Why is the old Article 19 mapping no longer current?
EN 319 401 V3.1.1 Annex B reproduced the original 2014 Article 19 and mapped its security and incident duties to clauses 5, 6.3, 7.2 through 7.12, especially 7.9 and 7.11. That table remains evidence of what the 2024 standard mapped, but it does not preserve a deleted legal article.
In the consolidated eIDAS text, applies to non-qualified TSPs. It requires appropriate risk policies and measures and notification of significant security breaches or service disruptions without undue delay and no later than 24 hours after awareness. Qualified TSP supervision now sits in Article 20, while NIS2 supplies the wider cybersecurity and significant-incident framework.
- Label any Article 19 evidence map as historical and record the EN 319 401 edition it used.
- For a non-qualified service, assess together with NIS2 and the applicable implementing rules; do not copy the former Article 19 test.
- For a qualified service, separate Article 20 supervision, provider duties, NIS2 cybersecurity and incident duties, and the service-specific standard.
Current ETSI source. Annex B maps security requirements to eIDAS Article 20 and NIS2 Article 21 rather than reproducing former eIDAS Article 19.
Binding current text showing the deletion of former Article 19 and the current Article 19a requirements for non-qualified TSPs.