- Supports clause 7.14 supply-chain policy, procedures, subcontracting, outsourcing, supplier agreements, SLAs, cloud-service responsibility, and supplier registers.
"Supply chain policy"
A practical guide to the compliance clause in ETSI EN 319 401 V3.1.1 and the evidence a trust service provider needs around it.
This page maps V3.1.1. ETSI published V3.2.1 in January 2026; confirm the edition in scope and keep legal operation, privacy, accessibility, incident, continuity, and supplier evidence separate from broad compliance claims.
Structured answer sets in this page tree.
Cited legal and guidance references.
Clause 7.13 of ETSI EN 319 401 V3.1.1 requires a trust service provider to operate legally and trustworthily, show how it meets applicable legal requirements, make trust services and related end-user products accessible to persons with disabilities where feasible, and protect personal data. A compliance file should connect those requirements to the service-specific legal inventory and to evidence from the risk, policy, personnel, access, logging, incident, continuity, termination, and supply-chain controls elsewhere in the standard.
Clause 7.13 does not identify every law that applies to a service. The has to identify those laws from its jurisdiction, service type, qualified or non-qualified status, processing activities, contracts, and operating locations, then retain evidence showing how each applicable requirement is met. EN 301 549 is a standard the clause says should be considered for accessibility; V3.1.1 does not make every EN 301 549 provision automatically applicable.
EN 319 401 is a type-independent baseline for operation and management. It does not supersede service-specific standards or define independent assessment methods. ETSI published V3.2.1 in January 2026, so this V3.1.1 guide is neither proof of qualified status nor a substitute for checking the edition and legal rules that control the actual service.
A defensible EN 319 401 compliance file starts with the risk assessment in clause 5. The has to identify, analyse, and evaluate trust-service risks, choose risk treatment measures, document the necessary security requirements and operational procedures, review the assessment regularly, and have management approve the assessment and residual risk.
Clauses 6.1 through 6.3 then turn that risk work into governance evidence. The practice statement identifies how the addresses the applicable trust service policy, the terms and conditions tell subscribers and relying parties what service policy, limits, liabilities, log-retention period, assessment status, contact details, and availability commitments apply, and the information security policy sets the organization's approach to information security.
This ETSI EN 319 401 guide helps connect clause 7.13 legal, accessibility, and privacy duties with the risk, policy, incident, continuity, and supplier evidence that supports them.
Convert EN 319 401 controls into accountable tasks, evidence requests, and review milestones.
Use cited ETSI material to resolve scope, applicability, evidence, and version questions before implementation.
Review trust-service scope, evidence owners, supplier dependencies, and the next EN 319 401 compliance actions with Sorena.
The compliance claim is weak if it is not tied to operational controls. EN 319 401 requires segregation of conflicting duties, trained and reliable personnel, identified trusted roles, asset inventory and classification, least-privilege access administration, privileged-account controls, critical-application authentication, accountability through logs, key lifecycle controls, physical protection for critical systems, secure development analysis, and change control for operational software and configurations.
For review purposes, summarize those controls by evidence type rather than by department. A visitor should be able to see which asset register, role appointment record, access review, change ticket, key-management record, physical access record, or software-release approval supports the compliance statement.
EN 319 401 makes incident and record evidence concrete. The has to establish monitoring and logging mechanisms, detect abnormal activities, maintain and review logs, establish incident response procedures, document incident detection and response, report significant breaches according to applicable rules, assess and classify events, and perform post-incident reviews that identify root cause and reduce recurrence risk.
Records and continuity are also compliance evidence. Clause 7.10 requires relevant information about data issued and received by the to be recorded and kept accessible for an appropriate period, including after the TSP's activities cease, for legal evidence and service continuity. Clause 7.11 requires continuity, backup, recovery, and crisis-management planning; clause 7.12 requires termination planning for subscriber, relying-party, subcontractor, key, evidence-transfer, and service-transfer issues.
Include supply-chain evidence when a supplier, cloud provider, subcontractor, outsourcer, or trust service component provider is involved. EN 319 401 requires processes and procedures for security risks associated with supplier products and services, including the ICT supply chain, and it requires the to maintain overall responsibility when other parties provide parts of the service.
For practical review, keep the supplier file close to the compliance file. It should show selection criteria, cybersecurity requirements, supplier agreements, service levels or audit mechanisms, critical-component traceability, cloud shared-responsibility expectations, monitoring of supplier changes, and a register of suppliers and agreements showing where information is managed or archived.
"Supply chain policy"