WorkflowGLOBALETSI EN 319 411-2

ETSI EN 319 411-2 eIDAS QTSP supervision workflow

A source-backed workflow for running qualified-certificate supervision tasks before a change, incident, assessment, trusted-list update, or service termination reaches an EU supervisory body.

Use it as operational guidance for certificate-service governance, not for legal interpretation or proof of qualified status.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

ETSI EN 319 411-2 is a qualified-certificate standard, not a full eIDAS supervision rulebook. A must pair the standard's certificate controls with the binding eIDAS supervision, notification, audit, trusted-list, and termination rules. This workflow covers the qualified certificate service boundary, certificate policy evidence, relying-party trusted-list notice, breach and change escalation, termination planning, and conformity-assessment preparation.

Section 1

1. Open the workflow with a qualified-service boundary

Start each supervision review by naming the exact qualified certificate service: natural-person certificate, legal-person certificate, QSCD-backed certificate, or qualified website authentication certificate. Record the issuing TSP, CA hierarchy, certificate policy identifier, CP/CPS versions, subscriber terms, repository location, and certificate population in scope.

This boundary matters because EN 319 411-2 builds on EN 319 411-1 and EN 319 401. A supervision pack should not mix non-qualified CA evidence with qualified certificate evidence unless it shows which inherited Part 1 or EN 319 401 requirement is being reused.

  • Required input: certificate policy identifier such as QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.
  • Required input: CP, CPS, PKI disclosure statement, subscriber agreement, relying-party notice, and repository evidence for the exact service boundary.
  • Owner: certificate policy owner, with sign-off from security operations, CA operations, legal/compliance, and the assessment lead.
  • Output: a scoped supervision intake record that separates EN 319 411-2 qualified-certificate evidence from general EN 319 411-1 certificate controls.
Section 2

2. Triage supervisory-body triggers before operations change

Run this gate before any material change to qualified certificate issuance, certificate profiles, CA hierarchy, QSCD handling, revocation/status services, repository publication, subcontracted service components, or termination planning. Under the amended eIDAS Article 24, a QTSP must inform its supervisory body at least one month before changing the provision of a qualified trust service and at least three months before it intends to cease those activities.

The review should decide whether the event is only a CP/CPS maintenance item, an assessment item, a subscriber or relying-party notice item, or an Article 24 notification. Commission Implementing Regulation (EU) 2025/2530 identifies significant changes to service descriptions, policies, practice statements, terms, architecture, hosting, cryptography, registration, governance, termination, financial resources or insurance, trusted-list data, and third-party arrangements. The notice must describe the change, planned date and time, reasons and supporting evidence where applicable, and updated documents where applicable. The supervisory body may request more information or a conformity-assessment result and may condition permission to implement an intended change. Confirm the national submission channel with the qualified-service compliance owner.

  • Trigger: new or changed qualified certificate policy, certificate profile, OID, CA chain, repository, CPS, PKI disclosure statement, or subscriber terms.
  • Trigger: QSCD status change, remote QSCD component change, or loss of evidence that a certificate request used a QSCD-generated key pair.
  • Trigger: planned termination, status-service discontinuity, last-CRL handling, or a change that affects revocation information beyond certificate validity.
  • Escalation rule: start supervisory-body review early enough to meet the one-month change notice or three-month cessation notice; do not treat those periods as permission to wait until the deadline.
Section 3

3. Handle breach and loss-of-integrity escalation as a timed evidence pack

When a security breach or service disruption has a significant impact on the qualified certificate service or personal data maintained in it, open an incident evidence pack immediately. The current eIDAS Article 24 requires notice to the supervisory body, identifiable affected individuals, and other relevant competent bodies where applicable, without undue delay and in any event within 24 hours of the incident. This differs from the older Article 19 wording that measured 24 hours from awareness.

Do not treat the incident review as a generic security ticket. The pack should identify the trust service affected, certificates or repositories affected, relying-party impact, personal-data impact, known start time, awareness time, containment status, notification decision, and whether subscribers or affected persons also need notice.

  • Required input: incident classification, affected qualified service, affected certificate population, integrity impact, personal-data impact, and awareness timestamp.
  • Decision criterion: whether the breach or disruption has a significant impact on the trust service provided or on personal data maintained in the service.
  • Escalation rule: preserve the incident time and route the notification decision immediately; when the threshold is met, the outer limit is 24 hours from the incident, not 24 hours from discovery.
  • Output: notification decision record, evidence bundle, sent notices where applicable, and post-incident control changes.
Section 4

4. Verify trusted-list, status-service, and termination evidence

Before assessment or supervisory review, confirm that relying-party evidence is current. EN 319 411-2 says relying-party notices should explain that the trust anchor for relying on a certificate as an EU qualified certificate is identified in the service digital identifier of an appropriate EU trusted-list entry for the QTSP.

Also verify continuity evidence. EN 319 411-2 includes requirements for revocation status information beyond certificate validity and maps eIDAS qualified-provider requirements to record retention, certificate databases, revocation publication, and termination planning. Commission Implementing Regulation (EU) 2025/2530 now requires a termination plan for each qualified trust service, review at least every two years and whenever provider or service changes are implemented, coverage of anticipated, unanticipated, partial, and complete termination, and continued access to records needed for legal evidence and validation. A termination or status-service gap should block the workflow until the responsible owner documents the corrective action.

  • Trusted-list check: service digital identifier, QTSP entry, qualified service status, certificate population covered, and date checked.
  • Status-service check: CRL or OCSP method, beyond-validity availability, expired revoked certificate handling, and final-CRL or archive evidence where relevant.
  • Termination check: service-specific plan, last review date, two-year review due date, change-triggered review, record accessibility, certificate database continuity, certificate revocation or uninterrupted transfer route, subscriber and relying-party communications, third-party arrangements, funding or insurance, and supervisory-body verification point.
  • Stop condition: the certificate policy says qualified, but trusted-list, status-service, or termination evidence does not support the claim.
Section 5

5. Close with assessment-ready outputs

The workflow is complete only when the reviewer can hand the assessor or supervisory liaison a compact evidence set. EN 319 411-2 points to ETSI TR 119 411-4 for a conformity assessment checklist, so keep requirement identifiers visible rather than replacing them with informal task names.

Close the record with the decision, source clauses used, evidence files, gaps, owner, next review trigger, and whether a supervisory-body contact, conformity-assessment follow-up, subscriber notice, relying-party notice, or CP/CPS publication update remains open.

  • Output field: service boundary, policy identifier, CP/CPS version, repository URL, and trusted-list evidence reference.
  • Output field: issue type: change, incident, QSCD status, certificate status service, termination, assessment finding, or relying-party notice.
  • Output field: clause or requirement identifier, evidence artifact, accountable owner, approval result, and open gap.
  • Output field: external action needed, such as supervisory-body contact, assessor follow-up, subscriber notice, relying-party notice, or CP/CPS publication.
Primary sources

References and citations

Related guides

Explore more topics

ETSI EN 319 411-2 certificate operations
Operational guide for ETSI EN 319 411-2 qualified certificate services: policy identifiers, identity validation, issuance, QSCD handling, revocation status, and relying-party notices.
ETSI EN 319 411-2 compliance checklist
Compliance checklist for ETSI EN 319 411-2 qualified certificate services, covering policy selection, CP/CPS evidence, identity validation, QSCD status, trusted-list reliance, and certificate status services.
ETSI EN 319 411-2 FAQ for EU Qualified Certificates
Answers to common ETSI EN 319 411-2 questions about EU qualified certificate policies, QSCD use, identity validation, trusted lists, and revocation status services.
ETSI EN 319 411-2 Identity Proofing
How EN 319 411-2 applies identity validation for EU qualified certificates, including QCP natural-person, legal-person, website, and evidence-record checks.
ETSI EN 319 411-2 profile selector
Select the right ETSI EN 319 411-2 qualified certificate policy profile for signatures, seals, QSCD use, and website authentication.
ETSI EN 319 411-2 QSCD Route
When QCP-n-qscd or QCP-l-qscd is the right EN 319 411-2 route, what QSCD evidence is needed, and which certificate-profile claims must stay aligned.
ETSI EN 319 411-2 QTSP supervision evidence workflow
Build an assessment-ready QTSP supervision evidence pack for ETSI EN 319 411-2 qualified certificate services, covering policy identifiers, trusted-list checks, incident records, QSCD evidence, and termination controls.
ETSI EN 319 411-2 Qualified Certificate Scope
Use ETSI EN 319 411-2 to scope EU qualified certificate services by certificate policy, subject type, QSCD use, website authentication profile, and eIDAS context.
ETSI EN 319 411-2 requirements map
Map ETSI EN 319 411-2 requirements for EU qualified certificate services across QCP profiles, CP/CPS documentation, QSCD use, certificate profiles, revocation, and eIDAS Annex A references.
ETSI EN 319 411-2 trusted-list evidence
Build EN 319 411-2 trusted-list evidence for EU qualified certificate reliance: relying-party notice text, QTSP service identifiers, validation records, and change triggers.
ETSI EN 319 411-2 trusted-list validation workflow
Validate an EN 319 411-2 EU qualified-certificate claim by mapping the certificate service to the QTSP trusted-list entry, policy profile, relying-party notice, and status evidence.
ETSI EN 319 411-2 vs eIDAS Qualified Trust Services
Compare ETSI EN 319 411-2 certificate policy requirements with the eIDAS qualified-status, supervision, audit, and trusted-list framework.
ETSI EN 319 411-2 vs EN 319 411-1
Compare ETSI EN 319 411-2 EU qualified certificate requirements with EN 319 411-1 general certificate-service requirements, including policy inheritance, QSCD controls, and CP/CPS evidence reuse.
ETSI EN 319 411-2: Certificate Revocation FAQ
Answer the ETSI EN 319 411-2 revocation question for qualified certificate services: CPS procedures, 24-hour publication, CRL or OCSP status, and evidence to retain.
ETSI EN 319 411-2: end-to-end qualified certificate lifecycle management workflow
Lifecycle workflow for ETSI EN 319 411-2 qualified certificate services, from policy selection and identity validation through issuance, renewal, re-key, modification, revocation, status services, and records.
ETSI EN 319 411-2: Legal vs Natural Person Certs
ETSI EN 319 411-2 separates qualified certificate policies for natural persons, legal persons, QSCD use, and website authentication subscribers.
ETSI EN 319 411-2: QCP, QNCP, and QEVCP Profile Selection
Choose the right ETSI EN 319 411-2 qualified certificate policy profile: QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.
How should QTSPs select an ETSI EN 319 411-2 qualified certificate profile?
A focused FAQ on choosing QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen under ETSI EN 319 411-2.
How should relying parties use trusted lists under ETSI EN 319 411-2?
FAQ on EN 319 411-2 trusted-list reliance for EU qualified certificates: relying-party notices, QTSP service identifiers, validation evidence, and source references.
QSCD Requirements in ETSI EN 319 411-2
How ETSI EN 319 411-2 treats QSCD-backed qualified certificates, including QCP-n-qscd and QCP-l-qscd policies, key-use controls, QSCD verification, and certificate profile evidence.
QTSP Supervision and ETSI EN 319 411-2
How ETSI EN 319 411-2 supports QTSP supervision evidence for qualified certificate services, trusted-list reliance, liability responsibility, incident records, and audit preparation.
Qualified certificates under ETSI EN 319 411-2
FAQ answer for QTSPs on how ETSI EN 319 411-2 treats EU qualified certificates, policy identifiers, QSCD variants, website certificates, and lifecycle evidence.
What are the qualified certificate policies in ETSI EN 319 411-2?
FAQ on ETSI EN 319 411-2 qualified certificate policies, including QCP-n, QCP-l, QSCD variants, QEVCP-w, QNCP-w, and policy identifiers.
Which QWAC Profile Fits ETSI EN 319 411-2?
Choose between QEVCP-w, QNCP-w, and QNCP-w-gen for qualified website authentication certificates under ETSI EN 319 411-2.