ETSI EN 319 411 1 Certificate Issuance Guide
ETSI EN 319 411-1 V1.5.1 is the European standard for generally applicable policy and security requirements for trust service providers (TSPs) issuing public-key certificates, including trusted website certificates. It covers policy documentation, registration, issuance, revocation, status services, keys, and retained evidence.
Follow the grouped path from policy and role scope to registration, certificate lifecycle, revocation, -key evidence, and assessment preparation. Account separately for short-term and validity-assured certificate exceptions. Conformity with this standard alone does not establish qualified status, browser trust, legal compliance, or a completed conformity assessment.
Choose the policy profile and service boundary first. NCP+ and EVCP build on NCP; DVCP, OVCP, and IVCP build on LCP; and the web-certificate profiles also depend on the applicable live /Browser Forum requirements. V1.5.1 cites ETSI EN 319 401 without a version, so its clause 2.1 rule for non-specific references makes the latest EN 319 401 edition applicable; record the editions and assessment date used. The retains overall responsibility even when a CA component, registration authority (), or another provider performs part of the service.
Choose the next certificate-service decision
New to the standard? Establish the policy profile, service boundary, and participant roles first. If scope is already documented, jump to registration, lifecycle operations, evidence, or a focused comparison.
Start here: policy, service, and role scope
Select the certificate policy and its inherited requirements, distinguish the responsible TSP from CA and delegated RA functions, identify subscribers, subjects, and relying parties, and connect policy commitments to operating practices.
Registration, identity, and delegated RA work
Map who validates subscriber and subject information, how authority and proof of possession are checked, what an RA may perform, and which records the responsible TSP retains.
Certificate lifecycle and status operations
Trace applications through issuance, acceptance, renewal, re-key, modification, revocation or suspension, status information, and protected CA-key operation, including the standard's short-term and validity-assured certificate branches.
Evidence and assessment preparation
Build a traceable assessment file while keeping internal evidence preparation separate from independent conformity assessment, legal compliance, qualified status, and browser root-program acceptance.
Compare requirements or answer a focused question
Separate Part 1 from the qualified-certificate requirements in Part 2, identify live CA/Browser Forum dependencies for publicly trusted TLS certificates, or open the FAQ for a specific operational question.
Turn ETSI EN 319 411 1 certificate requirements into an assessment workflow
The ETSI EN 319 411 1 guide is the shared starting point for / review, subscriber registration evidence, certificate lifecycle controls, and operating controls, revocation status services, and audit-file preparation.
- Assign , , repository, registration, revocation, status-service, -key, and archival requirements to accountable owners.
- Use Assessment Autopilot to request the records that support identity validation, certificate issuance, revocation decisions, audit logging, and records archival.
- Use Research Copilot to compare ETSI EN 319 411-1 with related ETSI certificate standards and external certificate-program requirements before changing policy text.
- Move from clause reading to a reviewable assessment file without mixing general Part 1 requirements with qualified-certificate requirements from Part 2.