Artifact GuideGLOBALETSI EN 319 401

ETSI EN 319 401 vs eIDAS

A comparison of ETSI EN 319 401 V3.2.1 operational controls with current eIDAS duties for trust service providers.

Use Annex B as a control map, then use the consolidated regulation for legal duties, notification clocks, qualified status, and supervision.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
6

Structured answer sets in this page tree.

Primary sources
20

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

ETSI EN 319 401 is an operational control standard, not a replacement for . The current ETSI edition is V3.2.1 (2026-01). Its informative Annex B maps selected controls to eIDAS, while the consolidated regulation sets the legal duties. Start by deciding whether the service is qualified or non-qualified: Article 19a governs non-qualified providers, Articles 20 and 24 add audit, security, incident, record, and termination duties for qualified providers, and service-specific standards may add further controls.

Side-by-side comparison

ETSI EN 319 401 vs eIDAS: what changes operationally?

Use the current EN 319 401 Annex B to locate controls, then use the consolidated regulation to determine the legal duty, provider category, deadline, and supervisory route.

Review all sources
First framework
ETSI EN 319 401

A general TSP policy baseline for operation and management practices, including risk, security policy, personnel, incident handling, continuity, records, termination, and suppliers.

Second framework
Current eIDAS duties

Legal duties under the consolidated regulation: Article 19a for non-qualified providers and Articles 20 and 24 for qualified providers, plus service-specific provisions.

Comparison row 1

Scope and covered activity

ETSI EN 319 401

EN 319 401 covers general policy requirements for Trust Service Providers, independent of trust service type, and does not define every service-specific assessment requirement.

Current eIDAS duties

applies legal duties according to the provider and service status. Annex B is a selective mapping aid, not the full regulation.

Operational implication

Define the trust service and its qualified or non-qualified status first. Then identify the legal provision, EN 319 401 control, service-specific standard, owner, and evidence.

Comparison row 2

Who must act

ETSI EN 319 401

EN 319 401 assigns work to the TSP and its management, including approval of risk assessment, information security policy, role allocation, personnel competence, and supplier control.

Current eIDAS duties

Article 19a assigns duties to non-qualified providers. Articles 20 and 24 assign audit, notification, security, staffing, record, and termination duties to qualified providers, with supervisory bodies and CABs performing separate roles.

Operational implication

Assign an operational control owner, a legal or supervisory-process owner, and an evidence owner. One artifact may support several duties, but the responsibilities remain distinct.

Comparison row 3

Trigger or threshold

ETSI EN 319 401

EN 319 401 triggers operational review when risk assessments, information security policy, assets, suppliers, incidents, continuity plans, or service termination facts change.

Current eIDAS duties

Current triggers include a significant security breach or service disruption, a planned change to a qualified service, an intention to cease it, the recurring qualified-provider audit, and the start of a qualified service.

Operational implication

Keep a trigger register that distinguishes internal control review, Article 19a or Article 24.2(fb) incident reporting, one-month change notice, three-month cessation notice, and the Article 20 audit cycle.

Comparison row 4

Core obligations

ETSI EN 319 401

EN 319 401 requires the TSP to assess risks, select treatment measures, document policies and procedures, manage personnel and assets, operate security controls, handle incidents, maintain continuity, keep records, and manage suppliers.

Current eIDAS duties

Current requires non-qualified providers to manage specified risk areas and report significant incidents. Qualified providers also face recurring audits and Article 24 duties covering notices, staff, financial resources or insurance, terms, trustworthy systems, risk measures, incidents, records, and termination.

Operational implication

Build a crosswalk row only when the EN 319 401 control and current paragraph apply to the same provider, service boundary, and evidence artifact.

Comparison row 5

Evidence and records

ETSI EN 319 401

EN 319 401 evidence should include the risk assessment, residual-risk approval, Trust Service Practice statement, terms and conditions, security policy, asset inventory, monitoring logs, incident records, continuity tests, and supplier agreements.

Current eIDAS duties

The legal file should show the applicable Article 19a or Article 24 incident path, Article 20 audit reports for qualified providers, advance change or cessation notices, pre-contract terms, staff competence, risk measures, retained records, and the termination plan.

Operational implication

Label each artifact by source and status: EN 319 401 control, current duty, service-specific requirement, CAB assessment evidence, or supervisory submission.

Comparison row 6

Timing and cadence

ETSI EN 319 401

EN 319 401 uses planned review cycles and event-driven reviews, including regular risk assessment review, planned information security policy review, incident procedure testing, continuity plan testing, and supplier monitoring.

Current eIDAS duties

Article 19a requires a non-qualified provider to report a qualifying incident without undue delay and no later than 24 hours after awareness. Article 24.2(fb) sets a 24-hour limit from the incident for a qualified provider. Article 24.2(a) requires at least one month's notice before a qualified-service change and at least three months before cessation. Article 20 requires audits at least every 24 months and report submission within three working days of receipt.

Operational implication

Track internal review dates separately from legal notice and audit deadlines. Confirm the incident meets the relevant significant-impact test before applying the 24-hour reporting path.

Comparison row 7

Enforcement or assurance route

ETSI EN 319 401

EN 319 401 states that it does not specify how requirements are assessed by an independent party and points to EN 319 403-1 for conformity assessment bodies.

Current eIDAS duties

Under , supervisory bodies receive specified notices and conformity assessment reports. CABs audit qualified providers, while the supervisory body verifies compliance and grants or withdraws qualified status through the regulation's process.

Operational implication

Use EN 319 401 to build operational evidence. Use and the applicable assessment scheme to identify the CAB, supervisory body, filing route, timing, and legal effect.

Comparison row 8

Overlap and reuse

ETSI EN 319 401

EN 319 401 evidence can be reused where it proves the same TSP operation, control, and review result for the same service boundary.

Current eIDAS duties

Annex B supports control mapping only for the entries it contains. Current duties outside those entries still need direct legal analysis and may need service-specific or assessment evidence.

Operational implication

Reuse evidence with a bridge note naming the EN 319 401 requirement, current paragraph, provider category, service boundary, artifact, owner, and remaining gap.

Comparison row 9

Practical decision rule

ETSI EN 319 401

Use EN 319 401 as the control baseline when the task is to operate and evidence a TSP management, security, incident, continuity, record, or supplier control.

Current eIDAS duties

Use when the decision concerns a legal duty, provider category, deadline, supervisory notification, conformity assessment, qualified status, or legal effect.

Operational implication

The crosswalk is useful for implementation evidence, but it is not a legal conclusion that EN 319 401 alone satisfies .

Practical decision rule

How to choose the controlling source

  • Use EN 319 401 when the work is a general TSP policy, risk, security, incident, continuity, record, termination, or supplier control.
  • Use Annex B to find candidate controls, not to identify the complete legal checklist.
  • Use Article 19a for current non-qualified-provider risk and incident duties; use Articles 20 and 24 for qualified-provider audits and operating duties.
  • Use the relevant service-specific ETSI standard and assessment scheme for certificate, validation, preservation, delivery, or other service-specific claims.
Section 1

When should teams compare ETSI EN 319 401 with eIDAS?

Compare them when a trust service provider needs to show how operational controls support a legal trust-service duty. EN 319 401 V3.2.1 covers the provider's general policy, risk, security, incident, continuity, record, termination, and supply-chain controls. determines which legal duties apply to qualified and non-qualified services.

Do not treat Annex B as a complete statement of . It is informative and selective. Check the consolidated regulation, the service type, the provider's qualified status, national supervisory requirements, and the relevant service-specific standard before making a compliance or qualified-status claim.

The jurisdiction also differs. EN 319 401 can be selected as a standards baseline outside an EU legal claim. controls when the service, provider, transaction, supervision, recognition route, or qualified-status claim falls within that EU legal framework. Record the establishment and service facts that connect the provider to eIDAS instead of applying the regulation merely because an ETSI standard is used.

  • For a non-qualified service, map EN 319 401 controls to Article 19a risk-management and significant-incident duties.
  • For a qualified service, also check Article 20's audit and reporting cycle and every applicable Article 24 duty, including the one-month change notice, three-month cessation notice, and 24-hour incident deadline.
  • Keep the provision, EN 319 401 requirement, service-specific requirement, responsible owner, and evidence artifact in separate fields.
  • If the provider status, service type, jurisdictional connection, or trusted-list evidence is unresolved, record an open legal-scope question rather than treating the Annex B mapping as the answer.
Section 2

What ETSI EN 319 401 contributes

EN 319 401 specifies baseline policy requirements for the operation and management practices of TSPs, independent of the type of trust service. It covers risk assessment, Trust Service Practice statements, terms and conditions, information security policy, internal organization, personnel, assets, access control, incident management, continuity, termination, and supplier relationships.

That makes it useful for building an evidence pack, but it does not by itself define every legal result under or every assessment method for a particular qualified trust service.

  • Start the EN 319 401 side with a current risk assessment approved by TSP management and linked to selected treatment measures.
  • Keep the Trust Service Practice statement, terms and conditions, information security policy, and asset inventory under review after significant changes.
  • Map each operational control to evidence: policies, role descriptions, training records, monitoring logs, incident records, continuity tests, supplier agreements, and termination records.
Section 3

How the current Annex B mapping fits eIDAS

Annex B of EN 319 401 V3.2.1 maps its clauses 5, 6, and 7 to security requirements for trust service providers and maps selected Article 24.2 duties for qualified trust service providers. It is useful for locating controls, but it does not reproduce the full legal framework or decide whether a provider or service has qualified status.

The consolidated regulation separates the paths. Article 19a applies risk-management and significant-incident duties to non-qualified providers. Qualified providers are audited at least every 24 months under Article 20, must notify the supervisory body no later than one month before a planned audit, and must submit the resulting report within three working days of receipt. Article 24 adds qualified-provider duties, including advance notice of changes or cessation, competent staff, financial resources or insurance, terms, trustworthy systems, risk measures, incident notice, records, and a termination plan.

A provider starting a qualified trust service follows Article 21, not Annex B alone. It submits its intention and a conformity assessment report to the supervisory body. The service may start only after qualified status has been granted and indicated in the trusted list. The regulation sets a three-month period for the supervisory verification after notification, with notice of reasons and a new period if verification is not complete.

  • Use Annex B to locate candidate EN 319 401 controls, then verify the exact current paragraph.
  • For non-qualified services, record the Article 19a risk and incident path separately from qualified-provider obligations.
  • For qualified services, add Article 20 audit evidence and every applicable Article 24 duty; do not limit the legal checklist to Annex B.
  • For EU qualified certificates or another specific trust service, add the applicable service-specific ETSI standard.
  • For a new qualified service, retain the notification, conformity assessment report, supervisory correspondence, decision, and trusted-list entry as separate evidence.
Section 4

Evidence model for the crosswalk

Build the comparison as an evidence matrix, not as a merged checklist. Each row should identify the provision, the EN 319 401 clause or requirement family, the service boundary, the owner, and the artifact that proves the control is operated.

Use concrete evidence: risk assessment outputs, management approval of residual risk, Trust Service Practice statements, terms and conditions, information security policy, personnel competence records, incident logs, post-incident reviews, continuity plans, backup records, supplier registers, and termination notices.

Give every row one of five statuses: both sources apply to the same artifact, only EN 319 401 applies, only applies, a service-specific source is still needed, or applicability is unresolved. This keeps evidence reuse visible without implying that a standards control has the same legal effect as the regulation.

  • Record whether the evidence supports EN 319 401 only, an Annex B mapping, or a service-specific qualified-trust-service claim.
  • Keep current incident evidence tied to the applicable Article 19a or Article 24.2(fb) trigger, recipients, timing, response, notification, review, and continuity interfaces.
  • Keep Article 24.2 evidence tied to the exact duty, such as terms before contract, staff competence, risk measures, record retention, or termination planning.
Section 5

Implementation checklist for ETSI EN 319 401 vs eIDAS

Review this checklist before a customer response, conformity-assessment preparation, qualified-service change, or internal audit. Every item should produce a visible artifact rather than a general claim of compliance.

  • Confirm the trust service type and whether the claim is non-qualified, qualified, certificate-specific, or another service-specific ETSI profile.
  • Confirm the provider's EU legal connection and, for a qualified claim, the current trusted-list evidence for the provider and service.
  • Classify the service as qualified or non-qualified and map the applicable Article 19a, Article 20, and Article 24 duties before attaching EN 319 401 controls.
  • Attach EN 319 401 clauses to owners for risk assessment, policy maintenance, staff competence, incident response, continuity, records, and supplier management.
  • Name any service-specific ETSI standard needed before claiming qualified certificate or other qualified trust service coverage.
  • Record the one-month change notice, three-month cessation notice, applicable 24-hour incident deadline, and qualified-provider audit required at least every 24 months where they apply.
  • For a planned qualified-provider audit, record the one-month advance notice to the supervisory body and the three-working-day report-submission deadline separately.
  • Document unresolved questions instead of filling them with generic compliance language.
Section 6

Common mistakes in this comparison

Teams often read Annex B as proof of full compliance. It is only an informative map. EN 319 401 can support an eIDAS evidence file when the service boundary and control evidence match, but the regulation, supervisory process, conformity assessment, and service-specific requirements remain separate.

  • Do not claim full compliance from EN 319 401 alone.
  • Do not apply qualified certificate conclusions without a service-specific source such as EN 319 411-2.
  • Do not use the superseded Article 19 label as the current incident checklist; use Article 19a for non-qualified providers and Article 24.2(fb) for qualified providers.
  • Do not cite evidence records or local reference files; source URLs on the public page must be external HTTPS links with the Sorena reference parameter.
Primary sources

References and citations

Related guides

Explore more topics

CA and RA responsibilities under ETSI EN 319 401
How ETSI EN 319 401 frames CA and RA responsibility: TSP practice statements, management approval, role segregation, subcontractor control, and evidence boundaries.
eIDAS Articles 19 and 24: current ETSI mapping
Understand why old EN 319 401 editions mapped eIDAS Article 19, what replaced it, and how V3.2.1 maps current Article 24 duties.
ETSI EN 319 401 Audit and Conformity Assessment Evidence
How to prepare ETSI EN 319 401 evidence for audit and conformity assessment without overstating what the standard itself assesses.
ETSI EN 319 401 Audit Evidence Pack
Build an ETSI EN 319 401 audit evidence pack around records, logs, policies, risk assessment, incident handling, continuity, and supplier evidence.
ETSI EN 319 401 Audit Evidence Pack Workflow
Build an ETSI EN 319 401 audit evidence pack for trust service providers: risk assessment, practice statement, policies, records, logs, continuity, and supplier evidence.
ETSI EN 319 401 compliance duties for TSPs
ETSI EN 319 401 compliance guidance for trust service providers covering legal operation, evidence, accessibility, privacy, records, incidents, continuity, and suppliers.
ETSI EN 319 401 conformity assessment bodies: what is covered?
Understand what ETSI EN 319 401 says, and does not say, about conformity assessment bodies, independent assessment, and TSP evidence preparation.
ETSI EN 319 401 FAQ for trust service providers
Plain-language ETSI EN 319 401 answers covering TSP scope, trust service practice statements, risk assessment, incidents, records, continuity, and supplier evidence.
ETSI EN 319 401 Incident and Continuity Workflow
Build an EN 319 401 incident and continuity evidence workflow for TSP monitoring, response, reporting, records, backup recovery, and crisis review.
ETSI EN 319 401 Incident Reporting and Continuity Duties
Practical ETSI EN 319 401 V3.1.1 guidance for trust service incident response, reporting, evidence retention, business continuity, and termination planning.
ETSI EN 319 401 Personnel, Asset, and Access Controls
Clause-focused EN 319 401 V3.1.1 guide to TSP personnel duties, trusted roles, asset inventories, classification, and access-control evidence.
ETSI EN 319 401 policy and security requirements
ETSI EN 319 401 guidance for TSP policy and security requirements covering risk assessment, practice statements, terms, security controls, incidents, and evidence.
ETSI EN 319 401 policy documentation: what is required?
How ETSI EN 319 401 treats practice statements, terms, network and information systems security policy, evidence records, and change review.
ETSI EN 319 401 requirements map
Map ETSI EN 319 401 V3.1.1 requirements for trust service providers across risk assessment, policies, TSP operations, incidents, evidence, continuity, termination, and supply chain controls.
ETSI EN 319 401 Risk Assessment and Treatment
Clause-cited ETSI EN 319 401 V3.1.1 guidance for trust service risk assessment, risk treatment, residual-risk approval, and evidence planning.
ETSI EN 319 401 Subcontractor Controls
Practical EN 319 401 guidance for TSP subcontractor controls: retained responsibility, agreements, SLAs, supplier registers, monitoring, and audit evidence.
ETSI EN 319 401 Subcontractor Evidence Workflow
Build an EN 319 401 subcontractor evidence workflow for TSP supplier agreements, SLAs, audit mechanisms, risk reviews, supplier registers, and archived records.
ETSI EN 319 401 Subcontractor Requirements FAQ
How ETSI EN 319 401 treats subcontractors, outsourcing, supplier agreements, SLAs, monitoring, evidence, and retained TSP responsibility.
ETSI EN 319 401 Trust Service Applicability Workflow
A scoped workflow for deciding when ETSI EN 319 401 applies to a trust service and what TSP policy, risk, terms, operations, and supplier evidence to collect.
ETSI EN 319 401 Trust Service Provider Applicability
Use ETSI EN 319 401 to decide whether a trust service provider activity falls in the standard's type-independent baseline and what service, policy, risk, supplier, and evidence boundaries to document.
ETSI EN 319 401 vs EN 319 403-1: TSP Policy vs CAB Assessment
Compare ETSI EN 319 401 V3.2.1 provider controls with EN 319 403-1 V2.3.1 CAB requirements for audit scope, evidence, sampling, reports, corrective action, and reassessment.
Security Incidents in ETSI EN 319 401
How ETSI EN 319 401 V3.2.1 expects TSPs to detect, classify, respond to, report, document, test, and review security incidents.
Trust service provider scope under ETSI EN 319 401
How to scope ETSI EN 319 401 for a trust service provider: service boundaries, trust service policy, practice statement, terms, risks, and third-party components.