ETSI EN 319 401 is an operational control standard, not a replacement for . The current ETSI edition is V3.2.1 (2026-01). Its informative Annex B maps selected controls to eIDAS, while the consolidated regulation sets the legal duties. Start by deciding whether the service is qualified or non-qualified: Article 19a governs non-qualified providers, Articles 20 and 24 add audit, security, incident, record, and termination duties for qualified providers, and service-specific standards may add further controls.
Side-by-side comparison
ETSI EN 319 401 vs eIDAS: what changes operationally?
Use the current EN 319 401 Annex B to locate controls, then use the consolidated regulation to determine the legal duty, provider category, deadline, and supervisory route.
A general TSP policy baseline for operation and management practices, including risk, security policy, personnel, incident handling, continuity, records, termination, and suppliers.
Second framework
Current eIDAS duties
Legal duties under the consolidated regulation: Article 19a for non-qualified providers and Articles 20 and 24 for qualified providers, plus service-specific provisions.
ETSI EN 319 401 vs eIDAS: what changes operationally?
EN 319 401 covers general policy requirements for Trust Service Providers, independent of trust service type, and does not define every service-specific assessment requirement.
Define the trust service and its qualified or non-qualified status first. Then identify the legal provision, EN 319 401 control, service-specific standard, owner, and evidence.
EN 319 401 assigns work to the TSP and its management, including approval of risk assessment, information security policy, role allocation, personnel competence, and supplier control.
Article 19a assigns duties to non-qualified providers. Articles 20 and 24 assign audit, notification, security, staffing, record, and termination duties to qualified providers, with supervisory bodies and CABs performing separate roles.
Assign an operational control owner, a legal or supervisory-process owner, and an evidence owner. One artifact may support several duties, but the responsibilities remain distinct.
EN 319 401 triggers operational review when risk assessments, information security policy, assets, suppliers, incidents, continuity plans, or service termination facts change.
Current triggers include a significant security breach or service disruption, a planned change to a qualified service, an intention to cease it, the recurring qualified-provider audit, and the start of a qualified service.
Keep a trigger register that distinguishes internal control review, Article 19a or Article 24.2(fb) incident reporting, one-month change notice, three-month cessation notice, and the Article 20 audit cycle.
Current requires non-qualified providers to manage specified risk areas and report significant incidents. Qualified providers also face recurring audits and Article 24 duties covering notices, staff, financial resources or insurance, terms, trustworthy systems, risk measures, incidents, records, and termination.
EN 319 401 evidence should include the risk assessment, residual-risk approval, Trust Service Practice statement, terms and conditions, security policy, asset inventory, monitoring logs, incident records, continuity tests, and supplier agreements.
The legal file should show the applicable Article 19a or Article 24 incident path, Article 20 audit reports for qualified providers, advance change or cessation notices, pre-contract terms, staff competence, risk measures, retained records, and the termination plan.
Label each artifact by source and status: EN 319 401 control, current duty, service-specific requirement, CAB assessment evidence, or supervisory submission.
EN 319 401 uses planned review cycles and event-driven reviews, including regular risk assessment review, planned information security policy review, incident procedure testing, continuity plan testing, and supplier monitoring.
Article 19a requires a non-qualified provider to report a qualifying incident without undue delay and no later than 24 hours after awareness. Article 24.2(fb) sets a 24-hour limit from the incident for a qualified provider. Article 24.2(a) requires at least one month's notice before a qualified-service change and at least three months before cessation. Article 20 requires audits at least every 24 months and report submission within three working days of receipt.
Track internal review dates separately from legal notice and audit deadlines. Confirm the incident meets the relevant significant-impact test before applying the 24-hour reporting path.
EN 319 401 states that it does not specify how requirements are assessed by an independent party and points to EN 319 403-1 for conformity assessment bodies.
Under , supervisory bodies receive specified notices and conformity assessment reports. CABs audit qualified providers, while the supervisory body verifies compliance and grants or withdraws qualified status through the regulation's process.
Use EN 319 401 to build operational evidence. Use and the applicable assessment scheme to identify the CAB, supervisory body, filing route, timing, and legal effect.
Annex B supports control mapping only for the entries it contains. Current duties outside those entries still need direct legal analysis and may need service-specific or assessment evidence.
Reuse evidence with a bridge note naming the EN 319 401 requirement, current paragraph, provider category, service boundary, artifact, owner, and remaining gap.
Use EN 319 401 as the control baseline when the task is to operate and evidence a TSP management, security, incident, continuity, record, or supplier control.
Use when the decision concerns a legal duty, provider category, deadline, supervisory notification, conformity assessment, qualified status, or legal effect.
EN 319 401 covers general policy requirements for Trust Service Providers, independent of trust service type, and does not define every service-specific assessment requirement.
Define the trust service and its qualified or non-qualified status first. Then identify the legal provision, EN 319 401 control, service-specific standard, owner, and evidence.
EN 319 401 assigns work to the TSP and its management, including approval of risk assessment, information security policy, role allocation, personnel competence, and supplier control.
Article 19a assigns duties to non-qualified providers. Articles 20 and 24 assign audit, notification, security, staffing, record, and termination duties to qualified providers, with supervisory bodies and CABs performing separate roles.
Assign an operational control owner, a legal or supervisory-process owner, and an evidence owner. One artifact may support several duties, but the responsibilities remain distinct.
EN 319 401 triggers operational review when risk assessments, information security policy, assets, suppliers, incidents, continuity plans, or service termination facts change.
Current triggers include a significant security breach or service disruption, a planned change to a qualified service, an intention to cease it, the recurring qualified-provider audit, and the start of a qualified service.
Keep a trigger register that distinguishes internal control review, Article 19a or Article 24.2(fb) incident reporting, one-month change notice, three-month cessation notice, and the Article 20 audit cycle.
Current requires non-qualified providers to manage specified risk areas and report significant incidents. Qualified providers also face recurring audits and Article 24 duties covering notices, staff, financial resources or insurance, terms, trustworthy systems, risk measures, incidents, records, and termination.
EN 319 401 evidence should include the risk assessment, residual-risk approval, Trust Service Practice statement, terms and conditions, security policy, asset inventory, monitoring logs, incident records, continuity tests, and supplier agreements.
The legal file should show the applicable Article 19a or Article 24 incident path, Article 20 audit reports for qualified providers, advance change or cessation notices, pre-contract terms, staff competence, risk measures, retained records, and the termination plan.
Label each artifact by source and status: EN 319 401 control, current duty, service-specific requirement, CAB assessment evidence, or supervisory submission.
EN 319 401 uses planned review cycles and event-driven reviews, including regular risk assessment review, planned information security policy review, incident procedure testing, continuity plan testing, and supplier monitoring.
Article 19a requires a non-qualified provider to report a qualifying incident without undue delay and no later than 24 hours after awareness. Article 24.2(fb) sets a 24-hour limit from the incident for a qualified provider. Article 24.2(a) requires at least one month's notice before a qualified-service change and at least three months before cessation. Article 20 requires audits at least every 24 months and report submission within three working days of receipt.
Track internal review dates separately from legal notice and audit deadlines. Confirm the incident meets the relevant significant-impact test before applying the 24-hour reporting path.
EN 319 401 states that it does not specify how requirements are assessed by an independent party and points to EN 319 403-1 for conformity assessment bodies.
Under , supervisory bodies receive specified notices and conformity assessment reports. CABs audit qualified providers, while the supervisory body verifies compliance and grants or withdraws qualified status through the regulation's process.
Use EN 319 401 to build operational evidence. Use and the applicable assessment scheme to identify the CAB, supervisory body, filing route, timing, and legal effect.
Annex B supports control mapping only for the entries it contains. Current duties outside those entries still need direct legal analysis and may need service-specific or assessment evidence.
Reuse evidence with a bridge note naming the EN 319 401 requirement, current paragraph, provider category, service boundary, artifact, owner, and remaining gap.
Use EN 319 401 as the control baseline when the task is to operate and evidence a TSP management, security, incident, continuity, record, or supplier control.
Use when the decision concerns a legal duty, provider category, deadline, supervisory notification, conformity assessment, qualified status, or legal effect.
Use EN 319 401 when the work is a general TSP policy, risk, security, incident, continuity, record, termination, or supplier control.
Use Annex B to find candidate controls, not to identify the complete legal checklist.
Use Article 19a for current non-qualified-provider risk and incident duties; use Articles 20 and 24 for qualified-provider audits and operating duties.
Use the relevant service-specific ETSI standard and assessment scheme for certificate, validation, preservation, delivery, or other service-specific claims.
When should teams compare ETSI EN 319 401 with eIDAS?
Compare them when a trust service provider needs to show how operational controls support a legal trust-service duty. EN 319 401 V3.2.1 covers the provider's general policy, risk, security, incident, continuity, record, termination, and supply-chain controls. determines which legal duties apply to qualified and non-qualified services.
Do not treat Annex B as a complete statement of . It is informative and selective. Check the consolidated regulation, the service type, the provider's qualified status, national supervisory requirements, and the relevant service-specific standard before making a compliance or qualified-status claim.
The jurisdiction also differs. EN 319 401 can be selected as a standards baseline outside an EU legal claim. controls when the service, provider, transaction, supervision, recognition route, or qualified-status claim falls within that EU legal framework. Record the establishment and service facts that connect the provider to eIDAS instead of applying the regulation merely because an ETSI standard is used.
For a non-qualified service, map EN 319 401 controls to Article 19a risk-management and significant-incident duties.
For a qualified service, also check Article 20's audit and reporting cycle and every applicable Article 24 duty, including the one-month change notice, three-month cessation notice, and 24-hour incident deadline.
Keep the provision, EN 319 401 requirement, service-specific requirement, responsible owner, and evidence artifact in separate fields.
If the provider status, service type, jurisdictional connection, or trusted-list evidence is unresolved, record an open legal-scope question rather than treating the Annex B mapping as the answer.
EN 319 401 specifies baseline policy requirements for the operation and management practices of TSPs, independent of the type of trust service. It covers risk assessment, Trust Service Practice statements, terms and conditions, information security policy, internal organization, personnel, assets, access control, incident management, continuity, termination, and supplier relationships.
That makes it useful for building an evidence pack, but it does not by itself define every legal result under or every assessment method for a particular qualified trust service.
Start the EN 319 401 side with a current risk assessment approved by TSP management and linked to selected treatment measures.
Keep the Trust Service Practice statement, terms and conditions, information security policy, and asset inventory under review after significant changes.
Map each operational control to evidence: policies, role descriptions, training records, monitoring logs, incident records, continuity tests, supplier agreements, and termination records.
Annex B of EN 319 401 V3.2.1 maps its clauses 5, 6, and 7 to security requirements for trust service providers and maps selected Article 24.2 duties for qualified trust service providers. It is useful for locating controls, but it does not reproduce the full legal framework or decide whether a provider or service has qualified status.
The consolidated regulation separates the paths. Article 19a applies risk-management and significant-incident duties to non-qualified providers. Qualified providers are audited at least every 24 months under Article 20, must notify the supervisory body no later than one month before a planned audit, and must submit the resulting report within three working days of receipt. Article 24 adds qualified-provider duties, including advance notice of changes or cessation, competent staff, financial resources or insurance, terms, trustworthy systems, risk measures, incident notice, records, and a termination plan.
A provider starting a qualified trust service follows Article 21, not Annex B alone. It submits its intention and a conformity assessment report to the supervisory body. The service may start only after qualified status has been granted and indicated in the trusted list. The regulation sets a three-month period for the supervisory verification after notification, with notice of reasons and a new period if verification is not complete.
Use Annex B to locate candidate EN 319 401 controls, then verify the exact current paragraph.
For non-qualified services, record the Article 19a risk and incident path separately from qualified-provider obligations.
For qualified services, add Article 20 audit evidence and every applicable Article 24 duty; do not limit the legal checklist to Annex B.
For EU qualified certificates or another specific trust service, add the applicable service-specific ETSI standard.
For a new qualified service, retain the notification, conformity assessment report, supervisory correspondence, decision, and trusted-list entry as separate evidence.
Build the comparison as an evidence matrix, not as a merged checklist. Each row should identify the provision, the EN 319 401 clause or requirement family, the service boundary, the owner, and the artifact that proves the control is operated.
Use concrete evidence: risk assessment outputs, management approval of residual risk, Trust Service Practice statements, terms and conditions, information security policy, personnel competence records, incident logs, post-incident reviews, continuity plans, backup records, supplier registers, and termination notices.
Give every row one of five statuses: both sources apply to the same artifact, only EN 319 401 applies, only applies, a service-specific source is still needed, or applicability is unresolved. This keeps evidence reuse visible without implying that a standards control has the same legal effect as the regulation.
Record whether the evidence supports EN 319 401 only, an Annex B mapping, or a service-specific qualified-trust-service claim.
Keep current incident evidence tied to the applicable Article 19a or Article 24.2(fb) trigger, recipients, timing, response, notification, review, and continuity interfaces.
Keep Article 24.2 evidence tied to the exact duty, such as terms before contract, staff competence, risk measures, record retention, or termination planning.
Implementation checklist for ETSI EN 319 401 vs eIDAS
Review this checklist before a customer response, conformity-assessment preparation, qualified-service change, or internal audit. Every item should produce a visible artifact rather than a general claim of compliance.
Confirm the trust service type and whether the claim is non-qualified, qualified, certificate-specific, or another service-specific ETSI profile.
Confirm the provider's EU legal connection and, for a qualified claim, the current trusted-list evidence for the provider and service.
Classify the service as qualified or non-qualified and map the applicable Article 19a, Article 20, and Article 24 duties before attaching EN 319 401 controls.
Attach EN 319 401 clauses to owners for risk assessment, policy maintenance, staff competence, incident response, continuity, records, and supplier management.
Name any service-specific ETSI standard needed before claiming qualified certificate or other qualified trust service coverage.
Record the one-month change notice, three-month cessation notice, applicable 24-hour incident deadline, and qualified-provider audit required at least every 24 months where they apply.
For a planned qualified-provider audit, record the one-month advance notice to the supervisory body and the three-working-day report-submission deadline separately.
Document unresolved questions instead of filling them with generic compliance language.
Teams often read Annex B as proof of full compliance. It is only an informative map. EN 319 401 can support an eIDAS evidence file when the service boundary and control evidence match, but the regulation, supervisory process, conformity assessment, and service-specific requirements remain separate.
Do not claim full compliance from EN 319 401 alone.
Do not apply qualified certificate conclusions without a service-specific source such as EN 319 411-2.
Do not use the superseded Article 19 label as the current incident checklist; use Article 19a for non-qualified providers and Article 24.2(fb) for qualified providers.
Do not cite evidence records or local reference files; source URLs on the public page must be external HTTPS links with the Sorena reference parameter.