| Scope and covered activity | EN 319 401 applies to general policy requirements for TSPs and is independent of the type of TSP; it defines requirements on operation and management practices. | EN 319 403-1 applies ISO/IEC 17065 to CABs that assess and certify a TSP and its trust services against defined criteria. It also covers separate assessment of trust-service components. | The scope memo should name the TSP, trust service, sites, subcontractors, components, assessment criteria, and any existing component assessment. |
|---|
| Who owns the work | The TSP owns EN 319 401 implementation through management approval, policy ownership, trusted roles, personnel controls, operational controls, incident handling, continuity, termination planning, and supplier oversight. | The CAB owns application review, auditor competence, audit planning and performance, findings, review, and the certification decision. The applicant TSP must supply information, access, evidence, and corrective actions required by the process. | Assign TSP evidence and corrective-action owners, then keep the CAB's audit, review, and decision responsibilities separate in the assessment plan. |
|---|
| Trigger or threshold | EN 319 401 work starts when a provider is defining, operating, changing, assessing, or evidencing a trust service policy and the related TSP operation. | EN 319 403-1 applies when a CAB assesses a TSP or trust-service component against stated criteria. Surveillance, changes affecting conformity, complaints, or scheme and legal requirements can also trigger assessment activity. | Review scope when the service, criteria, sites, subcontractors, components, systems, policies, or prior findings change. |
|---|
| Core obligations | Convert EN 319 401 into TSP controls for risk assessment, risk treatment, practice statements, terms and conditions, information security policy, personnel, assets, access control, cryptographic controls, physical security, operational security, network security, incidents, continuity, termination, compliance, and supply chain. | EN 319 403-1 requires a competent and impartial CAB process covering application review, scope and method, audit time, sites, two-stage audit work, reports, corrective actions, review, decision, certification documents, surveillance, reassessment, records, complaints, and appeals. | Map each assessment criterion to EN 319 401 controls and TSP evidence, but track CAB process requirements in their own column. |
|---|
| Evidence and records | Evidence should include the risk assessment, risk treatment records, practice statement, terms and conditions, information security policy, asset inventory, trusted-role appointments, access records, monitoring and incident records, continuity and crisis-management tests, termination plan, and supplier agreements. | Before the on-site audit, the CAB requires service and activity information, relevant TSP and subcontractor locations, and policies, practices, infrastructure plans, manuals, and instructions. Audit access extends to relevant sites, records, personnel, and subcontractor areas. | Maintain one matrix with the criterion, EN 319 401 requirement, control owner, evidence location, site or component, confidentiality restriction, auditor finding, and corrective-action status. |
|---|
| Timing and cadence | EN 319 401 requires recurring review patterns, including regular risk-assessment review and review of the information security policy and asset inventory at planned intervals or when significant changes occur. | EN 319 403-1 sets no more than two years between full reassessment audits unless applicable legislation or the commercial scheme requires otherwise. Surveillance may occur under the surveillance programme or when required by an entitled party. | Schedule EN 319 401 evidence maintenance continuously and record the separate CAB surveillance and full-reassessment dates, including any shorter legal or scheme deadline. |
|---|
| Enforcement and supervisory context | EN 319 401 supplies control requirements. Any legal or scheme consequence depends on the regulation, contract, assessment criteria, and service-specific standard that calls for those controls. | EN 319 403-1 governs the CAB assessment and certification process; it does not by itself grant qualified status under eIDAS. For qualified services, eIDAS separately governs CAB accreditation, reports, supervisory verification, and trusted-list status. | Record the criteria and legal route separately from the standard: CAB and accreditation details, audit scope, report, certification decision, supervisory submission, and trusted-list status where applicable. |
|---|
| Overlap and reuse | EN 319 401 evidence can be reused when the trust service boundary, version, policy, systems, suppliers, and assessment period match the claim being made. | EN 319 403-1 permits component assessment and conditional multi-site sampling, but reuse depends on the assessment scope, criteria, common control, records, sites, and CAB judgment. Prior evidence does not remove the CAB's responsibility for its decision. | Reuse evidence only with a visible boundary statement covering the service, component, criteria, sites, systems, period, standard version, evidence owner, and prior assessment status. |
|---|
| Practical decision rule | If the task is to design, operate, document, or maintain a trust service provider control, start with EN 319 401. | If the task concerns CAB competence, audit scope, evidence access, site sampling, audit stages, findings, corrective action, review, or certification, use EN 319 403-1. | Produce three linked records: the TSP control map, the agreed assessment scope and criteria, and the CAB findings and decision trail. |
|---|