What does ETSI EN 319 401 say about Article 19?
Annex B of ETSI EN 319 401 V3.1.1 maps eIDAS Article 19.1 to clauses 5, 6.3, and 7.2 through 7.12. In practical terms, the file should show how the TSP identifies and evaluates trust service risks, selects risk treatment measures, documents the information security policy and practice statement, manages personnel and operations, handles incidents, and maintains continuity and termination arrangements.
Annex B also maps Article 19.1's requirement to prevent and minimize incident impact and inform stakeholders to clauses 7.9 and 7.11. The directly useful evidence is therefore incident monitoring, response, stakeholder communication, continuity coordination, and post-incident review evidence, not just a generic security policy.
- Keep the Article 19.1 evidence tied to EN 319 401 clause 5 risk assessment, clause 6.3 information security policy, and the TSP management and operation clauses in 7.2 through 7.12.
- For incident handling, keep procedures for detection, containment, eradication, recovery, stakeholder communication, documentation, testing, and post-incident review together with ownership records.
- For Article 19.2, document notification procedures for a breach of security or loss of integrity with significant impact on the trust service or related personal data, including the 24-hour timing referenced by EN 319 401.
Primary ETSI source for the Annex B mapping from eIDAS Article 19 to EN 319 401 risk, policy, incident, continuity, and TSP management clauses.