Artifact GuideGLOBALETSI EN 319 401

ETSI EN 319 401 How should teams handle subcontractors under ETSI EN 319 401

A focused FAQ for trust service teams deciding how subcontractors, outsourcers, direct suppliers, and trust service component providers should be controlled and evidenced.

Based on ETSI EN 319 401 V3.2.1 (2026-01). Applicable law, the trust service policy, service-specific standards, and the actual supplier role can add duties.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
1

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

A Trust Service Provider cannot transfer its EN 319 401 responsibility by or outsourcing part of a service. Under V3.2.1, the TSP keeps overall responsibility for conformance, must identify external obligations in its practice statement, control supply-chain risks, use documented agreements, monitor direct suppliers at least annually or after related incidents, and maintain current supplier registers.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What does EN 319 401 require when a TSP uses subcontractors?

EN 319 401 V3.2.1 treats , outsourcing, cloud use, and other third-party arrangements as part of the controlled supply chain. When another party, including a trust service component provider, supplies part of the service, the TSP keeps overall responsibility for the supply-chain policy, its network and information systems security policy, and the trust service policy requirements.

Supplier control extends beyond onboarding. The TSP should identify which part of the trust service the outside party performs, record the TSP-owned policy requirements that apply, and keep evidence of the documented responsibilities.

  • Map each subcontracted or outsourced activity to the affected trust service, component, policy, system, information flow, and evidence owner.
  • Keep the TSP as the accountable owner for conformance even when a subcontractor or trust service component provider performs part of the service.
  • Use the trust service practice statement to identify obligations of external organizations supporting the TSP's services.
  • Require staff and, where applicable, subcontractors to have suitable expertise, reliability, experience, qualifications, and relevant cybersecurity and personal data protection training.
Citations
ETSI EN 319 401 V3.2.1 (2026-01)

Supports retained TSP responsibility for subcontracting and outsourcing arrangements, external organization obligations in the practice statement, and subcontractor competence expectations.

Question 2

What should be in the subcontractor agreement evidence?

The agreement evidence should show that the supplier relationship is specific enough to enforce the TSP's information security requirements. EN 319 401 calls for documented agreements and contractual relationships when service provisioning involves , outsourcing, or other third-party arrangements, so both parties understand their obligations to fulfil relevant information security requirements.

Keep the signed agreement with a requirement map and evidence of supplier acceptance. V3.2.1 says contracts must address, where appropriate, cybersecurity requirements; staff awareness, skills, training, and certifications; background verification; prompt supplier notice of incidents that risk the TSP's systems; audit rights or audit reports; vulnerability handling; controls; and information retrieval or disposal at termination.

  • Document the service part or component the subcontractor provides and the trust service policy requirements it affects.
  • Define outsourcer liability and bind the outsourcer to implement controls required by the TSP.
  • Include applicable TSP security policies and requirements in contracts with direct suppliers or service providers.
  • Use service level agreements and/or auditing mechanisms to evidence that direct suppliers address TSP security requirements aligned with the TSP risk assessment.
  • Require approved subcontractors to receive cybersecurity requirements equivalent to those imposed on the direct supplier where the TSP permits further .
  • Set incident-notice, audit, vulnerability-handling, information-return or disposal, and contract-exit obligations where they are appropriate to the service and risk.
Citations
ETSI EN 319 401 V3.2.1 (2026-01)

Clause 7.14.3 supports documented agreements, liability, required controls, SLAs or audits, and the current contract-content requirements for incidents, audits, vulnerabilities, subcontracting, staff, and termination.

Question 3

How should teams keep subcontractor evidence current?

V3.2.1 requires the TSP to review its supply-chain policy and monitor, review, evaluate, and manage changes in direct-supplier cybersecurity practices at planned intervals, at least annually, or after an incident related to the supplier's services.

Maintain both views required by the standard: a register of suppliers and agreements showing where TSP information is managed or archived, and an up-to-date register of direct suppliers and service providers with contact points and the ICT products, services, and processes each provides. Review agreements for validity, fitness for purpose, and current security clauses. On TSP service termination, end subcontractor authority to act for trust-service-token issuance functions.

  • Maintain a register of suppliers and agreements showing where TSP information is managed or archived.
  • Review direct suppliers at least annually or after supplier-related incidents; document the result, decision, owner, and follow-up.
  • Review, validate, and update the supplier and agreement registers for current contacts, supplied ICT products, services and processes, information locations, validity, fitness for purpose, and security clauses.
  • Trigger reassessment after an incident related to a direct supplier's or service provider's provision of services.
  • Include subcontractor authorization termination in the TSP service termination plan when subcontractors act for functions related to issuing trust service tokens.
Citations
ETSI EN 319 401 V3.2.1 (2026-01)

Supports annual or incident-triggered monitoring, both supplier-register views, agreement review, and termination of subcontractor authorization before TSP service termination.

Primary sources

References and citations

etsi.org
Referenced sections
  • Supports annual or incident-triggered monitoring, both supplier-register views, agreement review, and termination of subcontractor authorization before TSP service termination.
"at planned intervals, at least annually"
Related guides

Explore more topics

CA and RA responsibilities under ETSI EN 319 401
How ETSI EN 319 401 frames CA and RA responsibility: TSP practice statements, management approval, role segregation, subcontractor control, and evidence boundaries.
eIDAS Articles 19 and 24: current ETSI mapping
Understand why old EN 319 401 editions mapped eIDAS Article 19, what replaced it, and how V3.2.1 maps current Article 24 duties.
ETSI EN 319 401 Audit and Conformity Assessment Evidence
How to prepare ETSI EN 319 401 evidence for audit and conformity assessment without overstating what the standard itself assesses.
ETSI EN 319 401 Audit Evidence Pack
Build an ETSI EN 319 401 audit evidence pack around records, logs, policies, risk assessment, incident handling, continuity, and supplier evidence.
ETSI EN 319 401 Audit Evidence Pack Workflow
Build an ETSI EN 319 401 audit evidence pack for trust service providers: risk assessment, practice statement, policies, records, logs, continuity, and supplier evidence.
ETSI EN 319 401 compliance duties for TSPs
ETSI EN 319 401 compliance guidance for trust service providers covering legal operation, evidence, accessibility, privacy, records, incidents, continuity, and suppliers.
ETSI EN 319 401 conformity assessment bodies: what is covered?
Understand what ETSI EN 319 401 says, and does not say, about conformity assessment bodies, independent assessment, and TSP evidence preparation.
ETSI EN 319 401 FAQ for trust service providers
Plain-language ETSI EN 319 401 answers covering TSP scope, trust service practice statements, risk assessment, incidents, records, continuity, and supplier evidence.
ETSI EN 319 401 Incident and Continuity Workflow
Build an EN 319 401 incident and continuity evidence workflow for TSP monitoring, response, reporting, records, backup recovery, and crisis review.
ETSI EN 319 401 Incident Reporting and Continuity Duties
Practical ETSI EN 319 401 V3.1.1 guidance for trust service incident response, reporting, evidence retention, business continuity, and termination planning.
ETSI EN 319 401 Personnel, Asset, and Access Controls
Clause-focused EN 319 401 V3.1.1 guide to TSP personnel duties, trusted roles, asset inventories, classification, and access-control evidence.
ETSI EN 319 401 policy and security requirements
ETSI EN 319 401 guidance for TSP policy and security requirements covering risk assessment, practice statements, terms, security controls, incidents, and evidence.
ETSI EN 319 401 policy documentation: what is required?
How ETSI EN 319 401 treats practice statements, terms, network and information systems security policy, evidence records, and change review.
ETSI EN 319 401 requirements map
Map ETSI EN 319 401 V3.1.1 requirements for trust service providers across risk assessment, policies, TSP operations, incidents, evidence, continuity, termination, and supply chain controls.
ETSI EN 319 401 Risk Assessment and Treatment
Clause-cited ETSI EN 319 401 V3.1.1 guidance for trust service risk assessment, risk treatment, residual-risk approval, and evidence planning.
ETSI EN 319 401 Subcontractor Controls
Practical EN 319 401 guidance for TSP subcontractor controls: retained responsibility, agreements, SLAs, supplier registers, monitoring, and audit evidence.
ETSI EN 319 401 Subcontractor Evidence Workflow
Build an EN 319 401 subcontractor evidence workflow for TSP supplier agreements, SLAs, audit mechanisms, risk reviews, supplier registers, and archived records.
ETSI EN 319 401 Trust Service Applicability Workflow
A scoped workflow for deciding when ETSI EN 319 401 applies to a trust service and what TSP policy, risk, terms, operations, and supplier evidence to collect.
ETSI EN 319 401 Trust Service Provider Applicability
Use ETSI EN 319 401 to decide whether a trust service provider activity falls in the standard's type-independent baseline and what service, policy, risk, supplier, and evidence boundaries to document.
ETSI EN 319 401 vs eIDAS: Controls and Legal Duties
Compare ETSI EN 319 401 V3.2.1 with current eIDAS duties for qualified and non-qualified trust service providers, including risk, incidents, audits, records, and termination.
ETSI EN 319 401 vs EN 319 403-1: TSP Policy vs CAB Assessment
Compare ETSI EN 319 401 V3.2.1 provider controls with EN 319 403-1 V2.3.1 CAB requirements for audit scope, evidence, sampling, reports, corrective action, and reassessment.
Security Incidents in ETSI EN 319 401
How ETSI EN 319 401 V3.2.1 expects TSPs to detect, classify, respond to, report, document, test, and review security incidents.
Trust service provider scope under ETSI EN 319 401
How to scope ETSI EN 319 401 for a trust service provider: service boundaries, trust service policy, practice statement, terms, risks, and third-party components.