Artifact GuideGLOBALETSI EN 319 411-1

ETSI EN 319 411-1 CP and CPS template

A field-by-field template for separating Certificate Policy commitments from Certification Practice Statement implementation details under ETSI EN 319 411-1.

Use it to draft public-facing certificate-service documentation and the internal evidence map that supports it.

Author
Sorena AI
Published
May 9, 2026
Updated
May 9, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated May 9, 2026
Overview

ETSI EN 319 411-1 treats the Certificate Policy (CP) and Certification Practice Statement (CPS) as connected but different documents. The CP states what certificate policy, quality, applicability, profile, and rules apply. The CPS states how the Trust Service Provider operates its certificate service to meet those rules. This template helps CA teams draft both documents without mixing public disclosures with confidential operating procedures.

Section 1

Template header: identify the certificate policy

Start the template with the policy identity, not with generic compliance language. EN 319 411-1 explains that certificate policy identification is communicated through subscriber and relying-party documentation, and certificates can include a CP identifier that relying parties use to assess suitability and trustworthiness.

Use these fields at the top of the CP and mirror them in the CPS traceability table: Field | Fill with | Evidence. Policy name | LCP, NCP, NCP+, DVCP, OVCP, IVCP, EVCP, or custom policy | approved CP document. Policy OID | object identifier used in certificates | certificate profile and issuance record. Certificate type | natural person, legal person, website, device, or other subject class | certificate profile reference. Intended use | permitted certificate usage and relying-party audience | subscriber terms and PKI disclosure statement.

  • State whether the CP uses one of the EN 319 411-1 reference policies or a custom policy defined under clause 7.
  • Record the policy OID, certificate profile, subject class, certificate usage limits, and whether the certificates are issued to the public.
  • Identify the policy authority or approving body for the CP, especially when the policy extends or constrains an EN 319 411-1 reference policy.
  • Keep the CPS version, effective date, approval record, publication location, and confidential-procedure references separate from the CP identifier.
Section 2

Certificate Policy fields: state what applies

The CP section should read like a policy promise that subscribers and relying parties can understand. It should not describe every internal CA procedure. EN 319 411-1 describes a CP as the document that defines certificate quality, applicability, profile, and the common rules for a certificate community.

Use this CP table as the core template: Field | Fill with | Evidence. Applicability | who can receive certificates and which applications may rely on them | policy approval record. Certificate profile | X.509 profile requirements and ETSI EN 319 412 part used where appropriate | profile specification. Validation basis | identity or domain validation level and source of attributes | registration evidence. Subscriber obligations | duties before and after acceptance | terms and conditions. Relying-party notice | status-checking and usage limits | PKI disclosure statement.

  • For LCP, NCP, NCP+, DVCP, OVCP, IVCP, or EVCP, preserve EN 319 411-1 profile markings instead of flattening them into one checklist.
  • For a custom CP, identify the adopted EN 319 411-1 base policy, added constraints, variances, approving authority, risk assessment basis, and review process.
  • Include the certificate profile requirements and unique object identifier when the policy is used in issued certificates.
  • Make revisions available to subscribers and relying parties when the CP changes.
Section 3

Certification Practice Statement fields: explain how the CA operates

The CPS section should explain how the TSP implements the CP in its actual organization, facilities, systems, and procedures. EN 319 411-1 notes that lower-level operating procedures may remain internal when they contain private or proprietary detail, so the CPS template should expose enough for subscribers, subjects, relying parties, and auditors without publishing sensitive runbooks.

Use this CPS table for implementation mapping: Field | Fill with | Evidence. Registration service | identity proofing, proof of possession, RA handoff, attribute validation | registration records. Certificate generation | approval checks, profile selection, signing controls | issuance logs. Dissemination | certificate delivery and publication handling | repository records. Revocation management | authorized request intake, decision criteria, subscriber notice | revocation case file. Revocation status service | CRL or OCSP operation and integrity controls | status-service monitoring.

  • Link each CP commitment to a CPS clause and to the operating evidence that proves the practice was followed.
  • Name external organizations that support the certificate service and identify the applicable policies and practices that govern their work.
  • Keep confidential procedure names, access lists, locations, and detailed key-ceremony steps in internal evidence, not in public CPS text.
  • Show how the CPS covers registration, certificate generation, dissemination, revocation management, revocation status, and optional subject device provisioning where used.
Section 4

Terms, conditions, and PKI disclosure statement fields

The CP/CPS package should include subscriber and relying-party material, not just a technical policy. EN 319 411-1 requires terms and conditions and describes the PKI disclosure statement as the part of those terms that relates to PKI operation. Annex A also makes clear that a disclosure statement helps users make trust decisions but does not supersede the CP or CPS.

Use this disclosure table: Field | Fill with | Evidence. TSP contact | legal name, location, support, revocation contact | published disclosure. Certificate type and validation | class of certificate and validation procedure | CP/CPS clause. Subscriber obligations | key protection, information accuracy, acceptance, notification duties | subscriber agreement. Relying-party obligations | certificate-status checking and reliance limits | relying-party notice. Audit and trust marks | conformity scheme, audit reference, trusted-list link where applicable | assessment record.

  • Include what constitutes certificate acceptance, records retention period, subscriber obligations, subject obligations where applicable, and notices to relying parties.
  • Publish or provide the CP, CPS, terms, and disclosure materials in a form suitable for subscribers, subjects, and relying parties.
  • Do not use the PKI disclosure statement as a substitute for the governing CP or CPS; use it as a readable index to the obligations and limitations.
  • Keep legal, complaint, dispute-resolution, privacy, refund, liability, audit, and repository information aligned with the terms and CPS.
Section 5

Maintenance controls for the CP/CPS template

Treat the template as a controlled document set. EN 319 401 expects the practice statement to have management-body approval, defined maintenance responsibilities, a review process, availability to subscribers and relying parties where needed, and notice for changes that may affect service acceptance.

Use this maintenance table: Field | Fill with | Evidence. Owner | policy authority, CPS maintainer, service owner | responsibility matrix. Review trigger | CP profile change, certificate profile change, RA change, revocation process change, CA key change, supplier change, audit finding | change-impact record. Publication | effective date, public URL, redaction rationale | publication log. Traceability | CP clause to CPS clause to evidence artifact | evidence register.

  • Review CP and CPS alignment after changes to policy OIDs, certificate profiles, registration methods, RA delegation, revocation handling, repository operation, CA key controls, or external support.
  • Give notice when a practice-statement change may affect acceptance of the service by a subject, subscriber, or relying party.
  • Keep a source-to-clause map so an assessor can see which EN 319 411-1 or EN 319 401 requirement supports each public statement.
  • Version public documents and internal evidence separately so sensitive implementation evidence can be reviewed without leaking it into subscriber-facing text.
Primary sources

References and citations

Related guides

Explore more topics

CP vs CPS under ETSI EN 319 411-1
Understand how ETSI EN 319 411-1 separates Certificate Policy from Certification Practice Statement work for certification authorities and trust service providers.
EN 319 411-1 vs EN 319 411-2 Certificate Policy
Compare ETSI EN 319 411-1 general certificate-service requirements with EN 319 411-2 EU qualified certificate requirements, including policy scope, CP/CPS evidence, and audit boundaries.
ETSI EN 319 411-1 Audit File Evidence
Build an ETSI EN 319 411-1 audit evidence file for CA logging, registration records, revocation records, CA key lifecycle evidence, and records archival.
ETSI EN 319 411-1 CA Key Management
CA key management guidance for ETSI EN 319 411-1: CPS commitments, key ceremonies, secure cryptographic devices, backup, recovery, and lifecycle evidence.
ETSI EN 319 411-1 certificate lifecycle workflow
Workflow for EN 319 411-1 certificate application, issuance, acceptance, renewal, re-key, modification, revocation, suspension, status services, and evidence records.
ETSI EN 319 411-1 certificate re-key FAQ
What ETSI EN 319 411-1 requires when a TSP re-keys an existing certificate with a new subject public key.
ETSI EN 319 411-1 Certificate Suspension FAQ
How CAs should handle certificate suspension under ETSI EN 319 411-1: CPS disclosure, validated requests, status publication, subscriber notice, and audit evidence.
ETSI EN 319 411-1 Certification Audit Evidence FAQ
How CAs should prepare ETSI EN 319 411-1 audit evidence for CP/CPS scope, registration records, revocation records, CA key logs, and retained assessment files.
ETSI EN 319 411-1 Compliance Guide
Build an ETSI EN 319 411-1 compliance file for certificate policies, CPS commitments, certificate lifecycle controls, revocation services, CA keys, and audit evidence.
ETSI EN 319 411-1 FAQ for Certificate Services
Answers to common ETSI EN 319 411-1 questions on certificate policies, CPS content, CA and RA boundaries, subscriber evidence, revocation, status services, and record retention.
ETSI EN 319 411-1 Identity Validation
Identity validation requirements in ETSI EN 319 411-1 for subscribers, subjects, RAs, certificate requests, registration evidence, and issuance records.
ETSI EN 319 411-1 Identity Validation Evidence Workflow
A workflow for building ETSI EN 319 411-1 identity validation evidence packs across subscriber, subject, certificate request, RA, logging, and retention controls.
ETSI EN 319 411-1 RA Delegation Guide
How to scope registration authority delegation under ETSI EN 319 411-1, including delegated RA tasks, external provider controls, registration records, and audit evidence.
ETSI EN 319 411-1 RA Delegation Review Workflow
Review delegated registration authority work under ETSI EN 319 411-1: retained CA responsibility, recognized registration service providers, secure data exchange, CPS coverage, and audit evidence.
ETSI EN 319 411-1 requirements map for certificate services
Map ETSI EN 319 411-1 requirements for certificate policies, CP/CPS content, registration, revocation, certificate status, and CA key-management evidence.
ETSI EN 319 411-1 Revocation Evidence Workflow
Build a revocation evidence workflow for ETSI EN 319 411-1 covering CPS procedures, request authentication, 24-hour status updates, CRL/OCSP publication, logs, and retention.
ETSI EN 319 411-1 Revocation, OCSP, and CRL Operations
Operate ETSI EN 319 411-1 revocation status services with CPS procedures, authenticated requests, 24-hour CRL or OCSP publication controls, and audit evidence.
ETSI EN 319 411-1 vs CA/B Forum Baseline Requirements
Compare how EN 319 411-1 incorporates CA/B Forum BRG concepts for DVCP, OVCP, IVCP, [WEB] requirements, CPS disclosure, domain validation, and conflict handling.
How should certificate authorities handle revocation evidence under ETSI EN 319 411-1?
What ETSI EN 319 411-1 expects CAs to evidence for certificate revocation requests, status publication, CRL or OCSP updates, and archived revocation records.
RA delegation under ETSI EN 319 411-1
How certificate authorities can delegate registration authority work under ETSI EN 319 411-1 while keeping identity validation, secure data exchange, role controls, and audit evidence traceable.
Subscriber agreements under ETSI EN 319 411-1
How ETSI EN 319 411-1 expects CAs and TSPs to inform subscribers, record acceptance, handle subject consent, and retain subscriber-agreement evidence.
Subscriber identity validation under ETSI EN 319 411-1
How certificate authorities should validate subscriber and subject identity under ETSI EN 319 411-1, including evidence, authorization, subject categories, and registration records.