ETSI EN 319 411 1Free Resource

ETSI EN 319 411 1 Certificate Issuance Guide

ETSI EN 319 411-1 V1.5.1 is the European standard for generally applicable policy and security requirements for trust service providers (TSPs) issuing public-key certificates, including trusted website certificates. It covers policy documentation, registration, issuance, revocation, status services, keys, and retained evidence.

Based on ETSI EN 319 411-1V1.5.1 (2025-04)Covers CP, CPS, RA, CA, CRL, and OCSP
Quick scan
Artifact
ETSI EN 319 411-1 requirements
Clause-oriented overview for certificate-issuing trust service providers.
CP and CPS template
Planning structure for policy identifiers, PKI participants, certificate usage, and disclosure material.
Certificate lifecycle workflow
Operational path from certificate application through issuance, and status services, revocation, and archival records.

Follow the grouped path from policy and role scope to registration, certificate lifecycle, revocation, -key evidence, and assessment preparation. Account separately for short-term and validity-assured certificate exceptions. Conformity with this standard alone does not establish qualified status, browser trust, legal compliance, or a completed conformity assessment.

Key dates
15
Topics
8
FAQs
2
Comparisons
V1.5.1
Edition
Where to start in ETSI EN 319 411-1
ETSI EN 319 411-1 requirements
Select LCP, NCP, NCP+, DVCP, OVCP, IVCP, EVCP, or a clause 7 policy, then map unmarked, conditional, choice-based, profile-marked, and web requirements.
CP and CPS structure
Separate the Certificate Policy rules from the Certification Practice Statement that describes how the issues, manages, revokes, renews, and re-keys certificates.
ETSI EN 319 411-1 certificate lifecycle workflow
Trace certificate application, processing, issuance, acceptance, usage, renewal, re-key, modification, revocation, suspension, and status-service obligations.
CP/CPS
Identity validation
Revocation status
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Mar 4, 2026
Updated
Jul 16, 2026

Choose the policy profile and service boundary first. NCP+ and EVCP build on NCP; DVCP, OVCP, and IVCP build on LCP; and the web-certificate profiles also depend on the applicable live /Browser Forum requirements. V1.5.1 cites ETSI EN 319 401 without a version, so its clause 2.1 rule for non-specific references makes the latest EN 319 401 edition applicable; record the editions and assessment date used. The retains overall responsibility even when a CA component, registration authority (), or another provider performs part of the service.

Recommended reading path

Choose the next certificate-service decision

New to the standard? Establish the policy profile, service boundary, and participant roles first. If scope is already documented, jump to registration, lifecycle operations, evidence, or a focused comparison.

1

Start here: policy, service, and role scope

Select the certificate policy and its inherited requirements, distinguish the responsible TSP from CA and delegated RA functions, identify subscribers, subjects, and relying parties, and connect policy commitments to operating practices.

2

Registration, identity, and delegated RA work

Map who validates subscriber and subject information, how authority and proof of possession are checked, what an RA may perform, and which records the responsible TSP retains.

3

Certificate lifecycle and status operations

Trace applications through issuance, acceptance, renewal, re-key, modification, revocation or suspension, status information, and protected CA-key operation, including the standard's short-term and validity-assured certificate branches.

4

Evidence and assessment preparation

Build a traceable assessment file while keeping internal evidence preparation separate from independent conformity assessment, legal compliance, qualified status, and browser root-program acceptance.

5

Compare requirements or answer a focused question

Separate Part 1 from the qualified-certificate requirements in Part 2, identify live CA/Browser Forum dependencies for publicly trusted TLS certificates, or open the FAQ for a specific operational question.

Next step

Turn ETSI EN 319 411 1 certificate requirements into an assessment workflow

The ETSI EN 319 411 1 guide is the shared starting point for / review, subscriber registration evidence, certificate lifecycle controls, and operating controls, revocation status services, and audit-file preparation.

What this unlocks
  • Assign , , repository, registration, revocation, status-service, -key, and archival requirements to accountable owners.
  • Use Assessment Autopilot to request the records that support identity validation, certificate issuance, revocation decisions, audit logging, and records archival.
  • Use Research Copilot to compare ETSI EN 319 411-1 with related ETSI certificate standards and external certificate-program requirements before changing policy text.
  • Move from clause reading to a reviewable assessment file without mixing general Part 1 requirements with qualified-certificate requirements from Part 2.