Artifact GuideGLOBALETSI EN 319 401

ETSI EN 319 401 Trust service provider scope under ETSI EN 319 401

Decide which trust services, systems, suppliers, policies, records, and operating activities belong in an ETSI EN 319 401 scope.

Based on ETSI EN 319 401 V3.2.1 (2026-01). Service-specific standards, applicable law, and the assessment scheme can add requirements beyond this general TSP baseline.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
1

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

ETSI EN 319 401 V3.2.1 is the general management and operations baseline for a (TSP). Scope it around each trust service the provider actually supplies, the systems and information that support it, the applicable , the practice statement and terms, and every supplier or component provider involved. Then add the service-specific standard, legal duties, and assessment-scheme rules that apply to that service.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What does EN 319 401 cover for TSP scope?

ETSI EN 319 401 V3.2.1 specifies policy requirements for Trust Service Providers that are independent of the type of TSP. It covers management and operating practices, including cybersecurity requirements intended to support NIS2. It is not the complete rulebook for a certificate, time-stamp, validation, preservation, electronic archiving, electronic ledger, or other specific trust service.

Start with a service inventory. For each service, name the provider entity, service policy, users and relying parties, delivery systems, information flows, locations, trusted roles, external organizations, and service components. Mark anything shared across services so a control or supplier failure is not assigned to only one scope.

  • Identify the provider entity and each trust service in scope; EN 319 401 defines a TSP as an entity that provides one or more trust services.
  • Treat EN 319 401 as the general policy layer for TSP operation, management, security, risk, continuity, incident handling, evidence, and supply-chain controls.
  • Record which service-specific ETSI standards, laws, assessment-scheme rules, certificate or trust service policies, and customer commitments refine the baseline.
  • Document exclusions and interfaces. An excluded system, location, or supplier still needs an owner when it exchanges information with, administers, monitors, backs up, or can disrupt an in-scope trust service.
Citations
ETSI EN 319 401 V3.2.1 (2026-01)

Clause 1 defines EN 319 401 as the service-independent baseline for TSP operation and management and says other specifications refine it for particular TSP forms.

Question 2

What documents should show the scope?

A generic statement that a provider follows EN 319 401 does not define scope. Clause 6 requires policies and practices appropriate to the services provided, a practice statement addressing the applicable , and relevant documentation for subscribers and relying parties where needed to demonstrate conformance. Sensitive details need not be disclosed in the available version.

The terms and conditions carry a second scope record. For each supported , they must cover the policy applied, use limits, subscriber obligations, relying-party information, event-log retention, liability limits, applicable legal system, complaints and disputes, assessment status and scheme if assessed, contact information, and availability undertakings.

  • Use the to explain the community, application class, or common security requirements the service is intended to serve.
  • Use the TSP practice statement to describe the practices and procedures used to meet the applicable .
  • Use terms and conditions to disclose service limitations and relying-party information before the subscriber enters a contractual relationship.
Citations
ETSI EN 319 401 V3.2.1 (2026-01)

Clauses 6.1 and 6.2 specify the practice-statement, disclosure, change-notice, and terms-and-conditions requirements that make the service scope reviewable.

Question 3

What scope questions should teams answer before claiming coverage?

A scope review should show which services are provided, which assets and suppliers support them, which risks were assessed, which policies and practice statements were approved, which records are retained, and who owns each boundary. V3.2.1 requires the risk assessment and treatment plan to be reviewed at planned intervals, at least annually, and after significant incidents or significant changes to operations or risks.

Do not use EN 319 401 alone to claim that a service passed an independent assessment. The standard does not define the assessment method, assessor information, or assessor requirements. It points to ETSI EN 319 403-1 for conformity assessment body requirements; the actual assessment scope and scheme still control the conclusion.

  • List the in-scope trust services and the applicable for each one.
  • Confirm management approval for the risk framework and residual risk, approval authority for the practice statement, and named owners and dates for risk treatment measures.
  • Identify external organizations supporting the service and document their obligations in the practice statement.
  • For subcontracting, outsourcing, cloud use, or other third-party arrangements, record how the TSP maintains overall responsibility for the supply chain policy, information security policy, and applicable requirements.
Citations
Primary sources

References and citations

etsi.org
Referenced sections
  • Clauses 5, 7.14, and 1 support the risk ownership, supplier boundary, retained TSP responsibility, and assessment-scope cautions.
"maintain overall responsibility for conformance"
Related guides

Explore more topics

CA and RA responsibilities under ETSI EN 319 401
How ETSI EN 319 401 frames CA and RA responsibility: TSP practice statements, management approval, role segregation, subcontractor control, and evidence boundaries.
eIDAS Articles 19 and 24: current ETSI mapping
Understand why old EN 319 401 editions mapped eIDAS Article 19, what replaced it, and how V3.2.1 maps current Article 24 duties.
ETSI EN 319 401 Audit and Conformity Assessment Evidence
How to prepare ETSI EN 319 401 evidence for audit and conformity assessment without overstating what the standard itself assesses.
ETSI EN 319 401 Audit Evidence Pack
Build an ETSI EN 319 401 audit evidence pack around records, logs, policies, risk assessment, incident handling, continuity, and supplier evidence.
ETSI EN 319 401 Audit Evidence Pack Workflow
Build an ETSI EN 319 401 audit evidence pack for trust service providers: risk assessment, practice statement, policies, records, logs, continuity, and supplier evidence.
ETSI EN 319 401 compliance duties for TSPs
ETSI EN 319 401 compliance guidance for trust service providers covering legal operation, evidence, accessibility, privacy, records, incidents, continuity, and suppliers.
ETSI EN 319 401 conformity assessment bodies: what is covered?
Understand what ETSI EN 319 401 says, and does not say, about conformity assessment bodies, independent assessment, and TSP evidence preparation.
ETSI EN 319 401 FAQ for trust service providers
Plain-language ETSI EN 319 401 answers covering TSP scope, trust service practice statements, risk assessment, incidents, records, continuity, and supplier evidence.
ETSI EN 319 401 Incident and Continuity Workflow
Build an EN 319 401 incident and continuity evidence workflow for TSP monitoring, response, reporting, records, backup recovery, and crisis review.
ETSI EN 319 401 Incident Reporting and Continuity Duties
Practical ETSI EN 319 401 V3.1.1 guidance for trust service incident response, reporting, evidence retention, business continuity, and termination planning.
ETSI EN 319 401 Personnel, Asset, and Access Controls
Clause-focused EN 319 401 V3.1.1 guide to TSP personnel duties, trusted roles, asset inventories, classification, and access-control evidence.
ETSI EN 319 401 policy and security requirements
ETSI EN 319 401 guidance for TSP policy and security requirements covering risk assessment, practice statements, terms, security controls, incidents, and evidence.
ETSI EN 319 401 policy documentation: what is required?
How ETSI EN 319 401 treats practice statements, terms, network and information systems security policy, evidence records, and change review.
ETSI EN 319 401 requirements map
Map ETSI EN 319 401 V3.1.1 requirements for trust service providers across risk assessment, policies, TSP operations, incidents, evidence, continuity, termination, and supply chain controls.
ETSI EN 319 401 Risk Assessment and Treatment
Clause-cited ETSI EN 319 401 V3.1.1 guidance for trust service risk assessment, risk treatment, residual-risk approval, and evidence planning.
ETSI EN 319 401 Subcontractor Controls
Practical EN 319 401 guidance for TSP subcontractor controls: retained responsibility, agreements, SLAs, supplier registers, monitoring, and audit evidence.
ETSI EN 319 401 Subcontractor Evidence Workflow
Build an EN 319 401 subcontractor evidence workflow for TSP supplier agreements, SLAs, audit mechanisms, risk reviews, supplier registers, and archived records.
ETSI EN 319 401 Subcontractor Requirements FAQ
How ETSI EN 319 401 treats subcontractors, outsourcing, supplier agreements, SLAs, monitoring, evidence, and retained TSP responsibility.
ETSI EN 319 401 Trust Service Applicability Workflow
A scoped workflow for deciding when ETSI EN 319 401 applies to a trust service and what TSP policy, risk, terms, operations, and supplier evidence to collect.
ETSI EN 319 401 Trust Service Provider Applicability
Use ETSI EN 319 401 to decide whether a trust service provider activity falls in the standard's type-independent baseline and what service, policy, risk, supplier, and evidence boundaries to document.
ETSI EN 319 401 vs eIDAS: Controls and Legal Duties
Compare ETSI EN 319 401 V3.2.1 with current eIDAS duties for qualified and non-qualified trust service providers, including risk, incidents, audits, records, and termination.
ETSI EN 319 401 vs EN 319 403-1: TSP Policy vs CAB Assessment
Compare ETSI EN 319 401 V3.2.1 provider controls with EN 319 403-1 V2.3.1 CAB requirements for audit scope, evidence, sampling, reports, corrective action, and reassessment.
Security Incidents in ETSI EN 319 401
How ETSI EN 319 401 V3.2.1 expects TSPs to detect, classify, respond to, report, document, test, and review security incidents.