Comparison GuideGLOBALETSI EN 319 401

ETSI EN 319 401 vs EN 319 403-1 TSP policy vs conformity assessment

A practical comparison for teams that need to separate a trust service provider's operating controls from the conformity-assessment context around those controls.

Use EN 319 401 to define what the TSP operates and EN 319 403-1 to understand how a CAB scopes, audits, reports, and decides on conformity.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
6

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use EN 319 401 V3.2.1 to design and operate a trust service provider's controls. Use EN 319 403-1 V2.3.1 to understand the 's competence, impartiality, audit, reporting, corrective-action, review, and certification process. The standards meet at the evidence boundary: the TSP supplies policies, system and site information, records, personnel access, and corrective actions; the CAB defines and performs the assessment against stated criteria. Neither standard alone grants qualified status under eIDAS.

Side-by-side comparison

ETSI EN 319 401 vs ETSI EN 319 403-1: what changes operationally?

This table separates the TSP controls and records governed by EN 319 401 from the CAB competence, audit, reporting, corrective-action, and certification process governed by EN 319 403-1.

Review all sources
First framework
ETSI EN 319 401

General policy requirements for trust service providers, focused on the TSP's operation and management practices across trust service policy, risk, security, incidents, continuity, termination, and suppliers.

Second framework
ETSI EN 319 403-1

Requirements for CABs assessing and certifying TSPs and trust services against defined criteria, including competence, impartiality, audit scope, evidence, reports, corrections, review, and decisions.

Comparison row 1

Scope and covered activity

ETSI EN 319 401

EN 319 401 applies to general policy requirements for TSPs and is independent of the type of TSP; it defines requirements on operation and management practices.

ETSI EN 319 403-1

EN 319 403-1 applies ISO/IEC 17065 to CABs that assess and certify a TSP and its trust services against defined criteria. It also covers separate assessment of trust-service components.

Operational implication

The scope memo should name the TSP, trust service, sites, subcontractors, components, assessment criteria, and any existing component assessment.

Comparison row 2

Who owns the work

ETSI EN 319 401

The TSP owns EN 319 401 implementation through management approval, policy ownership, trusted roles, personnel controls, operational controls, incident handling, continuity, termination planning, and supplier oversight.

ETSI EN 319 403-1

The CAB owns application review, auditor competence, audit planning and performance, findings, review, and the certification decision. The applicant TSP must supply information, access, evidence, and corrective actions required by the process.

Operational implication

Assign TSP evidence and corrective-action owners, then keep the CAB's audit, review, and decision responsibilities separate in the assessment plan.

Comparison row 3

Trigger or threshold

ETSI EN 319 401

EN 319 401 work starts when a provider is defining, operating, changing, assessing, or evidencing a trust service policy and the related TSP operation.

ETSI EN 319 403-1

EN 319 403-1 applies when a CAB assesses a TSP or trust-service component against stated criteria. Surveillance, changes affecting conformity, complaints, or scheme and legal requirements can also trigger assessment activity.

Operational implication

Review scope when the service, criteria, sites, subcontractors, components, systems, policies, or prior findings change.

Comparison row 4

Core obligations

ETSI EN 319 401

Convert EN 319 401 into TSP controls for risk assessment, risk treatment, practice statements, terms and conditions, information security policy, personnel, assets, access control, cryptographic controls, physical security, operational security, network security, incidents, continuity, termination, compliance, and supply chain.

ETSI EN 319 403-1

EN 319 403-1 requires a competent and impartial CAB process covering application review, scope and method, audit time, sites, two-stage audit work, reports, corrective actions, review, decision, certification documents, surveillance, reassessment, records, complaints, and appeals.

Operational implication

Map each assessment criterion to EN 319 401 controls and TSP evidence, but track CAB process requirements in their own column.

Comparison row 5

Evidence and records

ETSI EN 319 401

Evidence should include the risk assessment, risk treatment records, practice statement, terms and conditions, information security policy, asset inventory, trusted-role appointments, access records, monitoring and incident records, continuity and crisis-management tests, termination plan, and supplier agreements.

ETSI EN 319 403-1

Before the on-site audit, the CAB requires service and activity information, relevant TSP and subcontractor locations, and policies, practices, infrastructure plans, manuals, and instructions. Audit access extends to relevant sites, records, personnel, and subcontractor areas.

Operational implication

Maintain one matrix with the criterion, EN 319 401 requirement, control owner, evidence location, site or component, confidentiality restriction, auditor finding, and corrective-action status.

Comparison row 6

Timing and cadence

ETSI EN 319 401

EN 319 401 requires recurring review patterns, including regular risk-assessment review and review of the information security policy and asset inventory at planned intervals or when significant changes occur.

ETSI EN 319 403-1

EN 319 403-1 sets no more than two years between full reassessment audits unless applicable legislation or the commercial scheme requires otherwise. Surveillance may occur under the surveillance programme or when required by an entitled party.

Operational implication

Schedule EN 319 401 evidence maintenance continuously and record the separate CAB surveillance and full-reassessment dates, including any shorter legal or scheme deadline.

Comparison row 7

Enforcement and supervisory context

ETSI EN 319 401

EN 319 401 supplies control requirements. Any legal or scheme consequence depends on the regulation, contract, assessment criteria, and service-specific standard that calls for those controls.

ETSI EN 319 403-1

EN 319 403-1 governs the CAB assessment and certification process; it does not by itself grant qualified status under eIDAS. For qualified services, eIDAS separately governs CAB accreditation, reports, supervisory verification, and trusted-list status.

Operational implication

Record the criteria and legal route separately from the standard: CAB and accreditation details, audit scope, report, certification decision, supervisory submission, and trusted-list status where applicable.

Comparison row 8

Overlap and reuse

ETSI EN 319 401

EN 319 401 evidence can be reused when the trust service boundary, version, policy, systems, suppliers, and assessment period match the claim being made.

ETSI EN 319 403-1

EN 319 403-1 permits component assessment and conditional multi-site sampling, but reuse depends on the assessment scope, criteria, common control, records, sites, and CAB judgment. Prior evidence does not remove the CAB's responsibility for its decision.

Operational implication

Reuse evidence only with a visible boundary statement covering the service, component, criteria, sites, systems, period, standard version, evidence owner, and prior assessment status.

Comparison row 9

Practical decision rule

ETSI EN 319 401

If the task is to design, operate, document, or maintain a trust service provider control, start with EN 319 401.

ETSI EN 319 403-1

If the task concerns CAB competence, audit scope, evidence access, site sampling, audit stages, findings, corrective action, review, or certification, use EN 319 403-1.

Operational implication

Produce three linked records: the TSP control map, the agreed assessment scope and criteria, and the CAB findings and decision trail.

Practical decision rule

How should teams decide whether a task belongs in EN 319 401 or EN 319 403-1?

  • Use EN 319 401 when designing, implementing, documenting, or maintaining trust service policies, practices, controls, incident procedures, or security evidence.
  • Use EN 319 403-1 when selecting or evaluating a CAB, agreeing assessment criteria and scope, preparing Stage 1 and Stage 2 evidence, handling findings, or interpreting the certification process.
  • Keep TSP controls, audit evidence, CAB findings, corrective actions, review, and certification decisions distinct but linked by stable requirement and evidence identifiers.
  • Use eIDAS and the applicable assessment scheme in addition to these standards when the question concerns qualified status, supervisory submissions, trusted lists, or a legal audit deadline.
Section 1

Why compare ETSI EN 319 401 with ETSI EN 319 403-1?

ETSI EN 319 401 V3.2.1 specifies general policy requirements for trust service providers, independent of TSP type. It covers the provider's risk assessment, policy documents, information security policy, management and operation, incident handling, continuity, termination, compliance, and supply chain.

ETSI EN 319 403-1 V2.3.1 applies ISO/IEC 17065 to CABs assessing and certifying TSPs and their trust services against defined criteria. It covers CAB competence and impartiality, application review, audit scope and method, site sampling, two-stage audit work, reports, corrective actions, review, certification decisions, surveillance, reassessment, records, complaints, and appeals.

The editions also have different timelines. EN 319 403-1 V2.3.1 dates from June 2020. EN 319 401 V3.2.1 was adopted on 5 January 2026; its listed deadline for national publication or endorsement, and for withdrawal of conflicting national standards, is 31 October 2026. Record the edition used in every control map, application, report, and transition plan.

  • Use EN 319 401 to build or review TSP policy, practice, risk, security, operational, incident, continuity, and supplier evidence.
  • Use EN 319 403-1 to prepare the application, scope statement, site and subcontractor inventory, audit access, evidence index, corrective-action plan, and certification records.
  • State the assessment criteria and trust-service boundary explicitly. A CAB does not assess EN 319 401 by implication; the agreed criteria determine the audit.
Section 2

What ETSI EN 319 401 controls before assessment starts

Start the EN 319 401 side with the trust service boundary. The standard defines policy requirements on the operation and management practices of TSPs and says the requirements are independent of the type of TSP.

The implementation file should name the trust service policy, TSP practice statement, terms and conditions, information security policy, risk assessment, management approvals, trusted roles, asset inventory, access controls, incident procedures, continuity plans, termination plan, and supplier controls that support the service.

  • Document the risk assessment and management approval of residual risk before treating a control set as complete.
  • Keep the TSP practice statement and terms and conditions aligned with the trust service policy being offered.
  • Tie evidence to named TSP systems, facilities, personnel roles, suppliers, and service components rather than broad claims of compliance.
Section 3

What EN 319 403-1 requires from the assessment workflow

Before the on-site work, the CAB requires general information about the trust service, the relevant TSP and subcontractor sites, and the policies, practices, infrastructure plans, manuals, and operating instructions needed for the assessment. The CAB and TSP agree when and where the audit takes place, but the CAB remains responsible for the audit and certification process.

The audit has two stages. Stage 1 reviews the TSP and service documentation and helps plan Stage 2. Stage 2 includes on-site work, completes the assessment against the stated criteria, and leads to an audit report and, where needed, a TSP corrective-action plan reviewed by the CAB. Multi-site sampling is conditional; the CAB must assess whether common security-policy control and management review make sampling appropriate.

  • Application and scope: name the applicant, trust services, assessment criteria, locations, subcontractors, service components, and any existing component assessment.
  • Audit access: arrange access to relevant documentation, sites, subcontractor areas, records, internal audit reports, independent security reviews, and personnel.
  • Report and correction: trace each finding to the applicable criterion, its severity, the affected service or site, the corrective action, and the CAB's verification.
  • Certification: keep the audit team's findings separate from the independent review and certification decision required by the CAB process.
Section 4

Evidence that usually belongs on the EN 319 401 side

EN 319 401 evidence should show that the TSP has translated policy requirements into working operations. The source material supports evidence around risk assessment, risk treatment, trust service practice statements, terms and conditions, information security policy, trusted roles, access control, physical and environmental security, operational security, network security, vulnerability and incident management, business continuity, termination, compliance, and supply chain.

Do not use public labels such as assessed, certified, qualified, or conformant unless the evidence identifies the assessment scheme, boundary, service, version, and source supporting the claim.

  • Risk file: risk identification, analysis, evaluation, risk treatment measures, management approval, and review cadence.
  • Policy file: trust service policy mapping, practice statement, terms and conditions, and information security policy.
  • Operations file: trusted roles, personnel evidence, asset inventory, access reviews, monitoring logs, incident records, continuity tests, termination plan, and supplier agreements.
  • Assessment handoff: an evidence index that tells the CAB where each assessment criterion is implemented, which EN 319 401 requirement supports it, and which current record proves operation.
Section 5

Decision checklist for implementation teams

Use this checklist for an audit package, procurement response, or internal release decision. Each item should be answerable from the evidence file, not from memory.

  • Name the trust service and the applicable trust service policy before mapping EN 319 401 controls.
  • Identify whether the user question is about TSP operations, CAB assessment, or both.
  • Attach each EN 319 401 claim to a cited evidence artifact and owner.
  • Agree the assessment criteria, scope, sites, subcontractors, component services, audit method, and evidence-access arrangements with the CAB.
  • Prepare separate Stage 1 documentation and Stage 2 operational evidence, then track each finding through corrective action and CAB review.
  • Review evidence after significant changes to services, systems, information security policy, suppliers, incidents, or termination arrangements.
Section 6

Common mistakes in this comparison

Do not treat EN 319 401 and EN 319 403-1 as two labels for the same evidence. Keep the TSP operating evidence, the assessment criteria, and the CAB's audit and certification records visibly separate.

Do not overstate eIDAS or qualified-status claims. EN 319 401 includes an informative mapping to eIDAS requirements, but public claims still need the exact legal, service, assessment, supervisory, and trusted-list basis.

  • Do not state that a service is qualified, certified, assessed, or conformant unless the evidence file proves the boundary and scheme.
  • Do not assume the CAB will certify every control in the evidence pack; the stated assessment criteria and scope govern the conclusion.
  • Do not treat the audit report as the certification decision. EN 319 403-1 separates audit, review, and certification decision functions.
  • Do not mix generic cybersecurity controls with EN 319 401 evidence unless the control is mapped to a trust service risk, policy, or operation.
  • Do not publish draft notes, private evidence locations, or unverified references as public sources.
Primary sources

References and citations

Related guides

Explore more topics

CA and RA responsibilities under ETSI EN 319 401
How ETSI EN 319 401 frames CA and RA responsibility: TSP practice statements, management approval, role segregation, subcontractor control, and evidence boundaries.
eIDAS Articles 19 and 24: current ETSI mapping
Understand why old EN 319 401 editions mapped eIDAS Article 19, what replaced it, and how V3.2.1 maps current Article 24 duties.
ETSI EN 319 401 Audit and Conformity Assessment Evidence
How to prepare ETSI EN 319 401 evidence for audit and conformity assessment without overstating what the standard itself assesses.
ETSI EN 319 401 Audit Evidence Pack
Build an ETSI EN 319 401 audit evidence pack around records, logs, policies, risk assessment, incident handling, continuity, and supplier evidence.
ETSI EN 319 401 Audit Evidence Pack Workflow
Build an ETSI EN 319 401 audit evidence pack for trust service providers: risk assessment, practice statement, policies, records, logs, continuity, and supplier evidence.
ETSI EN 319 401 compliance duties for TSPs
ETSI EN 319 401 compliance guidance for trust service providers covering legal operation, evidence, accessibility, privacy, records, incidents, continuity, and suppliers.
ETSI EN 319 401 conformity assessment bodies: what is covered?
Understand what ETSI EN 319 401 says, and does not say, about conformity assessment bodies, independent assessment, and TSP evidence preparation.
ETSI EN 319 401 FAQ for trust service providers
Plain-language ETSI EN 319 401 answers covering TSP scope, trust service practice statements, risk assessment, incidents, records, continuity, and supplier evidence.
ETSI EN 319 401 Incident and Continuity Workflow
Build an EN 319 401 incident and continuity evidence workflow for TSP monitoring, response, reporting, records, backup recovery, and crisis review.
ETSI EN 319 401 Incident Reporting and Continuity Duties
Practical ETSI EN 319 401 V3.1.1 guidance for trust service incident response, reporting, evidence retention, business continuity, and termination planning.
ETSI EN 319 401 Personnel, Asset, and Access Controls
Clause-focused EN 319 401 V3.1.1 guide to TSP personnel duties, trusted roles, asset inventories, classification, and access-control evidence.
ETSI EN 319 401 policy and security requirements
ETSI EN 319 401 guidance for TSP policy and security requirements covering risk assessment, practice statements, terms, security controls, incidents, and evidence.
ETSI EN 319 401 policy documentation: what is required?
How ETSI EN 319 401 treats practice statements, terms, network and information systems security policy, evidence records, and change review.
ETSI EN 319 401 requirements map
Map ETSI EN 319 401 V3.1.1 requirements for trust service providers across risk assessment, policies, TSP operations, incidents, evidence, continuity, termination, and supply chain controls.
ETSI EN 319 401 Risk Assessment and Treatment
Clause-cited ETSI EN 319 401 V3.1.1 guidance for trust service risk assessment, risk treatment, residual-risk approval, and evidence planning.
ETSI EN 319 401 Subcontractor Controls
Practical EN 319 401 guidance for TSP subcontractor controls: retained responsibility, agreements, SLAs, supplier registers, monitoring, and audit evidence.
ETSI EN 319 401 Subcontractor Evidence Workflow
Build an EN 319 401 subcontractor evidence workflow for TSP supplier agreements, SLAs, audit mechanisms, risk reviews, supplier registers, and archived records.
ETSI EN 319 401 Subcontractor Requirements FAQ
How ETSI EN 319 401 treats subcontractors, outsourcing, supplier agreements, SLAs, monitoring, evidence, and retained TSP responsibility.
ETSI EN 319 401 Trust Service Applicability Workflow
A scoped workflow for deciding when ETSI EN 319 401 applies to a trust service and what TSP policy, risk, terms, operations, and supplier evidence to collect.
ETSI EN 319 401 Trust Service Provider Applicability
Use ETSI EN 319 401 to decide whether a trust service provider activity falls in the standard's type-independent baseline and what service, policy, risk, supplier, and evidence boundaries to document.
ETSI EN 319 401 vs eIDAS: Controls and Legal Duties
Compare ETSI EN 319 401 V3.2.1 with current eIDAS duties for qualified and non-qualified trust service providers, including risk, incidents, audits, records, and termination.
Security Incidents in ETSI EN 319 401
How ETSI EN 319 401 V3.2.1 expects TSPs to detect, classify, respond to, report, document, test, and review security incidents.
Trust service provider scope under ETSI EN 319 401
How to scope ETSI EN 319 401 for a trust service provider: service boundaries, trust service policy, practice statement, terms, risks, and third-party components.