Artifact GuideGLOBALETSI EN 319 401

ETSI EN 319 401 FAQ for TSPs

Practical answers for trust service providers using ETSI EN 319 401 V3.2.1 to structure scope, risk, policies, incidents, continuity, records, and supplier evidence.

V3.2.1 was published in January 2026 and adds detailed NIS2-aligned risk, incident, and supplier controls. Service-specific standards, applicable law, and assessment schemes still apply.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
FAQ modules
7

Structured answer sets in this page tree.

Primary sources
1

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

ETSI EN 319 401 V3.2.1 (2026-01) is the current ETSI baseline for general Trust Service Provider policies and operations. Use it to define service scope, risk governance, practice statements and terms, network and information systems security, incident handling, records, continuity, termination, and supply-chain evidence. It does not replace a service-specific ETSI standard, applicable law, or the assessment scheme used for a particular trust service.

Browse sub-FAQs

Choose the question set you need

These focused FAQ modules break this artifact into narrower answer sets so teams can move straight to the right source-backed guidance.

Browse all FAQ items22
Focused FAQ modules
7
Showing 7 of 7
Question 1

What does ETSI EN 319 401 cover?

ETSI EN 319 401 V3.2.1 specifies general policy requirements for Trust Service Providers that are independent of the type of trust service. Its scope is operation and management, including cybersecurity requirements intended to support NIS2 for qualified and non-qualified trust services.

The standard is not a service-specific rulebook for every trust service. It says other specifications refine and extend the requirements for particular forms of , and it does not specify how an independent party assesses the requirements or what information assessors must receive. Use EN 319 401 as the general TSP baseline, then add the service-specific ETSI standard, legal obligation, customer requirement, or assessment scheme that applies to the actual service.

  • Start the FAQ decision with the trust service being provided, the applicable trust service policy, and the systems and organizations in the operating boundary.
  • Do not claim that EN 319 401 alone proves qualified trust service status or completion of an independent conformity assessment.
  • Use EN 319 403-1 for conformity assessment body context when the question is about how TSPs are assessed rather than what EN 319 401 requires of operation.
  • Keep service-specific requirements separate from this general baseline so subscribers, relying parties, auditors, and internal owners can see which source drives each control.
Question 2

Who should use ETSI EN 319 401?

The standard defines a Trust Service Provider as an entity that provides one or more trust services. It also defines a trust service policy as rules indicating applicability to a community or class of application with common security requirements, and a as the practices the employs in providing a trust service.

This FAQ is for teams that run or support a trust service and need to assign EN 319 401 controls. The standard's overview gives examples of TSPs such as public-key certificate issuers, time-stamping service providers, and providers of remote electronic signature generation or validation services. If your organization only consumes a trust service, focus on supplier assurance and relying-party obligations rather than full implementation.

  • It is relevant when your organization provides a trust service or a service component that supports the trust service.
  • Map every answer to the exact trust service policy, community or class of application, and in scope.
  • When external organizations support the service, include their obligations in the practice statement evidence.
  • When the organization is a customer or relying party, use the FAQ to ask better supplier, terms, incident, and continuity questions rather than asserting duties internally.
Question 3

What documents does EN 319 401 expect a TSP to maintain or make available?

Clause 6 makes documentation central. A has to specify policies and practices appropriate for its services, maintain a practice statement covering the applicable trust service policy, identify external-organization obligations, and make the practice statement and relevant documentation available where needed to demonstrate conformance. Sensitive details need not be disclosed.

Terms and conditions are also explicit. EN 319 401 expects them to be available to subscribers and relying parties and to cover, for each supported trust service policy, items such as the policy applied, service-use limits, subscriber obligations, relying-party information, event-log retention, liability limits, applicable legal system, complaint and dispute procedures, conformity assessment status and scheme if assessed, contact information, and availability undertakings.

  • Keep the practice statement approved by the management body with final authority for it.
  • Define a review process and maintenance responsibilities for the practice statement.
  • Give notice when intended practice-statement changes might affect acceptance of the service by subjects, subscribers, or relying parties.
  • Make terms and conditions available through a durable means of communication and in readily understandable language.
Question 4

How does risk assessment drive EN 319 401 implementation?

Clause 5 requires a risk-management framework, assessment, and monitored treatment plan. V3.2.1 adds an all-hazards approach, third-party and single-point-of-failure risks, risk appetite and tolerance, named treatment owners and dates, documented residual-risk reasons, and measures for monitoring control effectiveness.

The must review and, where appropriate, update the assessment results and treatment plan at planned intervals, at least annually, and after significant incidents or significant changes to operations or risks. Management bodies, or accountable risk authorities where applicable, approve the framework and accept residual risk.

  • Keep risk identification, analysis, evaluation, treatment selection, security requirements, and operational procedures linked in one evidence trail.
  • Use the risk assessment to justify control depth for assets, access, cryptography, physical security, operation security, network security, incidents, continuity, and suppliers.
  • Record the risk method, criteria, appetite, tolerance, owners, treatment dates, management approval, and residual-risk acceptance instead of leaving decisions in technical tickets.
  • Run the required annual review and trigger an additional review after significant incidents or significant changes to operations or risks.
Question 5

What incident and record evidence matters most?

Incident evidence should cover a documented handling policy, risk-based logging scope, protected and backed-up logs, monitoring availability, event triage, response, reporting, testing, and post-incident review. V3.2.1 also requires predefined classification criteria, quarterly assessment of recurring incidents, response records, and planned incident-response tests.

Record evidence is broader than incident files. Clause 7.10 requires the to record and keep accessible relevant information about data issued and received by the TSP, including after the TSP's activities cease, for legal-evidence and service-continuity purposes. It also requires confidentiality and integrity of current and archived records, UTC-synchronized audit-log time at least once a day, stated retention periods in terms and conditions, and logging that cannot be easily deleted or destroyed during the required retention period.

  • Retain logs for network traffic, user administration, permission management, administrator actions, critical configuration and backup changes, security events, system resources, physical access where appropriate, and network device access.
  • For reportable incidents, preserve the legal basis, significance calculation, authority and CSIRT route, awareness time, notification timeline, and affected-person decision.
  • Record event severity assessment and any later reassessment or reclassification when new inputs change the picture.
  • Keep post-incident root-cause analysis and recurrence-reduction measures with the incident record.
Question 6

How should a TSP handle continuity, termination, and suppliers under EN 319 401?

Continuity evidence should show that the can act during disasters and recover according to its own continuity plan. EN 319 401 requires a continuity plan, restoration within the delay established in that plan after a disaster, backup copies and sufficient resources aligned with risk assessment and the business continuity plan, integrity checks on backups, documented backup recovery tests, and crisis-management processes with roles, authority communications, and security controls.

Termination and supplier evidence are part of the same assurance picture. EN 319 401 requires an up-to-date termination plan, notices before termination, subcontractor authorization termination, transfer or maintenance of evidence, private-key destruction or withdrawal where applicable, and arrangements for public keys or trust service tokens. V3.2.1 requires supplier monitoring at planned intervals at least annually and after related incidents. Contracts must address appropriate cybersecurity, staff, incident notice, audit, vulnerability, subcontracting, and termination obligations.

  • Test backup recovery and document findings, corrective actions, and integrity checks.
  • Keep crisis-management reviews tied to planned intervals or the post-incident review process.
  • Use termination planning to protect subscribers and relying parties from avoidable disruption and preserve evidence needed after service cessation.
  • For subcontracting, outsourcing, third-party arrangements, or trust service components, keep overall responsibility with the and bind suppliers to the required controls.
Primary sources

References and citations

etsi.org
Referenced sections
  • Grounds clauses 7.11, 7.12, and 7.14 for business continuity, backup, crisis management, TSP termination, supply-chain controls, third-party agreements, SLAs, and supplier registers.
"Supply chain policy"
Related guides

Explore more topics

ETSI EN 319 401 Audit and Conformity Assessment Evidence
How to prepare ETSI EN 319 401 evidence for audit and conformity assessment without overstating what the standard itself assesses.
ETSI EN 319 401 Audit Evidence Pack
Build an ETSI EN 319 401 audit evidence pack around records, logs, policies, risk assessment, incident handling, continuity, and supplier evidence.
ETSI EN 319 401 Audit Evidence Pack Workflow
Build an ETSI EN 319 401 audit evidence pack for trust service providers: risk assessment, practice statement, policies, records, logs, continuity, and supplier evidence.
ETSI EN 319 401 compliance duties for TSPs
ETSI EN 319 401 compliance guidance for trust service providers covering legal operation, evidence, accessibility, privacy, records, incidents, continuity, and suppliers.
ETSI EN 319 401 Incident and Continuity Workflow
Build an EN 319 401 incident and continuity evidence workflow for TSP monitoring, response, reporting, records, backup recovery, and crisis review.
ETSI EN 319 401 Incident Reporting and Continuity Duties
Practical ETSI EN 319 401 V3.1.1 guidance for trust service incident response, reporting, evidence retention, business continuity, and termination planning.
ETSI EN 319 401 Personnel, Asset, and Access Controls
Clause-focused EN 319 401 V3.1.1 guide to TSP personnel duties, trusted roles, asset inventories, classification, and access-control evidence.
ETSI EN 319 401 policy and security requirements
ETSI EN 319 401 guidance for TSP policy and security requirements covering risk assessment, practice statements, terms, security controls, incidents, and evidence.
ETSI EN 319 401 requirements map
Map ETSI EN 319 401 V3.1.1 requirements for trust service providers across risk assessment, policies, TSP operations, incidents, evidence, continuity, termination, and supply chain controls.
ETSI EN 319 401 Risk Assessment and Treatment
Clause-cited ETSI EN 319 401 V3.1.1 guidance for trust service risk assessment, risk treatment, residual-risk approval, and evidence planning.
ETSI EN 319 401 Subcontractor Controls
Practical EN 319 401 guidance for TSP subcontractor controls: retained responsibility, agreements, SLAs, supplier registers, monitoring, and audit evidence.
ETSI EN 319 401 Subcontractor Evidence Workflow
Build an EN 319 401 subcontractor evidence workflow for TSP supplier agreements, SLAs, audit mechanisms, risk reviews, supplier registers, and archived records.
ETSI EN 319 401 Trust Service Applicability Workflow
A scoped workflow for deciding when ETSI EN 319 401 applies to a trust service and what TSP policy, risk, terms, operations, and supplier evidence to collect.
ETSI EN 319 401 Trust Service Provider Applicability
Use ETSI EN 319 401 to decide whether a trust service provider activity falls in the standard's type-independent baseline and what service, policy, risk, supplier, and evidence boundaries to document.
ETSI EN 319 401 vs eIDAS: Controls and Legal Duties
Compare ETSI EN 319 401 V3.2.1 with current eIDAS duties for qualified and non-qualified trust service providers, including risk, incidents, audits, records, and termination.
ETSI EN 319 401 vs EN 319 403-1: TSP Policy vs CAB Assessment
Compare ETSI EN 319 401 V3.2.1 provider controls with EN 319 403-1 V2.3.1 CAB requirements for audit scope, evidence, sampling, reports, corrective action, and reassessment.