What does EN 319 401 cover for TSP scope?
ETSI EN 319 401 V3.2.1 specifies policy requirements for Trust Service Providers that are independent of the type of TSP. It covers management and operating practices, including cybersecurity requirements intended to support NIS2. It is not the complete rulebook for a certificate, time-stamp, validation, preservation, electronic archiving, electronic ledger, or other specific trust service.
Start with a service inventory. For each service, name the provider entity, service policy, users and relying parties, delivery systems, information flows, locations, trusted roles, external organizations, and service components. Mark anything shared across services so a control or supplier failure is not assigned to only one scope.
- Identify the provider entity and each trust service in scope; EN 319 401 defines a TSP as an entity that provides one or more trust services.
- Treat EN 319 401 as the general policy layer for TSP operation, management, security, risk, continuity, incident handling, evidence, and supply-chain controls.
- Record which service-specific ETSI standards, laws, assessment-scheme rules, certificate or trust service policies, and customer commitments refine the baseline.
- Document exclusions and interfaces. An excluded system, location, or supplier still needs an owner when it exchanges information with, administers, monitors, backs up, or can disrupt an in-scope trust service.
Clause 1 defines EN 319 401 as the service-independent baseline for TSP operation and management and says other specifications refine it for particular TSP forms.