Artifact GuideGLOBALETSI EN 319 401

ETSI EN 319 401 Article 19 history and current Article 24 mapping

Old EN 319 401 editions mapped former eIDAS Article 19. V3.2.1 reflects the amended eIDAS and NIS2 framework and keeps a current Article 24 mapping.

Use the ETSI annex as an informative evidence map. The consolidated regulation, NIS2, implementing rules, supervisory guidance, and service-specific standards control the legal assessment.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Do not use the Article 19 table in ETSI EN 319 401 V3.1.1 as current law. Regulation (EU) 2024/1183 deleted former eIDAS Article 19. The consolidated regulation now uses for non-qualified TSP risk and notification duties, Article 20 for supervision, and for qualified-provider requirements; NIS2 Article 21 and Article 23 govern cybersecurity measures and significant-incident reporting. ETSI EN 319 401 V3.2.1 (2026-01) updates its informative mapping accordingly.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

Why is the old Article 19 mapping no longer current?

EN 319 401 V3.1.1 Annex B reproduced the original 2014 Article 19 and mapped its security and incident duties to clauses 5, 6.3, 7.2 through 7.12, especially 7.9 and 7.11. That table remains evidence of what the 2024 standard mapped, but it does not preserve a deleted legal article.

In the consolidated eIDAS text, applies to non-qualified TSPs. It requires appropriate risk policies and measures and notification of significant security breaches or service disruptions without undue delay and no later than 24 hours after awareness. Qualified TSP supervision now sits in Article 20, while NIS2 supplies the wider cybersecurity and significant-incident framework.

  • Label any Article 19 evidence map as historical and record the EN 319 401 edition it used.
  • For a non-qualified service, assess together with NIS2 and the applicable implementing rules; do not copy the former Article 19 test.
  • For a qualified service, separate Article 20 supervision, provider duties, NIS2 cybersecurity and incident duties, and the service-specific standard.
Citations
ETSI EN 319 401 V3.2.1 (2026-01)

Current ETSI source. Annex B maps security requirements to eIDAS Article 20 and NIS2 Article 21 rather than reproducing former eIDAS Article 19.

Question 2

What does ETSI EN 319 401 say about Article 24?

V3.2.1 Annex B maps current (2)(a) to REQ-6.3-04, Article 24(2)(b) to clause 7.2, and Article 24(2)(d) to clause 6.2. The first mapping now includes the binding advance periods: at least one month before a change and three months before planned cessation.

The annex remains selective. also contains identity and attribute verification, risk-management, trustworthy-system, record, and termination duties. A qualified certificate issuer also needs the certificate-specific EN 319 411 series; conformance to one ETSI standard does not itself grant qualified status.

  • For (2)(a), keep approvals, supervisory-body contact details, notice content, delivery evidence, and calendars for the one-month change and three-month cessation periods.
  • For .2(b), keep personnel and subcontractor competence, training, reliability, and management evidence aligned with clause 7.2.
  • For .2(d), keep customer-facing terms and conditions evidence aligned with clause 6.2, including the trust service policy, limitations, relying-party information, and conformity-assessment statement where applicable.
  • For a provider granted qualified status before 20 May 2024, retain evidence that the (1), (1a), and (1b) conformity assessment report was submitted by the 21 May 2026 transition deadline.
Citations
Question 3

How should a team build the evidence file?

Start with the trust service, qualified or non-qualified status, and current legal provision. Then record the EN 319 401 clause used as supporting evidence and the actual artifact proving operation. Keep a separate historical column only when old Article 19 evidence must be migrated.

For a qualified certificate service, add EN 319 411-2 and the assessment scheme. EN 319 411-2 adds requirements for EU qualified certificates but warns that conformance to that standard alone does not imply qualified status under eIDAS.

  • Record the trust service type, whether the service is qualified or non-qualified, and whether the evidence concerns certificates, time-stamping, remote signing, validation, preservation, or another trust service.
  • For each current eIDAS or NIS2 row, cite the legal provision and ETSI clause separately, name the owner, attach the evidence, and set review triggers for source, service, supplier, and incident changes.
  • Mark former Article 19 rows for retirement or remapping instead of silently relabelling them.
Citations
Primary sources

References and citations

etsi.org
Referenced sections
  • Current source for general TSP controls and the revised informative eIDAS mapping.
"Mapping ETSI EN 319 401 requirements with eIDAS Regulation"
Related guides

Explore more topics

CA and RA responsibilities under ETSI EN 319 401
How ETSI EN 319 401 frames CA and RA responsibility: TSP practice statements, management approval, role segregation, subcontractor control, and evidence boundaries.
ETSI EN 319 401 Audit and Conformity Assessment Evidence
How to prepare ETSI EN 319 401 evidence for audit and conformity assessment without overstating what the standard itself assesses.
ETSI EN 319 401 Audit Evidence Pack
Build an ETSI EN 319 401 audit evidence pack around records, logs, policies, risk assessment, incident handling, continuity, and supplier evidence.
ETSI EN 319 401 Audit Evidence Pack Workflow
Build an ETSI EN 319 401 audit evidence pack for trust service providers: risk assessment, practice statement, policies, records, logs, continuity, and supplier evidence.
ETSI EN 319 401 compliance duties for TSPs
ETSI EN 319 401 compliance guidance for trust service providers covering legal operation, evidence, accessibility, privacy, records, incidents, continuity, and suppliers.
ETSI EN 319 401 conformity assessment bodies: what is covered?
Understand what ETSI EN 319 401 says, and does not say, about conformity assessment bodies, independent assessment, and TSP evidence preparation.
ETSI EN 319 401 FAQ for trust service providers
Plain-language ETSI EN 319 401 answers covering TSP scope, trust service practice statements, risk assessment, incidents, records, continuity, and supplier evidence.
ETSI EN 319 401 Incident and Continuity Workflow
Build an EN 319 401 incident and continuity evidence workflow for TSP monitoring, response, reporting, records, backup recovery, and crisis review.
ETSI EN 319 401 Incident Reporting and Continuity Duties
Practical ETSI EN 319 401 V3.1.1 guidance for trust service incident response, reporting, evidence retention, business continuity, and termination planning.
ETSI EN 319 401 Personnel, Asset, and Access Controls
Clause-focused EN 319 401 V3.1.1 guide to TSP personnel duties, trusted roles, asset inventories, classification, and access-control evidence.
ETSI EN 319 401 policy and security requirements
ETSI EN 319 401 guidance for TSP policy and security requirements covering risk assessment, practice statements, terms, security controls, incidents, and evidence.
ETSI EN 319 401 policy documentation: what is required?
How ETSI EN 319 401 treats practice statements, terms, network and information systems security policy, evidence records, and change review.
ETSI EN 319 401 requirements map
Map ETSI EN 319 401 V3.1.1 requirements for trust service providers across risk assessment, policies, TSP operations, incidents, evidence, continuity, termination, and supply chain controls.
ETSI EN 319 401 Risk Assessment and Treatment
Clause-cited ETSI EN 319 401 V3.1.1 guidance for trust service risk assessment, risk treatment, residual-risk approval, and evidence planning.
ETSI EN 319 401 Subcontractor Controls
Practical EN 319 401 guidance for TSP subcontractor controls: retained responsibility, agreements, SLAs, supplier registers, monitoring, and audit evidence.
ETSI EN 319 401 Subcontractor Evidence Workflow
Build an EN 319 401 subcontractor evidence workflow for TSP supplier agreements, SLAs, audit mechanisms, risk reviews, supplier registers, and archived records.
ETSI EN 319 401 Subcontractor Requirements FAQ
How ETSI EN 319 401 treats subcontractors, outsourcing, supplier agreements, SLAs, monitoring, evidence, and retained TSP responsibility.
ETSI EN 319 401 Trust Service Applicability Workflow
A scoped workflow for deciding when ETSI EN 319 401 applies to a trust service and what TSP policy, risk, terms, operations, and supplier evidence to collect.
ETSI EN 319 401 Trust Service Provider Applicability
Use ETSI EN 319 401 to decide whether a trust service provider activity falls in the standard's type-independent baseline and what service, policy, risk, supplier, and evidence boundaries to document.
ETSI EN 319 401 vs eIDAS: Controls and Legal Duties
Compare ETSI EN 319 401 V3.2.1 with current eIDAS duties for qualified and non-qualified trust service providers, including risk, incidents, audits, records, and termination.
ETSI EN 319 401 vs EN 319 403-1: TSP Policy vs CAB Assessment
Compare ETSI EN 319 401 V3.2.1 provider controls with EN 319 403-1 V2.3.1 CAB requirements for audit scope, evidence, sampling, reports, corrective action, and reassessment.
Security Incidents in ETSI EN 319 401
How ETSI EN 319 401 V3.2.1 expects TSPs to detect, classify, respond to, report, document, test, and review security incidents.
Trust service provider scope under ETSI EN 319 401
How to scope ETSI EN 319 401 for a trust service provider: service boundaries, trust service policy, practice statement, terms, risks, and third-party components.