Artifact GuideGLOBALETSI EN 319 411-2

ETSI EN 319 411-2 compliance checklist

A cited checklist for teams issuing, assessing, or procuring EU qualified certificate services under ETSI EN 319 411-2.

Use it with the binding eIDAS text and EU adaptations to verify policy selection, CP/CPS coverage, identity validation, QSCD handling, trusted-list status, and certificate status evidence.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
6

Structured answer sets in this page tree.

Primary sources
9

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Start with the applicable law, service type, and trusted-list entry, then use EN 319 411-2 V2.6.1 as the technical policy baseline. A (QTSP) has qualified status only for the specific service entered as qualified in a national trusted list. Regulation (EU) 2025/1943 references the standard with adaptations for qualified signature and seal certificates, while Regulation (EU) 2025/2530 adds current QTSP requirements for change notification, risk management, and termination planning. Conformance to the unadapted standard alone does not prove compliance or qualified status.

Section 1

Compliance boundary to confirm first

First establish the service boundary: issuance, maintenance, and lifecycle management of qualified certificates for natural persons, legal persons, or website authentication. Identify the issuing TSP, CA and RA roles, certificate population, policy, CP, CPS, and every inherited EN 319 411-1 control. Keep non-qualified services outside this qualified-policy checklist.

Next establish the legal layer. Record the applicable eIDAS provisions and implementing regulations, including each adaptation to EN 319 411-2. Record the national trusted-list service entry and service digital identifier separately. A provider may offer qualified and non-qualified services; only the listed service has qualified status.

  • Record whether the service issues qualified certificates to natural persons for signature use, to legal persons for seal use, or to natural or legal persons for website authentication; then record separately whether a QSCD profile is intended to support a qualified signature or seal.
  • Link each service boundary to the applicable EN 319 411-2 policy identifier, not just to a generic certificate practice statement.
  • Keep EN 319 411-1 general certificate controls visible because EN 319 411-2 incorporates them instead of replacing them.
  • Flag any claim of qualified status that lacks a matching national trusted-list service entry.
  • Record which binding EU adaptations change, replace, or add to the unadapted EN 319 411-2 text.
Section 2

Policy selection checks

Treat policy selection as the first compliance decision. EN 319 411-2 defines separate EU qualified certificate policy identifiers, and the certificate profile should show whether the service is using the ETSI policy identifier, a TSP-allocated OID, or both.

The selected policy should match the subject type and relying-party use. QCP-n and QCP-n-qscd are for natural persons; QCP-l and QCP-l-qscd are for legal persons; QEVCP-w, QNCP-w, and QNCP-w-gen cover qualified website authentication variants. A TSP-allocated OID must identify the certificate policy actually applied; the policy should incorporate or further constrain the applicable EN 319 411-2 requirements.

  • For QCP-n and QCP-l, verify whether the implementation requires a secure cryptographic device and whether that changes the evidence expected.
  • For QCP-n-qscd and QCP-l-qscd, confirm the QSCD basis and do not reuse the QSCD-specific policy for certificates that do not meet the QSCD conditions.
  • For QEVCP-w, QNCP-w, and QNCP-w-gen, document the website authentication route and any CA/Browser Forum BRG or EVCG dependency referenced by the selected policy. Regulation (EU) 2025/2527 applies its QWAC reference-standard rules from 6 January 2027.
  • Check that issued certificates include an appropriate policy identifier or documented OID choice for the policy actually applied.
Section 3

CP/CPS and certificate operation evidence

The compliance pack should show how the certificate policy, certification practice statement, subscriber terms, repository practices, and certificate lifecycle controls implement the selected EN 319 411-2 policy. Tie each requirement family to the operating record that shows how it was applied.

Prioritize evidence for identity validation, application processing, issuance, acceptance, renewal, re-key, modification, revocation, suspension, status services, and termination. For identity, apply current eIDAS Article 24 and the adaptations in Regulation (EU) 2025/1943 rather than treating the standard's unadapted physical-presence or equivalent-assurance wording as the complete legal route list. Regulation (EU) 2025/1566 makes ETSI TS 119 461 V2.1.1, with adaptations, the identity-verification reference standard from 19 August 2027.

  • Maintain a CP/CPS crosswalk from EN 319 411-2 requirement identifiers to the exact policy section, procedure, system control, and evidence record.
  • For QCP-n and QCP-n-qscd, keep the natural-person identity and attribute evidence required by the Article 24 route used.
  • For QCP-l and QCP-l-qscd, keep the legal-person identity, attribute, and authorized-representative evidence required by the route used.
  • For certificate acceptance, keep the subscriber agreement method; if the agreement is electronic, document how the advanced electronic signature or seal condition was handled.
  • For audit logging and archival, keep records that remain accessible beyond TSP termination where legal requirements require that continuity.
Section 4

QSCD and certificate status checks

For QCP-n-qscd and QCP-l-qscd, confirm that the device is certified as a QSCD, the certificate request links the public key to a key pair generated by a QSCD, and the CPS states what happens if QSCD status changes before certificate expiry. When the TSP manages a remote QSCD for the subject, Regulation (EU) 2025/1943 also requires that TSP to provide the corresponding qualified remote-QSCD management service.

Certificate status services also need specific evidence. EN 319 411-2 requires revocation status information beyond the certificate validity period using a method used during validity, such as CRL or OCSP, unless a validity-assured short certificate exception is being used. The CPS and terms should explain the availability period, CA key compromise handling, and TSP termination handling.

  • Verify QSCD certification evidence before issuing under QCP-n-qscd or QCP-l-qscd.
  • Confirm that QSCD certificates include the QSCD qcStatement and that non-QSCD certificates do not include it.
  • Keep a process for monitoring QSCD status changes and documenting the measures taken if the status changes before certificate expiry.
  • For CRL-based status, document whether expired revoked certificates remain on the CRL and whether the X.509 ExpiredCertsOnCRL extension is used when required.
  • For OCSP-based status, document the archive cutoff or final-response approach used for status information beyond certificate validity.
Section 5

Trusted-list and relying-party evidence

A qualified certificate compliance review should include relying-party evidence, not only issuer-side controls. EN 319 411-2 says the notice to relying parties should explain that the trust anchor for validating the certificate as an EU qualified certificate is identified in the service digital identifier of an appropriate EU trusted-list entry for the qualified TSP.

Record the date checked, national trusted-list source, service digital identifier, current and historical service status where relevant, certificate population covered, and any mismatch with the certificate policy claim. Do not infer that every service from a listed provider is qualified.

  • Capture the QTSP trusted-list entry used to support the qualified certificate claim.
  • Record the service digital identifier and the certificate population or service boundary it covers.
  • Preserve relying-party notice text that explains trusted-list reliance for EU qualified certificate validation.
  • Recheck trusted-list evidence after service-status changes, policy OID changes, CA hierarchy changes, or supervisory-body updates.
Section 6

Current QTSP governance checks

Regulation (EU) 2025/2530 adds binding requirements that a standard-only checklist can miss. It requires notification of significant service changes, a risk management framework, and a termination plan for each qualified trust service. These duties sit beside the certificate-policy and lifecycle controls in EN 319 411-2.

For change control, the notification record must cover the change, planned date and time, reasons, supporting evidence where applicable, and updated documents where applicable. The Regulation identifies service policies, practice statements, terms, architecture, hosting, cryptography, registration, governance, termination, trusted-list data, and third-party arrangements as change areas. Article 24(2)(a) of eIDAS requires at least one month's notice before a service change and at least three months before intended cessation.

  • Maintain a significant-change register and decide whether each change triggers supervisory notification.
  • Keep the risk assessment, treatment decisions, owners, and review evidence for legal, business, operational, and other service risks.
  • Maintain a termination plan for each qualified service, review it at least every two years and when relevant changes occur, and preserve the records needed for continuity and legal evidence.
  • Connect trusted-list updates, certificate revocation, status continuity, subscriber notices, third-party exit arrangements, and financial resources to the termination plan.
Primary sources

References and citations

etsi.org
Referenced sections
  • Supports retaining the general certificate policy, CPS, repository, CA/RA, revocation, and certificate life-cycle controls that EN 319 411-2 references.
"Policy and security requirements for Trust Service Providers issuing certificates"
digital-strategy.ec.europa.eu
Referenced sections
  • Official explanation of the trusted lists and their constitutive effect for the qualified status of a provider's specific service.
Related guides

Explore more topics

eIDAS QTSP supervision workflow for ETSI EN 319 411-2
Operational workflow for qualified trust service providers using ETSI EN 319 411-2 to manage supervisory-body changes, incidents, termination evidence, trusted-list checks, and assessment records.
ETSI EN 319 411-2 certificate operations
Operational guide for ETSI EN 319 411-2 qualified certificate services: policy identifiers, identity validation, issuance, QSCD handling, revocation status, and relying-party notices.
ETSI EN 319 411-2 FAQ for EU Qualified Certificates
Answers to common ETSI EN 319 411-2 questions about EU qualified certificate policies, QSCD use, identity validation, trusted lists, and revocation status services.
ETSI EN 319 411-2 Identity Proofing
How EN 319 411-2 applies identity validation for EU qualified certificates, including QCP natural-person, legal-person, website, and evidence-record checks.
ETSI EN 319 411-2 profile selector
Select the right ETSI EN 319 411-2 qualified certificate policy profile for signatures, seals, QSCD use, and website authentication.
ETSI EN 319 411-2 QSCD Route
When QCP-n-qscd or QCP-l-qscd is the right EN 319 411-2 route, what QSCD evidence is needed, and which certificate-profile claims must stay aligned.
ETSI EN 319 411-2 QTSP supervision evidence workflow
Build an assessment-ready QTSP supervision evidence pack for ETSI EN 319 411-2 qualified certificate services, covering policy identifiers, trusted-list checks, incident records, QSCD evidence, and termination controls.
ETSI EN 319 411-2 Qualified Certificate Scope
Use ETSI EN 319 411-2 to scope EU qualified certificate services by certificate policy, subject type, QSCD use, website authentication profile, and eIDAS context.
ETSI EN 319 411-2 requirements map
Map ETSI EN 319 411-2 requirements for EU qualified certificate services across QCP profiles, CP/CPS documentation, QSCD use, certificate profiles, revocation, and eIDAS Annex A references.
ETSI EN 319 411-2 trusted-list evidence
Build EN 319 411-2 trusted-list evidence for EU qualified certificate reliance: relying-party notice text, QTSP service identifiers, validation records, and change triggers.
ETSI EN 319 411-2 trusted-list validation workflow
Validate an EN 319 411-2 EU qualified-certificate claim by mapping the certificate service to the QTSP trusted-list entry, policy profile, relying-party notice, and status evidence.
ETSI EN 319 411-2 vs eIDAS Qualified Trust Services
Compare ETSI EN 319 411-2 certificate policy requirements with the eIDAS qualified-status, supervision, audit, and trusted-list framework.
ETSI EN 319 411-2 vs EN 319 411-1
Compare ETSI EN 319 411-2 EU qualified certificate requirements with EN 319 411-1 general certificate-service requirements, including policy inheritance, QSCD controls, and CP/CPS evidence reuse.
ETSI EN 319 411-2: Certificate Revocation FAQ
Answer the ETSI EN 319 411-2 revocation question for qualified certificate services: CPS procedures, 24-hour publication, CRL or OCSP status, and evidence to retain.
ETSI EN 319 411-2: end-to-end qualified certificate lifecycle management workflow
Lifecycle workflow for ETSI EN 319 411-2 qualified certificate services, from policy selection and identity validation through issuance, renewal, re-key, modification, revocation, status services, and records.
ETSI EN 319 411-2: Legal vs Natural Person Certs
ETSI EN 319 411-2 separates qualified certificate policies for natural persons, legal persons, QSCD use, and website authentication subscribers.
ETSI EN 319 411-2: QCP, QNCP, and QEVCP Profile Selection
Choose the right ETSI EN 319 411-2 qualified certificate policy profile: QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.
How should QTSPs select an ETSI EN 319 411-2 qualified certificate profile?
A focused FAQ on choosing QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen under ETSI EN 319 411-2.
How should relying parties use trusted lists under ETSI EN 319 411-2?
FAQ on EN 319 411-2 trusted-list reliance for EU qualified certificates: relying-party notices, QTSP service identifiers, validation evidence, and source references.
QSCD Requirements in ETSI EN 319 411-2
How ETSI EN 319 411-2 treats QSCD-backed qualified certificates, including QCP-n-qscd and QCP-l-qscd policies, key-use controls, QSCD verification, and certificate profile evidence.
QTSP Supervision and ETSI EN 319 411-2
How ETSI EN 319 411-2 supports QTSP supervision evidence for qualified certificate services, trusted-list reliance, liability responsibility, incident records, and audit preparation.
Qualified certificates under ETSI EN 319 411-2
FAQ answer for QTSPs on how ETSI EN 319 411-2 treats EU qualified certificates, policy identifiers, QSCD variants, website certificates, and lifecycle evidence.
What are the qualified certificate policies in ETSI EN 319 411-2?
FAQ on ETSI EN 319 411-2 qualified certificate policies, including QCP-n, QCP-l, QSCD variants, QEVCP-w, QNCP-w, and policy identifiers.
Which QWAC Profile Fits ETSI EN 319 411-2?
Choose between QEVCP-w, QNCP-w, and QNCP-w-gen for qualified website authentication certificates under ETSI EN 319 411-2.