Artifact GuideGLOBALETSI EN 319 401

ETSI EN 319 401 Subcontractor Controls

A focused control guide for trust service providers using subcontractors, outsourcers, direct suppliers, service providers, or trust service component providers.

This page maps V3.1.1. ETSI published V3.2.1 in January 2026, so confirm the required edition and use this as control guidance, not a legal or qualified-status conclusion.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
6

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use this page when another party provides part of a trust service. ETSI EN 319 401 V3.1.1 keeps overall responsibility with the and requires documented obligations, supplier agreements, risk-aligned security requirements, monitoring, and current supplier records. ETSI published V3.2.1 in January 2026, so record the edition that governs the arrangement.

Section 1

Start with retained TSP responsibility

The first control decision is whether the outside party provides any part of the trust service through subcontracting, outsourcing, or another third-party arrangement. If it does, EN 319 401 clause 7.14.3 keeps overall responsibility with the for conformance with the , information security policy, and trust service policy requirements.

The subcontractor file is assurance evidence as well as procurement paperwork. It should name the outsourced service part, affected trust service policy requirements, supplier-owned activities, -owned controls, and evidence that those controls were communicated and monitored.

  • List each subcontracted or outsourced activity that supports the trust service, including providers where relevant.
  • Map each activity to the affected trust service, system, information flow, policy requirement, and internal accountable owner.
  • Keep the , not the supplier, as the owner of conformance evidence for EN 319 401 and the trust service policy.
  • Use the trust service practice statement to identify obligations of external organizations supporting the 's services.
Section 2

Convert supplier selection into control evidence

EN 319 401 treats supplier selection as a security control. Clause 7.14 requires processes for security risks associated with supplier products and services, and the has to define criteria for selecting and contracting suppliers or service providers.

A complete supplier-selection record covers more than the vendor name. V3.1.1 requires criteria addressing the supplier's ability to meet the cybersecurity specifications, risks, and classification levels of the affected services, systems, or products; the TSP's ability to diversify supply and limit vendor lock-in; and coordinated security risk assessment results for critical supply chains.

  • Keep the supplier-selection record with the trust service scope it supports and the security requirements assigned to it.
  • Show how the supplier or service provider was evaluated against cybersecurity specifications, risk, classification levels, supply diversification, vendor lock-in, and critical-supply-chain risk results.
  • Where an ICT service supplier subcontracts part of the service, require propagation of the security requirements through that supply chain.
  • Where ICT products include components from other suppliers, require appropriate security practices to propagate through the chain and request information about software components, security functions, and secure configuration.
  • For critical components, retain origin traceability, evidence that delivered products function as expected without unwanted features, and assurance that components are genuine and unaltered.
Section 3

Make agreements specific enough to audit

When service provisioning involves subcontracting, outsourcing, or other third-party arrangements, EN 319 401 calls for a documented agreement and contractual relationship so both parties understand their obligations to fulfil relevant information security requirements.

The agreement evidence should connect directly to the 's risk assessment and policies. It should define the outsourcer's liability, bind the outsourcer to implement controls required by the TSP at service commencement and termination, include applicable TSP security policies and requirements in contracts with direct suppliers or service providers, and use and/or auditing mechanisms for direct suppliers and service providers, including cloud providers.

  • Keep signed agreements with a short control map showing the relevant EN 319 401 requirement IDs, policy clauses, and supplier obligations.
  • Define outsourcer liability and the controls the outsourcer is bound to implement for the .
  • Include applicable security policies and requirements in supplier or service-provider contracts.
  • Use SLAs and/or auditing mechanisms to check that direct suppliers and service providers address security requirements aligned with the TSP risk assessment.
  • For cloud services, define and communicate a topic-specific cloud policy and document the shared information-security responsibilities between the provider and the .
Section 4

Monitor changes instead of relying on onboarding

Subcontractor approval should not be treated as permanent. EN 319 401 requires planned or incident-triggered review of the and changes in the cybersecurity practices of direct suppliers or service providers related to the provision of services.

The standard also expects a register of suppliers and agreements that tracks where information is managed or archived. That register should be regularly reviewed, validated, and updated so agreements remain valid, fit for purpose, and include the relevant information security clauses.

  • Define planned review intervals for direct supplier and service-provider cybersecurity practices.
  • Trigger review after an incident related to services provided by a direct supplier or service provider.
  • Maintain a supplier-and-agreement register showing where information is managed or archived.
  • Regularly validate that supplier agreements remain current, fit for purpose, and include relevant information security clauses.
Section 5

Checklist for a subcontractor controls evidence pack

A useful evidence pack should let an assessor, security reviewer, procurement lead, or product owner understand the outsourced boundary without interviewing the whole team. It should show what the outside party does, why the still owns conformance, what controls are contractually required, how those controls are checked, and which event or planned interval triggers another review.

Also include the adjacent EN 319 401 controls that can affect subcontractors: staff and subcontractor competence, contractor incident reporting procedures, return of assets when external personnel or third parties change or terminate, and termination of subcontractor authorization before the TSP terminates services where subcontractors act for functions related to issuing trust service tokens.

  • Scope map: subcontracted activity, , affected policy requirements, systems, information, and owner.
  • Agreement pack: signed agreement, outsourcer liability, required controls, applicable security policy clauses, SLA or audit mechanism, and termination terms.
  • Monitoring pack: review cadence, supplier change reviews, incident-triggered reviews, audit results or SLA evidence, and exception decisions.
  • Register evidence: current supplier-and-agreement register, locations where information is managed or archived, and validation history.
  • Lifecycle evidence: competence checks for subcontractors where applicable, contractor incident reporting communication, asset return procedures, and service-termination authorization controls.
Section 6

Common mistakes to avoid

The common failure pattern is treating the supplier as outside the trust service boundary. Under EN 319 401, if the supplier provides part of the service or manages relevant information, the subcontractor controls need to be visible in the TSP's policies, agreements, monitoring, and evidence records.

Another weak pattern is citing a generic security questionnaire without connecting it to EN 319 401. A defensible review names the supplier arrangement, the applicable policies, the trust service policy requirements, the risk assessment connection, the agreement clauses, and the evidence that the arrangement is still current.

  • Do not describe subcontracting as a transfer of EN 319 401 responsibility away from the .
  • Do not rely on a generic vendor approval when the outsourced activity affects a or information.
  • Do not keep supplier agreements separate from the supplier register, policy requirements, SLA or audit evidence, and review history.
  • Do not leave subcontractor incident reporting, asset return, or service-termination authorization controls out of the evidence pack when those controls apply.
Primary sources

References and citations

etsi.org
Referenced sections
  • Supports these pitfalls by requiring retained responsibility, documented supplier obligations, supplier registers, planned or incident-triggered review, and adjacent personnel, incident, asset, and termination controls.
"still valid, fit for purpose"
etsi.org
Referenced sections
  • Published successor edition used to establish the edition boundary for this V3.1.1 subcontractor-control guide.
Related guides

Explore more topics

CA and RA responsibilities under ETSI EN 319 401
How ETSI EN 319 401 frames CA and RA responsibility: TSP practice statements, management approval, role segregation, subcontractor control, and evidence boundaries.
eIDAS Articles 19 and 24: current ETSI mapping
Understand why old EN 319 401 editions mapped eIDAS Article 19, what replaced it, and how V3.2.1 maps current Article 24 duties.
ETSI EN 319 401 Audit and Conformity Assessment Evidence
How to prepare ETSI EN 319 401 evidence for audit and conformity assessment without overstating what the standard itself assesses.
ETSI EN 319 401 Audit Evidence Pack
Build an ETSI EN 319 401 audit evidence pack around records, logs, policies, risk assessment, incident handling, continuity, and supplier evidence.
ETSI EN 319 401 Audit Evidence Pack Workflow
Build an ETSI EN 319 401 audit evidence pack for trust service providers: risk assessment, practice statement, policies, records, logs, continuity, and supplier evidence.
ETSI EN 319 401 compliance duties for TSPs
ETSI EN 319 401 compliance guidance for trust service providers covering legal operation, evidence, accessibility, privacy, records, incidents, continuity, and suppliers.
ETSI EN 319 401 conformity assessment bodies: what is covered?
Understand what ETSI EN 319 401 says, and does not say, about conformity assessment bodies, independent assessment, and TSP evidence preparation.
ETSI EN 319 401 FAQ for trust service providers
Plain-language ETSI EN 319 401 answers covering TSP scope, trust service practice statements, risk assessment, incidents, records, continuity, and supplier evidence.
ETSI EN 319 401 Incident and Continuity Workflow
Build an EN 319 401 incident and continuity evidence workflow for TSP monitoring, response, reporting, records, backup recovery, and crisis review.
ETSI EN 319 401 Incident Reporting and Continuity Duties
Practical ETSI EN 319 401 V3.1.1 guidance for trust service incident response, reporting, evidence retention, business continuity, and termination planning.
ETSI EN 319 401 Personnel, Asset, and Access Controls
Clause-focused EN 319 401 V3.1.1 guide to TSP personnel duties, trusted roles, asset inventories, classification, and access-control evidence.
ETSI EN 319 401 policy and security requirements
ETSI EN 319 401 guidance for TSP policy and security requirements covering risk assessment, practice statements, terms, security controls, incidents, and evidence.
ETSI EN 319 401 policy documentation: what is required?
How ETSI EN 319 401 treats practice statements, terms, network and information systems security policy, evidence records, and change review.
ETSI EN 319 401 requirements map
Map ETSI EN 319 401 V3.1.1 requirements for trust service providers across risk assessment, policies, TSP operations, incidents, evidence, continuity, termination, and supply chain controls.
ETSI EN 319 401 Risk Assessment and Treatment
Clause-cited ETSI EN 319 401 V3.1.1 guidance for trust service risk assessment, risk treatment, residual-risk approval, and evidence planning.
ETSI EN 319 401 Subcontractor Evidence Workflow
Build an EN 319 401 subcontractor evidence workflow for TSP supplier agreements, SLAs, audit mechanisms, risk reviews, supplier registers, and archived records.
ETSI EN 319 401 Subcontractor Requirements FAQ
How ETSI EN 319 401 treats subcontractors, outsourcing, supplier agreements, SLAs, monitoring, evidence, and retained TSP responsibility.
ETSI EN 319 401 Trust Service Applicability Workflow
A scoped workflow for deciding when ETSI EN 319 401 applies to a trust service and what TSP policy, risk, terms, operations, and supplier evidence to collect.
ETSI EN 319 401 Trust Service Provider Applicability
Use ETSI EN 319 401 to decide whether a trust service provider activity falls in the standard's type-independent baseline and what service, policy, risk, supplier, and evidence boundaries to document.
ETSI EN 319 401 vs eIDAS: Controls and Legal Duties
Compare ETSI EN 319 401 V3.2.1 with current eIDAS duties for qualified and non-qualified trust service providers, including risk, incidents, audits, records, and termination.
ETSI EN 319 401 vs EN 319 403-1: TSP Policy vs CAB Assessment
Compare ETSI EN 319 401 V3.2.1 provider controls with EN 319 403-1 V2.3.1 CAB requirements for audit scope, evidence, sampling, reports, corrective action, and reassessment.
Security Incidents in ETSI EN 319 401
How ETSI EN 319 401 V3.2.1 expects TSPs to detect, classify, respond to, report, document, test, and review security incidents.
Trust service provider scope under ETSI EN 319 401
How to scope ETSI EN 319 401 for a trust service provider: service boundaries, trust service policy, practice statement, terms, risks, and third-party components.