Regulation (EU) 2025/2530 adds binding requirements that a standard-only checklist can miss. It requires notification of significant service changes, a risk management framework, and a termination plan for each qualified trust service. These duties sit beside the certificate-policy and lifecycle controls in EN 319 411-2.
For change control, the notification record must cover the change, planned date and time, reasons, supporting evidence where applicable, and updated documents where applicable. The Regulation identifies service policies, practice statements, terms, architecture, hosting, cryptography, registration, governance, termination, trusted-list data, and third-party arrangements as change areas. Article 24(2)(a) of eIDAS requires at least one month's notice before a service change and at least three months before intended cessation.