ETSI EN 319 411 2Free Resource

ETSI EN 319 411 2 Qualified Certificate Policy Guide

ETSI EN 319 411-2 V2.6.1 sets policy and security requirements for trust service providers issuing EU qualified certificates for signatures, seals, and website authentication. It covers policy selection, identity, issuance, qualified signature or seal creation devices (QSCDs), revocation, status services, and relying-party information.

Based on ETSI EN 319 411-2V2.6.1 (2025-06)No signup required
Quick scan
Artifact
ETSI EN 319 411-2 requirements
Start with the CP, CPS, certificate usage, publication, identity validation, issuance, acceptance, revocation, and status-service topics. Identify which controls belong to the certification authority (CA), registration authority (RA), subscriber, subject, manager, or status-service operator.
Qualified certificate scope
Use when the question is whether EN 319 411-2, an inherited EN 319 411-1 control, a binding EU adaptation, or trusted-list status drives the decision.
Qualified profile selector workflow
Use when a profile, indication, or qualified website authentication certificate profile must be selected and documented.

Use the linked pages to identify the applicable policy, actor, control, and retained evidence. Recheck the mapping after a policy or OID change, CA hierarchy change, identity route change, status change, trusted-list update, significant service change, or new binding EU adaptation.

Key dates
16
Topics
9
FAQs
2
Comparisons
V2.6.1
Edition
Where to start in the EN 319 411-2 guide
ETSI EN 319 411-2 requirements
Review the policy rules and current EU adaptations before mapping the (CP), Certification Practice Statement (CPS), certificate policy identifiers, lifecycle controls, and publication duties. The CP states what the service promises; the CPS explains how the provider meets it.
ETSI EN 319 411-2 qualified certificate scope
Check whether the service issues to a natural person, legal person, or website-authentication subscriber; whether the private key must reside in a ; and which trusted-list service entry supports the qualified claim.
ETSI EN 319 411-2 profile selector workflow
Choose between QCP-n, QCP-l, QCP-n-, QCP-l-qscd, QEVCP-w, QNCP-w, and QNCP-w-gen using the certificate subject, QSCD condition, and website-certificate basis. Record the ETSI policy identifier or the object identifier (OID) tied to the policy actually applied.
QCP profiles
QSCD routes
Trusted-list context
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Mar 4, 2026
Updated
Jul 16, 2026

Choose the certificate purpose, subject, and policy profile first. Then apply the general EN 319 411-1 controls, the Part 2 additions, and each binding EU adaptation. Regulation (EU) 2025/1943 references and adapts V2.6.1 for qualified signature and seal certificates; the QWAC reference rules in Regulation (EU) 2025/2527 apply from 6 January 2027. A provider may run both qualified and non-qualified services, and qualified status attaches only to the specific service entered as qualified in a national trusted list.

Timeline

Key milestones for ETSI EN 319 411 2

Follow the standard's publication history, V2.6.1 ENAP and adoption milestones, and the national announcement, endorsement, and conflicting-standard withdrawal dates. These standards milestones are separate from the application dates of EU implementing regulations, including 6 January 2027 for the QWAC reference standards in Regulation (EU) 2025/2527 and 19 August 2027 for the identity-verification reference standard in Regulation (EU) 2025/1566.

Timeline in progress
We are reviewing the primary sources and will publish the complete timeline here.
Recommended reading path

Choose the next qualified-certificate decision

New to EN 319 411-2? Start with scope and the policy profile. If the profile is already fixed, jump to identity, , lifecycle, trusted-list, supervision, or comparison guidance without treating standard conformance as qualified status.

1

Start here: scope, profile, and requirements

Define the certificate purpose and subject, select the matching qualified certificate policy, and identify both the Part 2 additions and inherited EN 319 411-1 requirements.

2

Identity, QSCD, and relying-party trust

Connect the selected policy to subscriber and subject proofing, the qualified signature or seal creation device route, certificate statements, and the EU trusted-list information used by relying parties.

3

Lifecycle operations and assessment evidence

Translate the policy into issuance, acceptance, renewal, re-key, modification, revocation, status-service, archival, termination, and reviewable evidence controls.

4

Qualification, supervision, and comparisons

Separate the standard from eIDAS qualified status and supervision, understand the EN 319 411-1 dependency, or open the FAQ for a focused implementation question.

Next step

Turn ETSI EN 319 411 2 policy review into assessment work

The ETSI EN 319 411 2 guide is the shared starting point for qualified review. Route live assessment work into Assessment Autopilot; Research Copilot supports cited questions for profile selection, treatment, trusted-list context, or lifecycle evidence.

What this unlocks
  • Start from the EN 319 411 2 topic page that matches the , CPS, , QWAC, revocation, or trusted-list question.
  • Use Assessment Autopilot to assign owners for CPS updates, mapping, publication evidence, identity validation, revocation, and status-service controls.
  • Use Research Copilot to answer profile, scope, and source interpretation questions with cited outputs.
  • Keep official standard citations separate from organization-specific policy choices and assessor requests.
ETSI EN 319 411 2 artifact preview
Share it internally
Download the timeline export to align legal, product, engineering, and commercial teams on milestones and deadlines.