Artifact GuideGLOBALETSI EN 319 401

ETSI EN 319 401 Policy documentation requirements

A focused answer for teams turning EN 319 401 policy, practice, terms, security, and evidence requirements into maintainable documentation.

Based on ETSI EN 319 401 V3.2.1 (2026-01). It explains the standard's document set; service-specific standards, law, and an assessment scheme can require more.

Author
Sorena AI
Published
Jun 1, 2024
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
1

Cited legal and guidance references.

Publication metadata
Sorena AI
Published Jun 1, 2024
Updated Jul 24, 2026
Overview

ETSI EN 319 401 V3.2.1 does not call for one generic compliance file. A Trust Service Provider needs approved policies and practices, a , customer-facing terms and conditions, a policy on the security of network and information systems, risk assessment and treatment records, topic-specific policies, operating procedures, and retained evidence. Each document needs an owner, approval, review trigger, and controlled relationship to the trust service it supports.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What policy documents does EN 319 401 expect?

EN 319 401 V3.2.1 requires the TSP to specify policies and practices appropriate to the trust services it provides. Management must approve them, and the TSP must publish and communicate them to employees and external parties as relevant.

The core document is the . EN 319 401 requires it to describe the practices and procedures used to address the applicable trust service policy identified by the TSP, identify obligations of external organizations supporting the service, and be maintained through a defined review process. The standard does not mandate a particular practice-statement structure.

  • Maintain a that maps the applicable trust service policy to the practices and procedures actually used.
  • Record management approval and final authority for approving the practice statement.
  • Identify external organizations supporting the service and the policies or practices that apply to their obligations.
  • Define responsibilities for maintaining the practice statement and reviewing it over time.
  • State the provisions for service termination in the TSP's practices and connect them to the current termination plan.
Citations
ETSI EN 319 401 V3.2.1 (2026-01)

Clause 6.1 establishes the policy, practice-statement, approval, disclosure, maintenance, change-notice, and termination-practice requirements.

Question 2

What should be made available to subscribers and relying parties?

EN 319 401 distinguishes between documentation that demonstrates conformance and sensitive details that do not need to be publicly disclosed. The TSP must make its practice statement and other relevant documentation available to subscribers and relying parties as necessary to demonstrate conformance to the trust service policy, while sensitive aspects can remain undisclosed.

The terms and conditions are a separate public-facing requirement. For each supported trust service policy, they must cover the policy, use limits, subscriber obligations, relying-party information, event-log retention, liability limits, applicable legal system, complaint and dispute procedures, assessment status and scheme if assessed, contact information, and availability undertakings. V3.2.1 also requires precise terms to be presented before contract in a clear, comprehensive, easily accessible manner, both in a publicly accessible space and individually.

  • Keep a public or customer-facing version of the practice statement aligned with the controlled internal version.
  • Do not publish sensitive implementation details merely to prove conformance; disclose what is necessary and support the rest through controlled evidence.
  • Make terms and conditions available before a contractual relationship, through a durable means of communication, in readily understandable language.
  • Treat event-log retention, limitations of liability, contact details, and conformity-assessment claims as controlled terms-and-conditions content.
Citations
Question 3

How should policy documentation stay current?

V3.2.1 replaces the former information security policy wording with a policy on the security of network and information systems. It must set security objectives, continual-improvement and resource commitments, roles, retained documentation, topic-specific policies, implementation measures, maturity indicators, and the date of formal management approval. The TSP must document, implement, and maintain the policy with the controls and operating procedures for its facilities, systems, and information assets.

The policy and risk documents now have explicit review timing. The network and information systems security policy and the risk assessment results and treatment plan must be reviewed at planned intervals, at least annually, and after significant incidents or significant changes to operations or risks. Practice-statement changes that might affect service acceptance require due notice, and the approved revision must then be made available.

  • Connect the practice statement, network and information systems security policy, asset inventory, operating procedures, and terms and conditions instead of maintaining them as disconnected files.
  • Document the maximum interval between configuration checks in the .
  • Use the annual review, significant incidents, significant operational or risk changes, service-provision changes, security-impacting changes, and practice-statement changes as update triggers.
  • Keep records accessible for an appropriate period to support legal evidence and service continuity, including after TSP activities cease where applicable.
Citations
ETSI EN 319 401 V3.2.1 (2026-01)

Clauses 5 and 6.3 define the current risk, network and information systems security policy, approval, content, review, change-notice, and configuration-check documentation requirements.

Primary sources

References and citations

etsi.org
Referenced sections
  • Clauses 5 and 6.3 define the current risk, network and information systems security policy, approval, content, review, change-notice, and configuration-check documentation requirements.
"at planned intervals and at least annually"
Related guides

Explore more topics

CA and RA responsibilities under ETSI EN 319 401
How ETSI EN 319 401 frames CA and RA responsibility: TSP practice statements, management approval, role segregation, subcontractor control, and evidence boundaries.
eIDAS Articles 19 and 24: current ETSI mapping
Understand why old EN 319 401 editions mapped eIDAS Article 19, what replaced it, and how V3.2.1 maps current Article 24 duties.
ETSI EN 319 401 Audit and Conformity Assessment Evidence
How to prepare ETSI EN 319 401 evidence for audit and conformity assessment without overstating what the standard itself assesses.
ETSI EN 319 401 Audit Evidence Pack
Build an ETSI EN 319 401 audit evidence pack around records, logs, policies, risk assessment, incident handling, continuity, and supplier evidence.
ETSI EN 319 401 Audit Evidence Pack Workflow
Build an ETSI EN 319 401 audit evidence pack for trust service providers: risk assessment, practice statement, policies, records, logs, continuity, and supplier evidence.
ETSI EN 319 401 compliance duties for TSPs
ETSI EN 319 401 compliance guidance for trust service providers covering legal operation, evidence, accessibility, privacy, records, incidents, continuity, and suppliers.
ETSI EN 319 401 conformity assessment bodies: what is covered?
Understand what ETSI EN 319 401 says, and does not say, about conformity assessment bodies, independent assessment, and TSP evidence preparation.
ETSI EN 319 401 FAQ for trust service providers
Plain-language ETSI EN 319 401 answers covering TSP scope, trust service practice statements, risk assessment, incidents, records, continuity, and supplier evidence.
ETSI EN 319 401 Incident and Continuity Workflow
Build an EN 319 401 incident and continuity evidence workflow for TSP monitoring, response, reporting, records, backup recovery, and crisis review.
ETSI EN 319 401 Incident Reporting and Continuity Duties
Practical ETSI EN 319 401 V3.1.1 guidance for trust service incident response, reporting, evidence retention, business continuity, and termination planning.
ETSI EN 319 401 Personnel, Asset, and Access Controls
Clause-focused EN 319 401 V3.1.1 guide to TSP personnel duties, trusted roles, asset inventories, classification, and access-control evidence.
ETSI EN 319 401 policy and security requirements
ETSI EN 319 401 guidance for TSP policy and security requirements covering risk assessment, practice statements, terms, security controls, incidents, and evidence.
ETSI EN 319 401 requirements map
Map ETSI EN 319 401 V3.1.1 requirements for trust service providers across risk assessment, policies, TSP operations, incidents, evidence, continuity, termination, and supply chain controls.
ETSI EN 319 401 Risk Assessment and Treatment
Clause-cited ETSI EN 319 401 V3.1.1 guidance for trust service risk assessment, risk treatment, residual-risk approval, and evidence planning.
ETSI EN 319 401 Subcontractor Controls
Practical EN 319 401 guidance for TSP subcontractor controls: retained responsibility, agreements, SLAs, supplier registers, monitoring, and audit evidence.
ETSI EN 319 401 Subcontractor Evidence Workflow
Build an EN 319 401 subcontractor evidence workflow for TSP supplier agreements, SLAs, audit mechanisms, risk reviews, supplier registers, and archived records.
ETSI EN 319 401 Subcontractor Requirements FAQ
How ETSI EN 319 401 treats subcontractors, outsourcing, supplier agreements, SLAs, monitoring, evidence, and retained TSP responsibility.
ETSI EN 319 401 Trust Service Applicability Workflow
A scoped workflow for deciding when ETSI EN 319 401 applies to a trust service and what TSP policy, risk, terms, operations, and supplier evidence to collect.
ETSI EN 319 401 Trust Service Provider Applicability
Use ETSI EN 319 401 to decide whether a trust service provider activity falls in the standard's type-independent baseline and what service, policy, risk, supplier, and evidence boundaries to document.
ETSI EN 319 401 vs eIDAS: Controls and Legal Duties
Compare ETSI EN 319 401 V3.2.1 with current eIDAS duties for qualified and non-qualified trust service providers, including risk, incidents, audits, records, and termination.
ETSI EN 319 401 vs EN 319 403-1: TSP Policy vs CAB Assessment
Compare ETSI EN 319 401 V3.2.1 provider controls with EN 319 403-1 V2.3.1 CAB requirements for audit scope, evidence, sampling, reports, corrective action, and reassessment.
Security Incidents in ETSI EN 319 401
How ETSI EN 319 401 V3.2.1 expects TSPs to detect, classify, respond to, report, document, test, and review security incidents.
Trust service provider scope under ETSI EN 319 401
How to scope ETSI EN 319 401 for a trust service provider: service boundaries, trust service policy, practice statement, terms, risks, and third-party components.