Use Part 1 for the general certificate-service baseline. Use Part 2 when the service applies an EU qualified certificate policy profile.
Part 2 inherits many Part 1 controls and adds profile-specific eIDAS, identity, certificate, status-service, trusted-list, and QSCD requirements. Conformance to Part 2 alone does not grant qualified status.
ETSI EN 319 411-2 V2.6.1 builds on EN 319 411-1 V1.5.1; it is not an alternative general baseline. Start with the certificate policy identifier. Use Part 1 for LCP, NCP, NCP+, EVCP, DVCP, OVCP, IVCP, and the common [WEB] controls. Add Part 2 for QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen. A Part 2 assessment can support an EU qualified-service application, but the standard expressly says conformance alone does not make the TSP or its certificates qualified. Under eIDAS, the provider may begin the qualified service only after the supervisory process is complete and appears in the relevant trusted list.
Side-by-side comparison
ETSI EN 319 411-1 vs ETSI EN 319 411-2: what changes operationally?
Part 1 supplies the general baseline. Part 2 selects Part 1 policy requirements and adds the controls for a specific EU qualified certificate policy; eIDAS and the trusted list determine .
Part 1 covers general policy and security requirements for TSPs issuing certificates, including CP/CPS, PKI participants, certificate lifecycle operations, repositories, revocation, and records.
Second framework
ETSI EN 319 411-2
Part 2 covers EU qualified certificate policy profiles. It imports applicable Part 1 controls and adds qualified-certificate requirements, but conformance alone does not grant .
ETSI EN 319 411-1 vs ETSI EN 319 411-2: what changes operationally?
EN 319 411-1 is the general certificate-service standard for TSPs issuing certificates. Scope the CA, RA, subscriber and subject roles, certificate usage, repository, revocation service, and CP/CPS commitments before mapping controls.
EN 319 411-2 specifies policy and security requirements for issuing, maintaining, and managing the lifecycle of EU qualified certificates. It does not specify the independent assessment method and does not, by itself, establish .
Start with the certificate policy profile, then separate inherited Part 1 controls, Part 2 additions, conformity assessment evidence, and the eIDAS trusted-list status.
Part 1 ownership usually sits with the certificate service owner, CA operations, RA or registration service provider owner, security operations, repository or status-service owner, and CP/CPS maintainer.
Part 2 adds the qualified trust service owner, qualified certificate policy owner, trusted-list evidence owner, QSCD or signing-device owner where relevant, and conformity assessment lead.
ETSI EN 319 411-1 is the general baseline when the TSP issues public-key certificates under its Part 1 certificate policy profiles, including CP/CPS, CA/RA, subscriber registration, certificate issuance, repository, and revocation-service commitments.
Add EN 319 411-2 when the service uses a Part 2 policy profile for qualified certificates to natural persons, legal persons, or websites. The selected profile determines whether NCP, NCP+, EVCP, OVCP, IVCP, or [WEB] requirements are inherited and whether a QSCD is required.
Rerun the comparison when the policy identifier, subject type, QSCD condition, web profile, CA or RA boundary, repository, status service, conformity assessment scope, or trusted-list status changes.
Part 1 obligations center on CP/CPS structure, certificate policy identification, PKI participants, publication and repository responsibilities, identity validation, certificate lifecycle operations, revocation and status services, facility controls, technical security controls, audit logging, records archival, and CA or RA termination.
Part 2 selects a Part 1 base by profile: QCP-n and QCP-l use NCP or, when required by the terms and conditions, NCP+; the qscd profiles include NCP+; QEVCP-w uses EVCP; QNCP-w uses NCP plus OVCP or IVCP; and QNCP-w-gen uses NCP plus [WEB] controls. Part 2 then adds its qualified-certificate requirements.
ETSI EN 319 411-1 evidence should name the certificate policy and CPS version, certificate profiles, subscriber identity records, CA and RA responsibilities, issuance logs, repository and CRL/OCSP records, revocation files, and audit-period evidence.
ETSI EN 319 411-2 evidence should add the qualified policy OID and qcStatements, Part 2 identity evidence, status information beyond certificate validity, QSCD certification and key-origin evidence for qscd profiles, the conformity assessment report, supervisory records, and the trusted-list entry.
Keep a traceable evidence matrix with the source clause, claim, owner, artifact, review date, service boundary, and whether it supports Part 1 conformance, Part 2 conformance, or legal .
Part 1 evidence timing is driven by certificate validity, certificate lifecycle events, revocation and status-service operation, audit logging, records archival, key changeover, and CA or RA termination records.
Part 2 adds availability of revocation status beyond certificate validity and documentation of that period. eIDAS separately requires a qualified TSP audit at least every 24 months, advance notice of planned audits, notification before service changes or cessation, and current trusted-list status.
Track certificate validity, CP/CPS version, status-information retention, assessment dates, supervisory notices, and trusted-list status as separate clocks.
ETSI EN 319 411-1 assurance usually runs through TSP conformity assessment against EN 319 401 plus EN 319 411-1, with audit evidence tied to the applicable Part 1 certificate policy, CPS, CA operations, RA controls, and lifecycle records.
EN 319 411-2 can form part of the conformity evidence for a qualified certificate service, but the standard says conformance alone does not imply . The eIDAS route requires a conformity assessment report, supervisory verification, and the qualified-service entry in the trusted list.
Treat the assessment conclusion, supervisory decision, trusted-list entry, certificate policy, and any browser relying-party requirements as separate evidence items.
Part 1 evidence can be reused for common PKI operations, such as lifecycle processing, revocation services, repositories, audit logging, and records archival, when the service boundary and policy profile match.
Part 2 can reuse common PKI evidence only after adding the qualified certificate policy context and any qualified-status, QWAC, trusted-list, or QSCD evidence needed for the qualified claim.
Reuse the operational artifact, not the conclusion. The same log or CP/CPS section may support both sides, but the qualified-certificate conclusion needs its own cited row.
Use EN 319 411-1 as the controlling side when the claim is that a TSP certificate service meets the general Part 1 certificate policy and security requirements.
Use EN 319 411-2 for conformance to a Part 2 qualified certificate policy profile. Use eIDAS and the trusted list to determine whether the provider and service have legal .
Do not collapse conformance and legal status into one conclusion. Show the Part 1 base, Part 2 additions, assessment evidence, supervisory outcome, and trusted-list record separately.
EN 319 411-1 is the general certificate-service standard for TSPs issuing certificates. Scope the CA, RA, subscriber and subject roles, certificate usage, repository, revocation service, and CP/CPS commitments before mapping controls.
EN 319 411-2 specifies policy and security requirements for issuing, maintaining, and managing the lifecycle of EU qualified certificates. It does not specify the independent assessment method and does not, by itself, establish .
Start with the certificate policy profile, then separate inherited Part 1 controls, Part 2 additions, conformity assessment evidence, and the eIDAS trusted-list status.
Part 1 ownership usually sits with the certificate service owner, CA operations, RA or registration service provider owner, security operations, repository or status-service owner, and CP/CPS maintainer.
Part 2 adds the qualified trust service owner, qualified certificate policy owner, trusted-list evidence owner, QSCD or signing-device owner where relevant, and conformity assessment lead.
ETSI EN 319 411-1 is the general baseline when the TSP issues public-key certificates under its Part 1 certificate policy profiles, including CP/CPS, CA/RA, subscriber registration, certificate issuance, repository, and revocation-service commitments.
Add EN 319 411-2 when the service uses a Part 2 policy profile for qualified certificates to natural persons, legal persons, or websites. The selected profile determines whether NCP, NCP+, EVCP, OVCP, IVCP, or [WEB] requirements are inherited and whether a QSCD is required.
Rerun the comparison when the policy identifier, subject type, QSCD condition, web profile, CA or RA boundary, repository, status service, conformity assessment scope, or trusted-list status changes.
Part 1 obligations center on CP/CPS structure, certificate policy identification, PKI participants, publication and repository responsibilities, identity validation, certificate lifecycle operations, revocation and status services, facility controls, technical security controls, audit logging, records archival, and CA or RA termination.
Part 2 selects a Part 1 base by profile: QCP-n and QCP-l use NCP or, when required by the terms and conditions, NCP+; the qscd profiles include NCP+; QEVCP-w uses EVCP; QNCP-w uses NCP plus OVCP or IVCP; and QNCP-w-gen uses NCP plus [WEB] controls. Part 2 then adds its qualified-certificate requirements.
ETSI EN 319 411-1 evidence should name the certificate policy and CPS version, certificate profiles, subscriber identity records, CA and RA responsibilities, issuance logs, repository and CRL/OCSP records, revocation files, and audit-period evidence.
ETSI EN 319 411-2 evidence should add the qualified policy OID and qcStatements, Part 2 identity evidence, status information beyond certificate validity, QSCD certification and key-origin evidence for qscd profiles, the conformity assessment report, supervisory records, and the trusted-list entry.
Keep a traceable evidence matrix with the source clause, claim, owner, artifact, review date, service boundary, and whether it supports Part 1 conformance, Part 2 conformance, or legal .
Part 1 evidence timing is driven by certificate validity, certificate lifecycle events, revocation and status-service operation, audit logging, records archival, key changeover, and CA or RA termination records.
Part 2 adds availability of revocation status beyond certificate validity and documentation of that period. eIDAS separately requires a qualified TSP audit at least every 24 months, advance notice of planned audits, notification before service changes or cessation, and current trusted-list status.
Track certificate validity, CP/CPS version, status-information retention, assessment dates, supervisory notices, and trusted-list status as separate clocks.
ETSI EN 319 411-1 assurance usually runs through TSP conformity assessment against EN 319 401 plus EN 319 411-1, with audit evidence tied to the applicable Part 1 certificate policy, CPS, CA operations, RA controls, and lifecycle records.
EN 319 411-2 can form part of the conformity evidence for a qualified certificate service, but the standard says conformance alone does not imply . The eIDAS route requires a conformity assessment report, supervisory verification, and the qualified-service entry in the trusted list.
Treat the assessment conclusion, supervisory decision, trusted-list entry, certificate policy, and any browser relying-party requirements as separate evidence items.
Part 1 evidence can be reused for common PKI operations, such as lifecycle processing, revocation services, repositories, audit logging, and records archival, when the service boundary and policy profile match.
Part 2 can reuse common PKI evidence only after adding the qualified certificate policy context and any qualified-status, QWAC, trusted-list, or QSCD evidence needed for the qualified claim.
Reuse the operational artifact, not the conclusion. The same log or CP/CPS section may support both sides, but the qualified-certificate conclusion needs its own cited row.
Use EN 319 411-1 as the controlling side when the claim is that a TSP certificate service meets the general Part 1 certificate policy and security requirements.
Use EN 319 411-2 for conformance to a Part 2 qualified certificate policy profile. Use eIDAS and the trusted list to determine whether the provider and service have legal .
Do not collapse conformance and legal status into one conclusion. Show the Part 1 base, Part 2 additions, assessment evidence, supervisory outcome, and trusted-list record separately.
When should teams compare ETSI EN 319 411-1 with ETSI EN 319 411-2?
Compare the standards before a TSP reuses CP/CPS text, identity evidence, a certificate profile, revocation records, or an assessment finding for an EU qualified certificate policy. Part 2 repeatedly incorporates Part 1 clauses, so the service normally uses both standards rather than choosing one.
Separate three conclusions: the service meets an EN 319 411-1 policy profile; the service meets an EN 319 411-2 qualified certificate policy profile; and the provider and service hold under eIDAS. Evidence for one conclusion does not automatically establish the others.
Start with the certificate policy identifier and certificate profile: NCP, EVCP, and web certificate routes belong in the Part 1 analysis; QCP and qualified web certificate profiles belong in the Part 2 analysis.
Separate common PKI operations, such as CA/RA responsibilities and revocation status services, from legal-status proof such as the supervisory decision and the applicable EU trusted-list entry.
Keep crosswalk rows cited so audit reviewers can see when Part 2 incorporates or depends on Part 1 requirements.
Decision rules for Part 1 and Part 2 certificate services
Use EN 319 411-1 for the general certificate-service controls. Add EN 319 411-2 when the service uses one of Part 2's EU qualified certificate policy profiles. The Part 2 profile determines which Part 1 requirements are inherited and which qualified-certificate requirements are added.
QCP-n and QCP-l use NCP, or NCP+ when the terms and conditions require a secure cryptographic device. QCP-n-qscd and QCP-l-qscd include the corresponding QCP requirements and NCP+ and require the related private key to reside on a QSCD. QEVCP-w incorporates EVCP. QNCP-w incorporates NCP plus OVCP or IVCP and therefore the latest CA/Browser Forum BR. QNCP-w-gen incorporates NCP plus the selected [WEB] requirements from Part 1.
If the certificate service is not making an EU qualified certificate claim, keep the comparison anchored in EN 319 411-1 and avoid importing qualified-certificate obligations by label alone.
If the service claims , document the Part 2 policy profile, conformity assessment report, supervisory notification and decision, trusted-list entry, and any QSCD route before reusing Part 1 evidence.
When Part 2 points back to Part 1 clauses, cite both sides in the audit file and explain which requirement is being satisfied.
Decide whether the same CP/CPS text covers the service, policy object identifier, certificate usage, participants, and publication responsibilities on both sides. Part 1 and Part 2 both use CP/CPS concepts, but Part 2's qualified certificate policy profiles change what the evidence must prove.
For EN 319 411-1, the review should cover CA and RA responsibilities, subscribers and subjects, naming, initial identity validation, certificate application and issuance, certificate acceptance, revocation, status services, repositories, and records archival. For EN 319 411-2, add the qualified certificate policy profile, context, qualified website authentication certificate route if relevant, and QSCD-related evidence only where the Part 2 profile calls for it.
Name the certificate service, CA, RA or registration service provider, certificate policy, certificate profile, repository, and revocation-status service in scope.
Record whether the certificate is for a natural person, a legal person, or website authentication; whether a QSCD profile applies; and whether the service's is present in the trusted list.
Separate Part 1 evidence reused by Part 2 from Part 2-only evidence so the audit file does not hide qualified-service assumptions.
Version evidence by standard version, CP/CPS version, certificate profile, assessment period, and certificate service boundary.
Compare certificate policy evidence before the audit
Use the comparison to separate the general Part 1 evidence baseline from additional qualified-certificate evidence before a CP/CPS update, procurement response, or conformity assessment.
Evidence that belongs on each side of the comparison
Build the comparison as an evidence map, not as a merged checklist. The same operational record can sometimes support both standards, but the claim it supports should stay tied to the relevant Part 1 or Part 2 clause set.
For Part 1, keep CP and CPS versions, certificate policy identifiers, subscriber agreements, identity validation records, RA delegation evidence, issuance logs, CRL or OCSP records, revocation files, repository publication records, key-management records, audit logs, and archival evidence. For Part 2, add the qualified policy mapping, required qcStatements and policy OIDs, evidence for the Part 2 identity route, revocation-status availability beyond certificate validity, the conformity assessment and supervisory records, the trusted-list entry, and QSCD evidence when the profile requires it.
Mark each evidence item as Part 1-only, Part 2-only, or shared with a clause-level explanation.
Do not describe a certificate or service as qualified based only on a Part 2 policy OID or conformity result; verify the applicable trusted-list status and certificate conditions.
Do not describe a Part 1 control as sufficient for Part 2 unless the Part 2 source incorporates or aligns with that Part 1 requirement.
Review the crosswalk after CP/CPS changes, certificate profile changes, RA changes, revocation-service changes, key-management changes, or conformity-assessment scope changes.
Comparison checklist for certificate-service teams
This checklist is relevant when preparing a CP/CPS update, audit evidence pack, qualified certificate service review, or procurement response that mentions both standards.
List the certificate service, certificate policy object identifier, CP/CPS version, certificate profile, CA, RA, repository, and status service covered by EN 319 411-1.
Identify whether any Part 2 policy profile applies: QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.
Create a row for every shared operation, including identity validation, issuance, acceptance, revocation, status services, records archival, and CA or RA termination.
Attach the evidence artifact to the row: CP/CPS text, subscriber record, validation record, certificate sample, CRL or OCSP record, trusted-list reference, audit log, or conformity-assessment finding.
Flag unsupported reuse where the Part 1 evidence proves the general certificate-service controls but does not prove the qualified certificate claim.
Treating the standards as two labels for the same audit file hides the policy-specific requirements. Part 2 is narrower because it addresses EU qualified certificates, but it imports much of Part 1 and adds requirements that vary by qualified policy profile.
Do not call a service qualified because it satisfies Part 1 or Part 2. EN 319 411-2 states that conformance alone does not imply , and eIDAS ties operation of a qualified service to the supervisory process and trusted-list indication.
Do not hide certificate policy profile differences behind a vague CP/CPS title.
Do not reuse identity validation, revocation, repository, or audit-log evidence unless the certificate service boundary and policy profile match.
Do not mix CA/Browser Forum web certificate requirements, qualified website authentication certificate requirements, and general Part 1 certificate-policy requirements without a row-level source reference.
Do not assume the standard replaces current law. EN 319 411-2 V2.6.1 cites Regulation (EU) No 910/2014, while the current consolidated regulation includes the 2024 amendments; verify current identity, supervision, status, and implementing-act requirements against EUR-Lex.
Primary ETSI source for general policy, risk assessment, management, security, incident, continuity, and audit evidence requirements for trust service providers.
"General Policy Requirements for Trust Service Providers"
Primary source for the general certificate-policy baseline, CPS, subscriber identity, revocation, repository, CA/RA, and certificate lifecycle requirements.
"Policy and security requirements for Trust Service Providers issuing certificates"