Artifact GuideGLOBALETSI EN 319 401

ETSI EN 319 401 CA and RA responsibilities

A focused answer for teams mapping certification authority and registration authority work into ETSI EN 319 401 governance evidence.

Based on ETSI EN 319 401 V3.2.1 and certificate-specific ETSI EN 319 411-1 V1.5.1. The applicable certificate policy, legal regime, and service design still control the assignment.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

ETSI EN 319 401 V3.2.1 does not assign every (CA) and (RA) task. ETSI EN 319 411-1 supplies the certificate-service boundary: the CA creates and assigns certificates, while the RA is mainly responsible for identifying and authenticating certificate subjects and may support applications or revocation. The TSP must document the actual allocation, segregate conflicting duties, control external parties, and retain overall responsibility for the certification services.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What does EN 319 401 require for CA and RA responsibility?

Treat CA and RA responsibility as part of the TSP's controlled practice system. EN 319 401 requires appropriate policies and practices, a practice statement addressing the applicable trust service policy, management approval, implementation, and a defined maintenance process.

A mainly identifies and authenticates certificate subjects and may assist with applications or revocation. A creates and assigns certificates, but the term can also describe the technical certificate-generation component used by the issuing TSP.

For CA or RA activities performed by external organizations, the practice statement should not hide the dependency. EN 319 401 requires the trust service practice statement to identify obligations of external organizations supporting the TSP's services, including applicable policies and practices.

  • Map CA and RA activities to the TSP practice statement or certificate-specific , with detailed internal procedures where public disclosure would expose sensitive operations.
  • Show management approval and a named review process for the practices that govern certificate issuance, registration support, revocation support, and related service components.
  • Identify any external organization, registration service provider, component provider, outsourcer, or subcontractor that supports the CA or RA process.
Citations
Question 2

Where should teams draw the CA/RA boundary?

ETSI EN 319 411-1 V1.5.1 treats the TSP as the authority trusted by subscribers and relying parties and gives it overall responsibility for certification services. In that standard, CA can also mean the technical component concerned with certificate issuance. An RA mainly identifies and authenticates subjects; the registration service passes verified identity and attribute results to certificate generation.

Do not collapse those service functions into job titles. One organization may perform several functions, or an external party may perform the RA work, but the and internal procedures must show the boundary, approvals, evidence, access, and segregation that apply.

  • Separate registration and identity verification from certificate generation, dissemination, revocation decision processing, and certificate-status publication; assign each function and its evidence.
  • Document who performs the work, whether the role is internal or external, which trust service policy or certificate policy applies, and which practice statement governs it.
  • If the RA function is delegated or outsourced, retain evidence that the TSP remains accountable for conformance and has a documented agreement covering the relevant security obligations.
Citations
ETSI EN 319 411-1 V1.5.1 certificate TSP requirements

Defines CA, RA, CPS, and registration officer; clause 4.3 separates registration, certificate generation, dissemination, revocation management, and status services; clause 5.4.1 assigns overall certification-service responsibility to the TSP.

Question 3

What evidence should support the responsibility map?

Use a responsibility map that connects every certificate lifecycle activity to the governing policy, section, role, approval, system access, evidence record, and external agreement. EN 319 401 requires policies and practices to be approved, communicated where relevant, maintained, and made available as needed to demonstrate conformance, while allowing sensitive details to remain undisclosed.

For certificate services, keep the public-facing or terms aligned with the private operating evidence. EN 319 411-1 explains that low-level operational procedures can hold specific task and responsibility details that are useful for daily operation and process review, even if they are not publicly disclosed.

  • Practice statement or section identifying CA, RA, registration officer, revocation-support, and external-support responsibilities.
  • Management approval record, review cadence, and change-notice trigger for practice-statement changes that may affect subjects, subscribers, or relying parties.
  • Role and access evidence showing segregation of conflicting duties, documented trusted roles, personnel competence, and contractor or supplier obligations.
Citations
Primary sources

References and citations

Related guides

Explore more topics

eIDAS Articles 19 and 24: current ETSI mapping
Understand why old EN 319 401 editions mapped eIDAS Article 19, what replaced it, and how V3.2.1 maps current Article 24 duties.
ETSI EN 319 401 Audit and Conformity Assessment Evidence
How to prepare ETSI EN 319 401 evidence for audit and conformity assessment without overstating what the standard itself assesses.
ETSI EN 319 401 Audit Evidence Pack
Build an ETSI EN 319 401 audit evidence pack around records, logs, policies, risk assessment, incident handling, continuity, and supplier evidence.
ETSI EN 319 401 Audit Evidence Pack Workflow
Build an ETSI EN 319 401 audit evidence pack for trust service providers: risk assessment, practice statement, policies, records, logs, continuity, and supplier evidence.
ETSI EN 319 401 compliance duties for TSPs
ETSI EN 319 401 compliance guidance for trust service providers covering legal operation, evidence, accessibility, privacy, records, incidents, continuity, and suppliers.
ETSI EN 319 401 conformity assessment bodies: what is covered?
Understand what ETSI EN 319 401 says, and does not say, about conformity assessment bodies, independent assessment, and TSP evidence preparation.
ETSI EN 319 401 FAQ for trust service providers
Plain-language ETSI EN 319 401 answers covering TSP scope, trust service practice statements, risk assessment, incidents, records, continuity, and supplier evidence.
ETSI EN 319 401 Incident and Continuity Workflow
Build an EN 319 401 incident and continuity evidence workflow for TSP monitoring, response, reporting, records, backup recovery, and crisis review.
ETSI EN 319 401 Incident Reporting and Continuity Duties
Practical ETSI EN 319 401 V3.1.1 guidance for trust service incident response, reporting, evidence retention, business continuity, and termination planning.
ETSI EN 319 401 Personnel, Asset, and Access Controls
Clause-focused EN 319 401 V3.1.1 guide to TSP personnel duties, trusted roles, asset inventories, classification, and access-control evidence.
ETSI EN 319 401 policy and security requirements
ETSI EN 319 401 guidance for TSP policy and security requirements covering risk assessment, practice statements, terms, security controls, incidents, and evidence.
ETSI EN 319 401 policy documentation: what is required?
How ETSI EN 319 401 treats practice statements, terms, network and information systems security policy, evidence records, and change review.
ETSI EN 319 401 requirements map
Map ETSI EN 319 401 V3.1.1 requirements for trust service providers across risk assessment, policies, TSP operations, incidents, evidence, continuity, termination, and supply chain controls.
ETSI EN 319 401 Risk Assessment and Treatment
Clause-cited ETSI EN 319 401 V3.1.1 guidance for trust service risk assessment, risk treatment, residual-risk approval, and evidence planning.
ETSI EN 319 401 Subcontractor Controls
Practical EN 319 401 guidance for TSP subcontractor controls: retained responsibility, agreements, SLAs, supplier registers, monitoring, and audit evidence.
ETSI EN 319 401 Subcontractor Evidence Workflow
Build an EN 319 401 subcontractor evidence workflow for TSP supplier agreements, SLAs, audit mechanisms, risk reviews, supplier registers, and archived records.
ETSI EN 319 401 Subcontractor Requirements FAQ
How ETSI EN 319 401 treats subcontractors, outsourcing, supplier agreements, SLAs, monitoring, evidence, and retained TSP responsibility.
ETSI EN 319 401 Trust Service Applicability Workflow
A scoped workflow for deciding when ETSI EN 319 401 applies to a trust service and what TSP policy, risk, terms, operations, and supplier evidence to collect.
ETSI EN 319 401 Trust Service Provider Applicability
Use ETSI EN 319 401 to decide whether a trust service provider activity falls in the standard's type-independent baseline and what service, policy, risk, supplier, and evidence boundaries to document.
ETSI EN 319 401 vs eIDAS: Controls and Legal Duties
Compare ETSI EN 319 401 V3.2.1 with current eIDAS duties for qualified and non-qualified trust service providers, including risk, incidents, audits, records, and termination.
ETSI EN 319 401 vs EN 319 403-1: TSP Policy vs CAB Assessment
Compare ETSI EN 319 401 V3.2.1 provider controls with EN 319 403-1 V2.3.1 CAB requirements for audit scope, evidence, sampling, reports, corrective action, and reassessment.
Security Incidents in ETSI EN 319 401
How ETSI EN 319 401 V3.2.1 expects TSPs to detect, classify, respond to, report, document, test, and review security incidents.
Trust service provider scope under ETSI EN 319 401
How to scope ETSI EN 319 401 for a trust service provider: service boundaries, trust service policy, practice statement, terms, risks, and third-party components.