ETSI EN 319 411 2 Qualified Certificate Policy Guide
ETSI EN 319 411-2 V2.6.1 sets policy and security requirements for trust service providers issuing EU qualified certificates for signatures, seals, and website authentication. It covers policy selection, identity, issuance, qualified signature or seal creation devices (QSCDs), revocation, status services, and relying-party information.
Use the linked pages to identify the applicable policy, actor, control, and retained evidence. Recheck the mapping after a policy or OID change, CA hierarchy change, identity route change, status change, trusted-list update, significant service change, or new binding EU adaptation.
Choose the certificate purpose, subject, and policy profile first. Then apply the general EN 319 411-1 controls, the Part 2 additions, and each binding EU adaptation. Regulation (EU) 2025/1943 references and adapts V2.6.1 for qualified signature and seal certificates; the QWAC reference rules in Regulation (EU) 2025/2527 apply from 6 January 2027. A provider may run both qualified and non-qualified services, and qualified status attaches only to the specific service entered as qualified in a national trusted list.
Key milestones for ETSI EN 319 411 2
Follow the standard's publication history, V2.6.1 ENAP and adoption milestones, and the national announcement, endorsement, and conflicting-standard withdrawal dates. These standards milestones are separate from the application dates of EU implementing regulations, including 6 January 2027 for the QWAC reference standards in Regulation (EU) 2025/2527 and 19 August 2027 for the identity-verification reference standard in Regulation (EU) 2025/1566.
Choose the next qualified-certificate decision
New to EN 319 411-2? Start with scope and the policy profile. If the profile is already fixed, jump to identity, , lifecycle, trusted-list, supervision, or comparison guidance without treating standard conformance as qualified status.
Start here: scope, profile, and requirements
Define the certificate purpose and subject, select the matching qualified certificate policy, and identify both the Part 2 additions and inherited EN 319 411-1 requirements.
Identity, QSCD, and relying-party trust
Connect the selected policy to subscriber and subject proofing, the qualified signature or seal creation device route, certificate statements, and the EU trusted-list information used by relying parties.
Lifecycle operations and assessment evidence
Translate the policy into issuance, acceptance, renewal, re-key, modification, revocation, status-service, archival, termination, and reviewable evidence controls.
Qualification, supervision, and comparisons
Separate the standard from eIDAS qualified status and supervision, understand the EN 319 411-1 dependency, or open the FAQ for a focused implementation question.
Turn ETSI EN 319 411 2 policy review into assessment work
The ETSI EN 319 411 2 guide is the shared starting point for qualified review. Route live assessment work into Assessment Autopilot; Research Copilot supports cited questions for profile selection, treatment, trusted-list context, or lifecycle evidence.
- Start from the EN 319 411 2 topic page that matches the , CPS, , QWAC, revocation, or trusted-list question.
- Use Assessment Autopilot to assign owners for CPS updates, mapping, publication evidence, identity validation, revocation, and status-service controls.
- Use Research Copilot to answer profile, scope, and source interpretation questions with cited outputs.
- Keep official standard citations separate from organization-specific policy choices and assessor requests.
