allow it to observe on request. The resulting conformity assessment report must be submitted to the supervisory body within three working days of receipt. The supervisory body may also audit or request an assessment at any time. These are eIDAS duties, not frequencies or procedures set by EN 319 401 itself.

What happens if a qualified provider does not meet an eIDAS requirement?

Under current eIDAS Article 20, the supervisory body requires a remedy within a set time limit where applicable. If the provider does not remedy the failure, the supervisory body shall withdraw the qualified status of the provider or the affected service when justified by the extent, duration, and consequences of the failure. An EN 319 401 evidence pack can support the review and remedy, but it does not determine the supervisory outcome.

  • Do not describe EN 319 401 as a complete audit methodology or scheme.
  • Do not treat service-specific certificate, time-stamp, validation, preservation, or registered delivery requirements as covered unless the applicable service standard is mapped.
  • Do not publish an assessment claim without naming the trust service, policy, scheme, assessment period, and evidence boundary.
  • Do not keep retention, complaint, liability, or assessment-status facts only in private spreadsheets when EN 319 401 expects them in subscriber and relying-party terms.
Primary sources

References and citations

Related guides

Explore more topics

CA and RA responsibilities under ETSI EN 319 401
How ETSI EN 319 401 frames CA and RA responsibility: TSP practice statements, management approval, role segregation, subcontractor control, and evidence boundaries.
eIDAS Articles 19 and 24: current ETSI mapping
Understand why old EN 319 401 editions mapped eIDAS Article 19, what replaced it, and how V3.2.1 maps current Article 24 duties.
ETSI EN 319 401 Audit Evidence Pack
Build an ETSI EN 319 401 audit evidence pack around records, logs, policies, risk assessment, incident handling, continuity, and supplier evidence.
ETSI EN 319 401 Audit Evidence Pack Workflow
Build an ETSI EN 319 401 audit evidence pack for trust service providers: risk assessment, practice statement, policies, records, logs, continuity, and supplier evidence.
ETSI EN 319 401 compliance duties for TSPs
ETSI EN 319 401 compliance guidance for trust service providers covering legal operation, evidence, accessibility, privacy, records, incidents, continuity, and suppliers.
ETSI EN 319 401 conformity assessment bodies: what is covered?
Understand what ETSI EN 319 401 says, and does not say, about conformity assessment bodies, independent assessment, and TSP evidence preparation.
ETSI EN 319 401 FAQ for trust service providers
Plain-language ETSI EN 319 401 answers covering TSP scope, trust service practice statements, risk assessment, incidents, records, continuity, and supplier evidence.
ETSI EN 319 401 Incident and Continuity Workflow
Build an EN 319 401 incident and continuity evidence workflow for TSP monitoring, response, reporting, records, backup recovery, and crisis review.
ETSI EN 319 401 Incident Reporting and Continuity Duties
Practical ETSI EN 319 401 V3.1.1 guidance for trust service incident response, reporting, evidence retention, business continuity, and termination planning.
ETSI EN 319 401 Personnel, Asset, and Access Controls
Clause-focused EN 319 401 V3.1.1 guide to TSP personnel duties, trusted roles, asset inventories, classification, and access-control evidence.
ETSI EN 319 401 policy and security requirements
ETSI EN 319 401 guidance for TSP policy and security requirements covering risk assessment, practice statements, terms, security controls, incidents, and evidence.
ETSI EN 319 401 policy documentation: what is required?
How ETSI EN 319 401 treats practice statements, terms, network and information systems security policy, evidence records, and change review.
ETSI EN 319 401 requirements map
Map ETSI EN 319 401 V3.1.1 requirements for trust service providers across risk assessment, policies, TSP operations, incidents, evidence, continuity, termination, and supply chain controls.
ETSI EN 319 401 Risk Assessment and Treatment
Clause-cited ETSI EN 319 401 V3.1.1 guidance for trust service risk assessment, risk treatment, residual-risk approval, and evidence planning.
ETSI EN 319 401 Subcontractor Controls
Practical EN 319 401 guidance for TSP subcontractor controls: retained responsibility, agreements, SLAs, supplier registers, monitoring, and audit evidence.
ETSI EN 319 401 Subcontractor Evidence Workflow
Build an EN 319 401 subcontractor evidence workflow for TSP supplier agreements, SLAs, audit mechanisms, risk reviews, supplier registers, and archived records.
ETSI EN 319 401 Subcontractor Requirements FAQ
How ETSI EN 319 401 treats subcontractors, outsourcing, supplier agreements, SLAs, monitoring, evidence, and retained TSP responsibility.
ETSI EN 319 401 Trust Service Applicability Workflow
A scoped workflow for deciding when ETSI EN 319 401 applies to a trust service and what TSP policy, risk, terms, operations, and supplier evidence to collect.
ETSI EN 319 401 Trust Service Provider Applicability
Use ETSI EN 319 401 to decide whether a trust service provider activity falls in the standard's type-independent baseline and what service, policy, risk, supplier, and evidence boundaries to document.
ETSI EN 319 401 vs eIDAS: Controls and Legal Duties
Compare ETSI EN 319 401 V3.2.1 with current eIDAS duties for qualified and non-qualified trust service providers, including risk, incidents, audits, records, and termination.
ETSI EN 319 401 vs EN 319 403-1: TSP Policy vs CAB Assessment
Compare ETSI EN 319 401 V3.2.1 provider controls with EN 319 403-1 V2.3.1 CAB requirements for audit scope, evidence, sampling, reports, corrective action, and reassessment.
Security Incidents in ETSI EN 319 401
How ETSI EN 319 401 V3.2.1 expects TSPs to detect, classify, respond to, report, document, test, and review security incidents.
Trust service provider scope under ETSI EN 319 401
How to scope ETSI EN 319 401 for a trust service provider: service boundaries, trust service policy, practice statement, terms, risks, and third-party components.