Artifact FAQGLOBALETSI EN 319 411-1

ETSI EN 319 411-1 Subscriber agreements

A focused answer on what certificate authorities and trust service providers need to put in place before a certificate subscriber accepts terms.

Based on ETSI EN 319 411-1 and ETSI EN 319 401 source material. Use it as implementation guidance, not for legal interpretation.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Before a enters a relationship covered by ETSI EN 319 411-1 V1.5.1 (April 2025), the TSP must communicate the certificate terms and conditions in a durable, human-readable way, record the agreement, and keep evidence that the subscriber accepted those terms by a traceable, wilful act. The standard supplies a technical and contractual baseline. Applicable consumer, electronic-transactions, trust-services, data-protection, scheme, and national rules can add form, language, consent, retention, or withdrawal requirements.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What does ETSI EN 319 411-1 require before a subscriber agreement?

The CA or TSP should start with the terms and conditions that explain certificate use, acceptance, obligations, and limitations. ETSI EN 319 411-1 clause 6.3.4 requires the to be informed of those terms before the contractual relationship is formed.

The agreement process also needs to be usable as evidence later. The terms must be communicated through a durable means, in human-readable form, before the agreement. Electronic transmission is allowed, but the record must still show what version was presented and how acceptance occurred.

  • Identify the certificate policy, CPS, terms and conditions, and any PKI disclosure statement that govern the relationship.
  • Present the applicable terms before the enters the contractual relationship or accepts the certificate.
  • Use a durable communication method that preserves the terms with integrity over time and is readable by the .
  • Define what constitutes certificate acceptance in the terms and conditions, rather than leaving acceptance implied by operational workflow.
Citations
Question 2

How should the agreement handle subscribers and subjects?

ETSI EN 319 411-1 distinguishes the from the certificate . If the subscriber and subject are separate entities and the subject is a natural or legal person, the agreement shall be in two parts: one ratified by the subscriber and one ratified by the subject. The two parts may be ratified together when the subscriber is the subject legal person's official representative, or when the same official representative acts for both subscriber and subject.

That distinction matters for enterprise and delegated-certificate scenarios. The part should capture subscriber obligations, any secure-device requirement, consent to registration and revocation records, publication choices, and confirmation that certificate information is correct. The part should capture the subject obligations, secure-device acceptance where relevant, and consent to the records kept by the TSP.

  • Use a two-part agreement when the and are separate and the subject is a natural or legal person.
  • Use a such as signing or checking an acceptance box for each required ratification; an agreement may be electronic.
  • When the and are the same entity, or the subject is a device, include the subscriber and subject items in one or two agreement parts.
  • Allow staged acceptance only where the record still shows each accepted element, such as later confirmation that certificate information is correct.
Citations
Question 3

What evidence should a CA retain for subscriber agreements?

The evidence should prove the exact agreement, the terms accepted, the person or entity accepting, and the specific choices made during registration. ETSI EN 319 411-1 requires the agreement with the to be recorded, and, where the subscriber and are separate, the subject agreement to be recorded as well.

Records should also connect the agreement to the registration file. ETSI EN 319 411-1 lists the storage location of applications and identification documents, including the agreement, plus specific choices in the agreement such as consent to certificate publication.

  • Retain the signed or electronically accepted agreement and the version of terms and conditions presented at acceptance.
  • Keep evidence of the wilful act used for acceptance, such as signature data, acceptance timestamp, account identity, or equivalent trace record.
  • Record publication consent, secure-cryptographic-device acceptance, certificate-information confirmation, and any other agreement choices that affect issuance or relying-party information.
  • Retain the agreement records for the period indicated to the as part of the terms and conditions, and for at least the clause 6.4.6 minimum where that clause applies.
Citations
Primary sources

References and citations

etsi.org
Referenced sections
  • Clause 6.2 supports the general TSP requirement to inform subscribers and relying parties of precise terms before a contractual relationship.
"Subscribers and parties relying on the trust service shall be informed"
etsi.org
Referenced sections
  • Requirements REG-6.3.4-07, REG-6.3.4-08, and REG-6.3.4-17 support recorded acceptance and disclosed retention; REG-6.4.5-04 covers the subscriber agreement's storage location, and clause 6.4.6 sets the seven-year minimum for the clause 6.3.4 documentation it covers.
"including the subscriber agreement"
Related guides

Explore more topics

CP vs CPS under ETSI EN 319 411-1
Understand how ETSI EN 319 411-1 separates Certificate Policy from Certification Practice Statement work for certification authorities and trust service providers.
EN 319 411-1 vs EN 319 411-2 Certificate Policy
Compare ETSI EN 319 411-1 V1.5.1 with EN 319 411-2 V2.6.1, including policy profiles, inherited controls, QSCD routes, trusted-list status, and evidence boundaries.
ETSI EN 319 411-1 Audit File Evidence
Build an ETSI EN 319 411-1 audit evidence file for CA logging, registration records, revocation records, CA key lifecycle evidence, and records archival.
ETSI EN 319 411-1 CA Key Management
CA key management guidance for ETSI EN 319 411-1: CPS commitments, key ceremonies, secure cryptographic devices, backup, recovery, and lifecycle evidence.
ETSI EN 319 411-1 certificate lifecycle workflow
Workflow for EN 319 411-1 certificate application, issuance, acceptance, renewal, re-key, modification, revocation, suspension, status services, and evidence records.
ETSI EN 319 411-1 certificate re-key FAQ
What ETSI EN 319 411-1 requires when a TSP re-keys an existing certificate with a new subject public key.
ETSI EN 319 411-1 Certificate Suspension FAQ
How CAs should handle certificate suspension under ETSI EN 319 411-1: CPS disclosure, validated requests, status publication, subscriber notice, and audit evidence.
ETSI EN 319 411-1 Certification Audit Evidence FAQ
How CAs should prepare ETSI EN 319 411-1 audit evidence for CP/CPS scope, registration records, revocation records, CA key logs, and retained assessment files.
ETSI EN 319 411-1 Compliance Guide
Build an ETSI EN 319 411-1 compliance file for certificate policies, CPS commitments, certificate lifecycle controls, revocation services, CA keys, and audit evidence.
ETSI EN 319 411-1 CP and CPS template
Build a certificate policy and Certification Practice Statement template for ETSI EN 319 411-1 certificate services, with fields for policy identifiers, subscribers, relying parties, revocation, publication, and evidence.
ETSI EN 319 411-1 FAQ for Certificate Services
Answers to common ETSI EN 319 411-1 questions on certificate policies, CPS content, CA and RA boundaries, subscriber evidence, revocation, status services, and record retention.
ETSI EN 319 411-1 Identity Validation
Identity validation requirements in ETSI EN 319 411-1 for subscribers, subjects, RAs, certificate requests, registration evidence, and issuance records.
ETSI EN 319 411-1 Identity Validation Evidence Workflow
A workflow for building ETSI EN 319 411-1 identity validation evidence packs across subscriber, subject, certificate request, RA, logging, and retention controls.
ETSI EN 319 411-1 RA Delegation Guide
How to scope registration authority delegation under ETSI EN 319 411-1, including delegated RA tasks, external provider controls, registration records, and audit evidence.
ETSI EN 319 411-1 RA Delegation Review Workflow
Review delegated registration authority work under ETSI EN 319 411-1: retained CA responsibility, recognized registration service providers, secure data exchange, CPS coverage, and audit evidence.
ETSI EN 319 411-1 requirements map for certificate services
Map ETSI EN 319 411-1 requirements for certificate policies, CP/CPS content, registration, revocation, certificate status, and CA key-management evidence.
ETSI EN 319 411-1 Revocation Evidence Workflow
Build a revocation evidence workflow for ETSI EN 319 411-1 covering CPS procedures, request authentication, 24-hour status updates, CRL/OCSP publication, logs, and retention.
ETSI EN 319 411-1 Revocation, OCSP, and CRL Operations
Operate ETSI EN 319 411-1 revocation status services with CPS procedures, authenticated requests, applicable 24-hour timing, CRL and OCSP controls, exceptions, and audit evidence.
ETSI EN 319 411-1 vs CA/B Forum Baseline Requirements
Compare ETSI EN 319 411-1 V1.5.1 with the CA/Browser Forum TLS Baseline Requirements, including [WEB] controls, DVCP, OVCP, IVCP, CPS duties, and change monitoring.
How should certificate authorities handle revocation evidence under ETSI EN 319 411-1?
What ETSI EN 319 411-1 expects CAs to evidence for certificate revocation requests, status publication, CRL or OCSP updates, and archived revocation records.
RA delegation under ETSI EN 319 411-1
How certificate authorities can delegate registration authority work under ETSI EN 319 411-1 while keeping identity validation, secure data exchange, role controls, and audit evidence traceable.
Subscriber identity validation under ETSI EN 319 411-1
How certificate authorities should validate subscriber and subject identity under ETSI EN 319 411-1, including evidence, authorization, subject categories, and registration records.