FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
22of22items
Across 7 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
CA and RA responsibilities under ETSI EN 319 401

What does EN 319 401 require for CA and RA responsibility?

Treat CA and RA responsibility as part of the TSP's controlled practice system. EN 319 401 requires appropriate policies and practices, a practice statement addressing the applicable trust service policy, management approval, implementation, and a defined maintenance process.

A Registration Authority mainly identifies and authenticates certificate subjects and may assist with applications or revocation. A Certification Authority creates and assigns certificates, but the term can also describe the technical certificate-generation component used by the issuing TSP.

For CA or RA activities performed by external organizations, the practice statement should not hide the dependency. EN 319 401 requires the trust service practice statement to identify obligations of external organizations supporting the TSP's services, including applicable policies and practices.

  • Map CA and RA activities to the TSP practice statement or certificate-specific CPS, with detailed internal procedures where public disclosure would expose sensitive operations.
  • Show management approval and a named review process for the practices that govern certificate issuance, registration support, revocation support, and related service components.
  • Identify any external organization, registration service provider, component provider, outsourcer, or subcontractor that supports the CA or RA process.
Citations
CA and RA responsibilities under ETSI EN 319 401

Where should teams draw the CA/RA boundary?

ETSI EN 319 411-1 V1.5.1 treats the TSP as the authority trusted by subscribers and relying parties and gives it overall responsibility for certification services. In that standard, CA can also mean the technical component concerned with certificate issuance. An RA mainly identifies and authenticates subjects; the registration service passes verified identity and attribute results to certificate generation.

Do not collapse those service functions into job titles. One organization may perform several functions, or an external party may perform the RA work, but the CPS and internal procedures must show the boundary, approvals, evidence, access, and segregation that apply.

  • Separate registration and identity verification from certificate generation, dissemination, revocation decision processing, and certificate-status publication; assign each function and its evidence.
  • Document who performs the work, whether the role is internal or external, which trust service policy or certificate policy applies, and which practice statement governs it.
  • If the RA function is delegated or outsourced, retain evidence that the TSP remains accountable for conformance and has a documented agreement covering the relevant security obligations.
Citations
ETSI EN 319 411-1 V1.5.1 certificate TSP requirements

Defines CA, RA, CPS, and registration officer; clause 4.3 separates registration, certificate generation, dissemination, revocation management, and status services; clause 5.4.1 assigns overall certification-service responsibility to the TSP.

CA and RA responsibilities under ETSI EN 319 401

What evidence should support the responsibility map?

Use a responsibility map that connects every certificate lifecycle activity to the governing policy, CPS section, role, approval, system access, evidence record, and external agreement. EN 319 401 requires policies and practices to be approved, communicated where relevant, maintained, and made available as needed to demonstrate conformance, while allowing sensitive details to remain undisclosed.

For certificate services, keep the public-facing CPS or terms aligned with the private operating evidence. EN 319 411-1 explains that low-level operational procedures can hold specific task and responsibility details that are useful for daily operation and process review, even if they are not publicly disclosed.

  • Practice statement or CPS section identifying CA, RA, registration officer, revocation-support, and external-support responsibilities.
  • Management approval record, review cadence, and change-notice trigger for practice-statement changes that may affect subjects, subscribers, or relying parties.
  • Role and access evidence showing segregation of conflicting duties, documented trusted roles, personnel competence, and contractor or supplier obligations.
Citations
eIDAS Articles 19 and 24: current ETSI mapping

Why is the old Article 19 mapping no longer current?

EN 319 401 V3.1.1 Annex B reproduced the original 2014 Article 19 and mapped its security and incident duties to clauses 5, 6.3, 7.2 through 7.12, especially 7.9 and 7.11. That table remains evidence of what the 2024 standard mapped, but it does not preserve a deleted legal article.

In the consolidated eIDAS text, Article 19a applies to non-qualified TSPs. It requires appropriate risk policies and measures and notification of significant security breaches or service disruptions without undue delay and no later than 24 hours after awareness. Qualified TSP supervision now sits in Article 20, while NIS2 supplies the wider cybersecurity and significant-incident framework.

  • Label any Article 19 evidence map as historical and record the EN 319 401 edition it used.
  • For a non-qualified service, assess Article 19a together with NIS2 and the applicable implementing rules; do not copy the former Article 19 test.
  • For a qualified service, separate Article 20 supervision, Article 24 provider duties, NIS2 cybersecurity and incident duties, and the service-specific standard.
Citations
ETSI EN 319 401 V3.2.1 (2026-01)

Current ETSI source. Annex B maps security requirements to eIDAS Article 20 and NIS2 Article 21 rather than reproducing former eIDAS Article 19.

eIDAS Articles 19 and 24: current ETSI mapping

What does ETSI EN 319 401 say about Article 24?

V3.2.1 Annex B maps current Article 24(2)(a) to REQ-6.3-04, Article 24(2)(b) to clause 7.2, and Article 24(2)(d) to clause 6.2. The first mapping now includes the binding advance periods: at least one month before a change and three months before planned cessation.

The annex remains selective. Article 24 also contains identity and attribute verification, risk-management, trustworthy-system, record, and termination duties. A qualified certificate issuer also needs the certificate-specific EN 319 411 series; conformance to one ETSI standard does not itself grant qualified status.

  • For Article 24(2)(a), keep approvals, supervisory-body contact details, notice content, delivery evidence, and calendars for the one-month change and three-month cessation periods.
  • For Article 24.2(b), keep personnel and subcontractor competence, training, reliability, and management evidence aligned with clause 7.2.
  • For Article 24.2(d), keep customer-facing terms and conditions evidence aligned with clause 6.2, including the trust service policy, limitations, relying-party information, and conformity-assessment statement where applicable.
  • For a provider granted qualified status before 20 May 2024, retain evidence that the Article 24(1), (1a), and (1b) conformity assessment report was submitted by the 21 May 2026 transition deadline.
Citations
eIDAS Articles 19 and 24: current ETSI mapping

How should a team build the evidence file?

Start with the trust service, qualified or non-qualified status, and current legal provision. Then record the EN 319 401 clause used as supporting evidence and the actual artifact proving operation. Keep a separate historical column only when old Article 19 evidence must be migrated.

For a qualified certificate service, add EN 319 411-2 and the assessment scheme. EN 319 411-2 adds requirements for EU qualified certificates but warns that conformance to that standard alone does not imply qualified status under eIDAS.

  • Record the trust service type, whether the service is qualified or non-qualified, and whether the evidence concerns certificates, time-stamping, remote signing, validation, preservation, or another trust service.
  • For each current eIDAS or NIS2 row, cite the legal provision and ETSI clause separately, name the owner, attach the evidence, and set review triggers for source, service, supplier, and incident changes.
  • Mark former Article 19 rows for retirement or remapping instead of silently relabelling them.
Citations
ETSI EN 319 401 conformity assessment bodies: what is covered?

What does EN 319 401 say about conformity assessment bodies?

EN 319 401 V3.2.1 sets service-independent policy requirements for TSP operation and management. Its scope expressly excludes the independent assessment method, information that must be made available to assessors, and requirements imposed on those assessors.

A TSP therefore cannot use EN 319 401 alone to prove that a CAB is accredited, competent for the service, or following the required scheme. For EU qualified services, check the CAB's accreditation and scope, the scheme used, the services and locations covered by the report, and the supervisory body's qualified-status decision.

  • Use EN 319 401 to define the TSP policy, practice, security, recordkeeping, continuity, compliance, and supplier evidence that may be reviewed.
  • Do not treat EN 319 401 as the source for CAB accreditation, independence, sampling, audit-method, or assessor-competence rules.
  • When a customer asks for CAB status, separate the TSP's conformance evidence from the assessor's own authority, scope, and conformity assessment scheme.
Citations
ETSI EN 319 401 V3.2.1 (2026-01)

Clause 1 excludes independent assessment methods, assessor evidence requirements, and assessor requirements from EN 319 401 and points to EN 319 403-1.

ETSI EN 319 401 conformity assessment bodies: what is covered?

What evidence can a TSP prepare for assessor review?

EN 319 401 identifies TSP evidence even though it does not prescribe the CAB process. Start with the assessment scope, applicable trust service policy, practice statement, management approvals, risk assessment and treatment plan, policy set, supplier controls, incident and continuity records, and public documentation needed to demonstrate conformance.

The terms and conditions must state, for each supported trust service policy, whether the service has been assessed as conformant and, if so, through which scheme. Keep that statement aligned with the actual CAB report. Do not extend it to a different service, policy, site, supplier, or period.

  • Map the assessed service to the trust service policy being applied and the practices used to address that policy.
  • Keep management approval, publication, review responsibilities, and change-notice decisions traceable to the practice statement.
  • For customer-facing claims, ensure the terms and conditions identify whether conformity has been assessed and the conformity assessment scheme used, when such an assessment exists.
  • Avoid disclosing sensitive implementation details publicly; EN 319 401 allows relevant documentation to demonstrate conformance without requiring disclosure of sensitive aspects.
Citations
ETSI EN 319 401 V3.2.1 (2026-01)

Clauses 6.1 and 6.2 require the practice statement, controlled disclosures, and the terms-and-conditions statement about assessment status and scheme.

ETSI EN 319 401 conformity assessment bodies: what is covered?

What should not be claimed from EN 319 401 alone?

For EU qualified trust services, eIDAS requires an audit at the qualified TSP's expense at least every 24 months. The TSP must submit the CAB report to the supervisory body within three working days of receipt and inform that body at least one month before a planned audit. Those legal rules do not make every EN 319 401 assessment an eIDAS qualified-service audit.

A CAB report also does not itself grant qualified status. Under eIDAS, the supervisory body verifies compliance and grants the provider and service qualified status; the service may begin as qualified after that status appears on the trusted list. Check the current trusted-list entry as well as the report.

  • Verify CAB accreditation, competence, assessment scheme, report date, covered service, policy, sites, and exclusions outside EN 319 401.
  • Do not imply that an assessment covers all services unless the trust service policy, assessment scope, and scheme say so.
  • For outsourced service parts, keep the TSP's retained responsibility, agreements, supplier security requirements, monitoring evidence, and inclusion or exclusion from the CAB scope explicit.
  • Review the evidence package after practice-statement changes, information security policy changes, supplier changes, incidents, or changes to service provision.
Citations
Consolidated eIDAS Regulation (EU) No 910/2014

Articles 20 and 21 establish the qualified-service audit interval, report-submission timing, advance audit notice, supervisory verification, grant of qualified status, and trusted-list condition.

ETSI EN 319 401 policy documentation: what is required?

What policy documents does EN 319 401 expect?

EN 319 401 V3.2.1 requires the TSP to specify policies and practices appropriate to the trust services it provides. Management must approve them, and the TSP must publish and communicate them to employees and external parties as relevant.

The core document is the trust service practice statement. EN 319 401 requires it to describe the practices and procedures used to address the applicable trust service policy identified by the TSP, identify obligations of external organizations supporting the service, and be maintained through a defined review process. The standard does not mandate a particular practice-statement structure.

  • Maintain a trust service practice statement that maps the applicable trust service policy to the practices and procedures actually used.
  • Record management approval and final authority for approving the practice statement.
  • Identify external organizations supporting the service and the policies or practices that apply to their obligations.
  • Define responsibilities for maintaining the practice statement and reviewing it over time.
  • State the provisions for service termination in the TSP's practices and connect them to the current termination plan.
Citations
ETSI EN 319 401 V3.2.1 (2026-01)

Clause 6.1 establishes the policy, practice-statement, approval, disclosure, maintenance, change-notice, and termination-practice requirements.

ETSI EN 319 401 policy documentation: what is required?

What should be made available to subscribers and relying parties?

EN 319 401 distinguishes between documentation that demonstrates conformance and sensitive details that do not need to be publicly disclosed. The TSP must make its practice statement and other relevant documentation available to subscribers and relying parties as necessary to demonstrate conformance to the trust service policy, while sensitive aspects can remain undisclosed.

The terms and conditions are a separate public-facing requirement. For each supported trust service policy, they must cover the policy, use limits, subscriber obligations, relying-party information, event-log retention, liability limits, applicable legal system, complaint and dispute procedures, assessment status and scheme if assessed, contact information, and availability undertakings. V3.2.1 also requires precise terms to be presented before contract in a clear, comprehensive, easily accessible manner, both in a publicly accessible space and individually.

  • Keep a public or customer-facing version of the practice statement aligned with the controlled internal version.
  • Do not publish sensitive implementation details merely to prove conformance; disclose what is necessary and support the rest through controlled evidence.
  • Make terms and conditions available before a contractual relationship, through a durable means of communication, in readily understandable language.
  • Treat event-log retention, limitations of liability, contact details, and conformity-assessment claims as controlled terms-and-conditions content.
Citations
ETSI EN 319 401 policy documentation: what is required?

How should policy documentation stay current?

V3.2.1 replaces the former information security policy wording with a policy on the security of network and information systems. It must set security objectives, continual-improvement and resource commitments, roles, retained documentation, topic-specific policies, implementation measures, maturity indicators, and the date of formal management approval. The TSP must document, implement, and maintain the policy with the controls and operating procedures for its facilities, systems, and information assets.

The policy and risk documents now have explicit review timing. The network and information systems security policy and the risk assessment results and treatment plan must be reviewed at planned intervals, at least annually, and after significant incidents or significant changes to operations or risks. Practice-statement changes that might affect service acceptance require due notice, and the approved revision must then be made available.

  • Connect the practice statement, network and information systems security policy, asset inventory, operating procedures, and terms and conditions instead of maintaining them as disconnected files.
  • Document the maximum interval between configuration checks in the trust service practice statement.
  • Use the annual review, significant incidents, significant operational or risk changes, service-provision changes, security-impacting changes, and practice-statement changes as update triggers.
  • Keep records accessible for an appropriate period to support legal evidence and service continuity, including after TSP activities cease where applicable.
Citations
ETSI EN 319 401 V3.2.1 (2026-01)

Clauses 5 and 6.3 define the current risk, network and information systems security policy, approval, content, review, change-notice, and configuration-check documentation requirements.

ETSI EN 319 401 Subcontractor Requirements

What does EN 319 401 require when a TSP uses subcontractors?

EN 319 401 V3.2.1 treats subcontracting, outsourcing, cloud use, and other third-party arrangements as part of the controlled supply chain. When another party, including a trust service component provider, supplies part of the service, the TSP keeps overall responsibility for the supply-chain policy, its network and information systems security policy, and the trust service policy requirements.

Supplier control extends beyond onboarding. The TSP should identify which part of the trust service the outside party performs, record the TSP-owned policy requirements that apply, and keep evidence of the documented responsibilities.

  • Map each subcontracted or outsourced activity to the affected trust service, component, policy, system, information flow, and evidence owner.
  • Keep the TSP as the accountable owner for conformance even when a subcontractor or trust service component provider performs part of the service.
  • Use the trust service practice statement to identify obligations of external organizations supporting the TSP's services.
  • Require staff and, where applicable, subcontractors to have suitable expertise, reliability, experience, qualifications, and relevant cybersecurity and personal data protection training.
Citations
ETSI EN 319 401 V3.2.1 (2026-01)

Supports retained TSP responsibility for subcontracting and outsourcing arrangements, external organization obligations in the practice statement, and subcontractor competence expectations.

ETSI EN 319 401 Subcontractor Requirements

What should be in the subcontractor agreement evidence?

The agreement evidence should show that the supplier relationship is specific enough to enforce the TSP's information security requirements. EN 319 401 calls for documented agreements and contractual relationships when service provisioning involves subcontracting, outsourcing, or other third-party arrangements, so both parties understand their obligations to fulfil relevant information security requirements.

Keep the signed agreement with a requirement map and evidence of supplier acceptance. V3.2.1 says contracts must address, where appropriate, cybersecurity requirements; staff awareness, skills, training, and certifications; background verification; prompt supplier notice of incidents that risk the TSP's systems; audit rights or audit reports; vulnerability handling; subcontracting controls; and information retrieval or disposal at termination.

  • Document the service part or component the subcontractor provides and the trust service policy requirements it affects.
  • Define outsourcer liability and bind the outsourcer to implement controls required by the TSP.
  • Include applicable TSP security policies and requirements in contracts with direct suppliers or service providers.
  • Use service level agreements and/or auditing mechanisms to evidence that direct suppliers address TSP security requirements aligned with the TSP risk assessment.
  • Require approved subcontractors to receive cybersecurity requirements equivalent to those imposed on the direct supplier where the TSP permits further subcontracting.
  • Set incident-notice, audit, vulnerability-handling, information-return or disposal, and contract-exit obligations where they are appropriate to the service and risk.
Citations
ETSI EN 319 401 V3.2.1 (2026-01)

Clause 7.14.3 supports documented agreements, liability, required controls, SLAs or audits, and the current contract-content requirements for incidents, audits, vulnerabilities, subcontracting, staff, and termination.

ETSI EN 319 401 Subcontractor Requirements

How should teams keep subcontractor evidence current?

V3.2.1 requires the TSP to review its supply-chain policy and monitor, review, evaluate, and manage changes in direct-supplier cybersecurity practices at planned intervals, at least annually, or after an incident related to the supplier's services.

Maintain both views required by the standard: a register of suppliers and agreements showing where TSP information is managed or archived, and an up-to-date register of direct suppliers and service providers with contact points and the ICT products, services, and processes each provides. Review agreements for validity, fitness for purpose, and current security clauses. On TSP service termination, end subcontractor authority to act for trust-service-token issuance functions.

  • Maintain a register of suppliers and agreements showing where TSP information is managed or archived.
  • Review direct suppliers at least annually or after supplier-related incidents; document the result, decision, owner, and follow-up.
  • Review, validate, and update the supplier and agreement registers for current contacts, supplied ICT products, services and processes, information locations, validity, fitness for purpose, and security clauses.
  • Trigger reassessment after an incident related to a direct supplier's or service provider's provision of services.
  • Include subcontractor authorization termination in the TSP service termination plan when subcontractors act for functions related to issuing trust service tokens.
Citations
ETSI EN 319 401 V3.2.1 (2026-01)

Supports annual or incident-triggered monitoring, both supplier-register views, agreement review, and termination of subcontractor authorization before TSP service termination.

Page 1 of 2
Previous12Next