- Supports subcontractor competence and termination of subcontractor authorization before TSP service termination.
"terminate authorization of all subcontractors"
A focused guide for certificate authorities and trust service providers that use internal or external registration authority support.
Based on ETSI EN 319 411-1 and ETSI EN 319 401 source text. Use it as implementation guidance, not for legal interpretation.
Structured answer sets in this page tree.
Cited legal and guidance references.
A can assist with certificate applications, revocation, or both, but delegation does not transfer the TSP's overall responsibility. Define each delegated task, the policy profiles it supports, who accepts the resulting evidence, how registration data moves, and what happens when personnel, providers, or authority change. This page applies EN 319 411-1 V1.5.1. Its EN 319 401 reference is non-specific, so clause 2.1 makes the latest edition applicable; record the EN 319 401 edition and assessment date used.
ETSI EN 319 411-1 defines a as the entity mainly responsible for identifying and authenticating certificate subjects, and notes that an RA can assist in the certificate application process, the revocation process, or both. Define the exact tasks in scope and the certificate policies they support. The TSP may use other parties for parts of the service, but it remains responsible for meeting the applicable policy requirements.
Document the boundary in the CP/CPS or supporting operating procedures. Separate identity proofing, certificate application intake, authorization checks, registration-data submission, revocation request handling, and evidence retention so a reviewer can see which activities are performed by the CA, by an internal RA, or by an external registration service provider.
When an external registration service provider is used, EN 319 411-1 requires registration data to be exchanged securely and only with recognized providers whose identity is authenticated. The standard also points external RAs back to general TSP security requirements for human resources, operational security, networks, and privacy.
ETSI EN 319 401 V3.2.1 supplies the current governance layer. For subcontracting, outsourcing, or other third-party arrangements, the TSP maintains overall responsibility, defines outsourcer liability, binds the provider to required controls, keeps documented agreements, and maintains an up-to-date register of direct suppliers and service providers with contact points and the ICT products, services, or processes they provide.
This ETSI EN 319 411-1 guide helps align CP/CPS wording, RA agreements, registration records, and audit evidence before relying on delegated registration work.
Convert RA delegation into control owners, evidence requests, and audit-ready checkpoints.
Check ambiguous RA scope, CP/CPS wording, or registration evidence against cited ETSI requirements.
Review delegated RA scope, provider agreements, registration records, and termination evidence with Sorena.
Delegated RA work must still support the identity validation requirements behind the certificate. EN 319 411-1 requires the TSP to verify the identity of the subscriber and subject and to collect and validate direct evidence or an attestation from an appropriate and authorized source for the identity and relevant attributes.
For registration records, the audit trail should show what evidence was presented, how documents or attestations were validated, who accepted the application, where application and subscriber-agreement records are stored, and the receiving TSP or submitting RA when applicable. The registration officer who verifies identity cannot be the natural person named as the certificate subject. These records make the delegated chain reconstructable without relying on undocumented RA judgment.
RA delegation should be reviewed whenever the delegated role, provider, certificate profile, validation source, secure exchange method, or CP/CPS wording changes. EN 319 411-1 also highlights trusted roles for registration and revocation officers, so the delegation model should show who is authorized to perform registration and revocation work and how incompatible duties are controlled.
Termination is a separate trigger. If a CA or RA relationship ends, the evidence plan should preserve registration information, revocation status information, and event log archives for their applicable and disclosed periods. Before terminating its own services, the TSP must terminate subcontractor authority to act for it and transfer evidence-maintenance obligations to a reliable party unless it can show that it holds no such information.
"terminate authorization of all subcontractors"
"registration and revocation officers"