Artifact GuideGLOBALETSI EN 319 401

ETSI EN 319 401 Conformity assessment bodies and TSP evidence scope

A focused answer on how to read conformity assessment body references in ETSI EN 319 401 without overstating what the standard covers.

Based on ETSI EN 319 401 V3.2.1 and the current consolidated eIDAS Regulation. Assessment scope, accreditation, the applicable scheme, and the supervisory body's decision remain separate.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

ETSI EN 319 401 V3.2.1 tells a trust service provider what general policies and operating controls to maintain; it does not set the 's method, competence, accreditation, or evidence-access rules. For an EU qualified trust service, eIDAS defines the conformity assessment body as an accredited body competent to assess qualified TSPs and their qualified services. Use EN 319 403-1 and the applicable assessment scheme for the assessor's requirements, and keep the supervisory body's qualified-status decision separate from the CAB report.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What does EN 319 401 say about conformity assessment bodies?

EN 319 401 V3.2.1 sets service-independent policy requirements for TSP operation and management. Its scope expressly excludes the independent assessment method, information that must be made available to assessors, and requirements imposed on those assessors.

A TSP therefore cannot use EN 319 401 alone to prove that a CAB is accredited, competent for the service, or following the required scheme. For EU qualified services, check the CAB's accreditation and scope, the scheme used, the services and locations covered by the report, and the supervisory body's qualified-status decision.

  • Use EN 319 401 to define the TSP policy, practice, security, recordkeeping, continuity, compliance, and supplier evidence that may be reviewed.
  • Do not treat EN 319 401 as the source for CAB accreditation, independence, sampling, audit-method, or assessor-competence rules.
  • When a customer asks for CAB status, separate the TSP's conformance evidence from the assessor's own authority, scope, and conformity assessment scheme.
Citations
ETSI EN 319 401 V3.2.1 (2026-01)

Clause 1 excludes independent assessment methods, assessor evidence requirements, and assessor requirements from EN 319 401 and points to EN 319 403-1.

Question 2

What evidence can a TSP prepare for assessor review?

EN 319 401 identifies TSP evidence even though it does not prescribe the CAB process. Start with the assessment scope, applicable trust service policy, practice statement, management approvals, risk assessment and treatment plan, policy set, supplier controls, incident and continuity records, and public documentation needed to demonstrate conformance.

The terms and conditions must state, for each supported trust service policy, whether the service has been assessed as conformant and, if so, through which scheme. Keep that statement aligned with the actual CAB report. Do not extend it to a different service, policy, site, supplier, or period.

  • Map the assessed service to the trust service policy being applied and the practices used to address that policy.
  • Keep management approval, publication, review responsibilities, and change-notice decisions traceable to the practice statement.
  • For customer-facing claims, ensure the terms and conditions identify whether conformity has been assessed and the conformity assessment scheme used, when such an assessment exists.
  • Avoid disclosing sensitive implementation details publicly; EN 319 401 allows relevant documentation to demonstrate conformance without requiring disclosure of sensitive aspects.
Citations
ETSI EN 319 401 V3.2.1 (2026-01)

Clauses 6.1 and 6.2 require the practice statement, controlled disclosures, and the terms-and-conditions statement about assessment status and scheme.

Question 3

What should not be claimed from EN 319 401 alone?

For EU qualified trust services, eIDAS requires an audit at the qualified TSP's expense at least every 24 months. The TSP must submit the CAB report to the supervisory body within three working days of receipt and inform that body at least one month before a planned audit. Those legal rules do not make every EN 319 401 assessment an eIDAS qualified-service audit.

A CAB report also does not itself grant qualified status. Under eIDAS, the supervisory body verifies compliance and grants the provider and service qualified status; the service may begin as qualified after that status appears on the trusted list. Check the current trusted-list entry as well as the report.

  • Verify CAB accreditation, competence, assessment scheme, report date, covered service, policy, sites, and exclusions outside EN 319 401.
  • Do not imply that an assessment covers all services unless the trust service policy, assessment scope, and scheme say so.
  • For outsourced service parts, keep the TSP's retained responsibility, agreements, supplier security requirements, monitoring evidence, and inclusion or exclusion from the CAB scope explicit.
  • Review the evidence package after practice-statement changes, information security policy changes, supplier changes, incidents, or changes to service provision.
Citations
Consolidated eIDAS Regulation (EU) No 910/2014

Articles 20 and 21 establish the qualified-service audit interval, report-submission timing, advance audit notice, supervisory verification, grant of qualified status, and trusted-list condition.

Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Articles 20 and 21 establish the qualified-service audit interval, report-submission timing, advance audit notice, supervisory verification, grant of qualified status, and trusted-list condition.
etsi.org
Referenced sections
  • Supports the assessment boundary and retained TSP responsibility for outsourced or subcontracted service parts.
"maintain overall responsibility for conformance"
Related guides

Explore more topics

CA and RA responsibilities under ETSI EN 319 401
How ETSI EN 319 401 frames CA and RA responsibility: TSP practice statements, management approval, role segregation, subcontractor control, and evidence boundaries.
eIDAS Articles 19 and 24: current ETSI mapping
Understand why old EN 319 401 editions mapped eIDAS Article 19, what replaced it, and how V3.2.1 maps current Article 24 duties.
ETSI EN 319 401 Audit and Conformity Assessment Evidence
How to prepare ETSI EN 319 401 evidence for audit and conformity assessment without overstating what the standard itself assesses.
ETSI EN 319 401 Audit Evidence Pack
Build an ETSI EN 319 401 audit evidence pack around records, logs, policies, risk assessment, incident handling, continuity, and supplier evidence.
ETSI EN 319 401 Audit Evidence Pack Workflow
Build an ETSI EN 319 401 audit evidence pack for trust service providers: risk assessment, practice statement, policies, records, logs, continuity, and supplier evidence.
ETSI EN 319 401 compliance duties for TSPs
ETSI EN 319 401 compliance guidance for trust service providers covering legal operation, evidence, accessibility, privacy, records, incidents, continuity, and suppliers.
ETSI EN 319 401 FAQ for trust service providers
Plain-language ETSI EN 319 401 answers covering TSP scope, trust service practice statements, risk assessment, incidents, records, continuity, and supplier evidence.
ETSI EN 319 401 Incident and Continuity Workflow
Build an EN 319 401 incident and continuity evidence workflow for TSP monitoring, response, reporting, records, backup recovery, and crisis review.
ETSI EN 319 401 Incident Reporting and Continuity Duties
Practical ETSI EN 319 401 V3.1.1 guidance for trust service incident response, reporting, evidence retention, business continuity, and termination planning.
ETSI EN 319 401 Personnel, Asset, and Access Controls
Clause-focused EN 319 401 V3.1.1 guide to TSP personnel duties, trusted roles, asset inventories, classification, and access-control evidence.
ETSI EN 319 401 policy and security requirements
ETSI EN 319 401 guidance for TSP policy and security requirements covering risk assessment, practice statements, terms, security controls, incidents, and evidence.
ETSI EN 319 401 policy documentation: what is required?
How ETSI EN 319 401 treats practice statements, terms, network and information systems security policy, evidence records, and change review.
ETSI EN 319 401 requirements map
Map ETSI EN 319 401 V3.1.1 requirements for trust service providers across risk assessment, policies, TSP operations, incidents, evidence, continuity, termination, and supply chain controls.
ETSI EN 319 401 Risk Assessment and Treatment
Clause-cited ETSI EN 319 401 V3.1.1 guidance for trust service risk assessment, risk treatment, residual-risk approval, and evidence planning.
ETSI EN 319 401 Subcontractor Controls
Practical EN 319 401 guidance for TSP subcontractor controls: retained responsibility, agreements, SLAs, supplier registers, monitoring, and audit evidence.
ETSI EN 319 401 Subcontractor Evidence Workflow
Build an EN 319 401 subcontractor evidence workflow for TSP supplier agreements, SLAs, audit mechanisms, risk reviews, supplier registers, and archived records.
ETSI EN 319 401 Subcontractor Requirements FAQ
How ETSI EN 319 401 treats subcontractors, outsourcing, supplier agreements, SLAs, monitoring, evidence, and retained TSP responsibility.
ETSI EN 319 401 Trust Service Applicability Workflow
A scoped workflow for deciding when ETSI EN 319 401 applies to a trust service and what TSP policy, risk, terms, operations, and supplier evidence to collect.
ETSI EN 319 401 Trust Service Provider Applicability
Use ETSI EN 319 401 to decide whether a trust service provider activity falls in the standard's type-independent baseline and what service, policy, risk, supplier, and evidence boundaries to document.
ETSI EN 319 401 vs eIDAS: Controls and Legal Duties
Compare ETSI EN 319 401 V3.2.1 with current eIDAS duties for qualified and non-qualified trust service providers, including risk, incidents, audits, records, and termination.
ETSI EN 319 401 vs EN 319 403-1: TSP Policy vs CAB Assessment
Compare ETSI EN 319 401 V3.2.1 provider controls with EN 319 403-1 V2.3.1 CAB requirements for audit scope, evidence, sampling, reports, corrective action, and reassessment.
Security Incidents in ETSI EN 319 401
How ETSI EN 319 401 V3.2.1 expects TSPs to detect, classify, respond to, report, document, test, and review security incidents.
Trust service provider scope under ETSI EN 319 401
How to scope ETSI EN 319 401 for a trust service provider: service boundaries, trust service policy, practice statement, terms, risks, and third-party components.