What does EN 319 401 require when a TSP uses subcontractors?
EN 319 401 V3.2.1 treats , outsourcing, cloud use, and other third-party arrangements as part of the controlled supply chain. When another party, including a trust service component provider, supplies part of the service, the TSP keeps overall responsibility for the supply-chain policy, its network and information systems security policy, and the trust service policy requirements.
Supplier control extends beyond onboarding. The TSP should identify which part of the trust service the outside party performs, record the TSP-owned policy requirements that apply, and keep evidence of the documented responsibilities.
- Map each subcontracted or outsourced activity to the affected trust service, component, policy, system, information flow, and evidence owner.
- Keep the TSP as the accountable owner for conformance even when a subcontractor or trust service component provider performs part of the service.
- Use the trust service practice statement to identify obligations of external organizations supporting the TSP's services.
- Require staff and, where applicable, subcontractors to have suitable expertise, reliability, experience, qualifications, and relevant cybersecurity and personal data protection training.
Supports retained TSP responsibility for subcontracting and outsourcing arrangements, external organization obligations in the practice statement, and subcontractor competence expectations.