ETSI EN 319 411 1Free Resource

ETSI EN 319 411 1 Certificate Issuance Guide

Use this ETSI EN 319 411-1 cluster to map the general certificate-issuing TSP requirements in V1.5.1 (2025-04): CP and CPS documentation, subscriber and subject identity validation, certificate application and issuance, renewal and re-key, revocation and suspension, and status services.

The topic pages focus on the clauses readers usually need to operationalize: repository duties, registration evidence, CA and RA responsibilities, audit logging, records archival, CA key controls, certificate profiles, CRL profiles, OCSP profiles, and assessment preparation.

ETSI EN 319 411-1 requirements
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Mar 4, 2026
Updated
Mar 4, 2026
Where to start in ETSI EN 319 411-1
ETSI EN 319 411-1 requirements
Start with the general policy and security requirement map for TSPs issuing certificates under Part 1.
CP and CPS structure
Separate the Certificate Policy rules from the Certification Practice Statement that describes how the CA issues, manages, revokes, renews, and re-keys certificates.
ETSI EN 319 411-1 certificate lifecycle workflow
Trace certificate application, processing, issuance, acceptance, usage, renewal, re-key, modification, revocation, suspension, and status-service obligations.
Grounded in ETSI EN 319 411-1V1.5.1 (2025-04)Covers CP, CPS, RA, CA, CRL, and OCSP
Quick scan
Artifact
ETSI EN 319 411-1 requirements
Clause-oriented overview for certificate-issuing trust service providers.
CP and CPS template
Planning structure for policy identifiers, PKI participants, certificate usage, and disclosure material.
Certificate lifecycle workflow
Operational path from certificate application through issuance, status services, revocation, and archival records.
Use the cluster as a reader-friendly index to the certificate policy, registration, lifecycle, revocation, status-service, audit, and archival topics in ETSI EN 319 411-1.
13
Topics
8
FAQs
2
Comparisons
V1.5.1
Edition
CP/CPS
Identity validation
Revocation status

Topic guides

Deep dive pages for implementation planning, controls, reporting, and evidence.

1
EN 319 411-1 vs EN 319 411-2 Certificate Policy
Compare ETSI EN 319 411-1 general certificate-service requirements with EN 319 411-2 EU qualified certificate requirements, including policy scope, CP/CPS evidence, and audit boundaries.
Read Guide
2
ETSI EN 319 411-1 Audit File Evidence
Build an ETSI EN 319 411-1 audit evidence file for CA logging, registration records, revocation records, CA key lifecycle evidence, and records archival.
Read Guide
3
ETSI EN 319 411-1 CA Key Management
CA key management guidance for ETSI EN 319 411-1: CPS commitments, key ceremonies, secure cryptographic devices, backup, recovery, and lifecycle evidence.
Read Guide
4
ETSI EN 319 411-1 certificate lifecycle workflow
Workflow for EN 319 411-1 certificate application, issuance, acceptance, renewal, re-key, modification, revocation, suspension, status services, and evidence records.
Read Guide
5
ETSI EN 319 411-1 Compliance Guide
Build an ETSI EN 319 411-1 compliance file for certificate policies, CPS commitments, certificate lifecycle controls, revocation services, CA keys, and audit evidence.
Read Guide
6
ETSI EN 319 411-1 CP and CPS template
Build a certificate policy and Certification Practice Statement template for ETSI EN 319 411-1 certificate services, with fields for policy identifiers, subscribers, relying parties, revocation, publication, and evidence.
Read Guide
7
ETSI EN 319 411-1 FAQ for Certificate Services
Answers to common ETSI EN 319 411-1 questions on certificate policies, CPS content, CA and RA boundaries, subscriber evidence, revocation, status services, and record retention.
Read Guide
8
ETSI EN 319 411-1 Identity Validation
Identity validation requirements in ETSI EN 319 411-1 for subscribers, subjects, RAs, certificate requests, registration evidence, and issuance records.
Read Guide
9
ETSI EN 319 411-1 Identity Validation Evidence Workflow
A workflow for building ETSI EN 319 411-1 identity validation evidence packs across subscriber, subject, certificate request, RA, logging, and retention controls.
Read Guide
10
ETSI EN 319 411-1 RA Delegation Guide
How to scope registration authority delegation under ETSI EN 319 411-1, including delegated RA tasks, external provider controls, registration records, and audit evidence.
Read Guide
11
ETSI EN 319 411-1 RA Delegation Review Workflow
Review delegated registration authority work under ETSI EN 319 411-1: retained CA responsibility, recognized registration service providers, secure data exchange, CPS coverage, and audit evidence.
Read Guide
12
ETSI EN 319 411-1 requirements map for certificate services
Map ETSI EN 319 411-1 requirements for certificate policies, CP/CPS content, registration, revocation, certificate status, and CA key-management evidence.
Read Guide
13
ETSI EN 319 411-1 Revocation Evidence Workflow
Build a revocation evidence workflow for ETSI EN 319 411-1 covering CPS procedures, request authentication, 24-hour status updates, CRL/OCSP publication, logs, and retention.
Read Guide
14
ETSI EN 319 411-1 Revocation, OCSP, and CRL Operations
Operate ETSI EN 319 411-1 revocation status services with CPS procedures, authenticated requests, 24-hour CRL or OCSP publication controls, and audit evidence.
Read Guide
15
ETSI EN 319 411-1 vs CA/B Forum Baseline Requirements
Compare how EN 319 411-1 incorporates CA/B Forum BRG concepts for DVCP, OVCP, IVCP, [WEB] requirements, CPS disclosure, domain validation, and conflict handling.
Read Guide
Next step

Turn ETSI EN 319 411 1 certificate requirements into an assessment workflow

Use the ETSI EN 319 411 1 guide as the shared starting point for CP/CPS review, subscriber registration evidence, certificate lifecycle controls, CA and RA operating controls, revocation status services, and audit-file preparation.

What this unlocks
  • Assign CP, CPS, repository, registration, revocation, status-service, CA-key, and archival requirements to accountable owners.
  • Use Assessment Autopilot to request the records that support identity validation, certificate issuance, revocation decisions, audit logging, and records archival.
  • Use Research Copilot to compare ETSI EN 319 411-1 with related ETSI certificate standards and external certificate-program requirements before changing policy text.
  • Move from clause reading to a reviewable assessment file without mixing general Part 1 requirements with qualified-certificate requirements from Part 2.