What does EN 319 401 require when a TSP uses subcontractors?
EN 319 401 treats subcontracting, outsourcing, and other third-party arrangements as part of the TSP's controlled supply chain. Clause 7.14.3 says that when other parties, including trust service component providers, provide parts of the service, the TSP maintains overall responsibility for conformance with the supply chain policy, information security policy, and trust service policy requirements.
That means the practical control is not just vendor onboarding. The TSP should identify which part of the trust service is performed by the outside party, record the TSP-owned policy requirements that apply, and keep evidence showing that the arrangement is governed by documented responsibilities rather than informal reliance on the supplier.
- Map each subcontracted or outsourced activity to the affected trust service, component, policy, system, information flow, and evidence owner.
- Keep the TSP as the accountable owner for conformance even when a subcontractor or trust service component provider performs part of the service.
- Use the trust service practice statement to identify obligations of external organizations supporting the TSP's services.
- Require staff and, where applicable, subcontractors to have suitable expertise, reliability, experience, qualifications, and relevant cybersecurity and personal data protection training.
Supports retained TSP responsibility for subcontracting and outsourcing arrangements, external organization obligations in the practice statement, and subcontractor competence expectations.