Artifact GuideGLOBALETSI EN 319 411-2

ETSI EN 319 411-2 vs eIDAS qualified trust services

A comparison of the ETSI certificate-policy standard used for EU qualified certificates and the eIDAS legal framework that grants and supervises qualified trust-service status.

Separate standard-conformance evidence from qualified-status, trusted-list, and supervisory evidence.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
6

Structured answer sets in this page tree.

Primary sources
15

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Use both sources for an EU qualified certificate service, but do not treat them as interchangeable. ETSI EN 319 411-2 V2.6.1 specifies policy and security requirements for issuing, maintaining, and managing the lifecycle of EU qualified certificates. The current eIDAS Regulation, as amended by Regulation (EU) 2024/1183, controls , supervision, conformity assessment, trusted lists, and legal effects. Meeting the ETSI standard can support a conformity assessment; only the supervisory process and trusted-list entry establish that the provider and service hold qualified status.

Side-by-side comparison

ETSI EN 319 411-2 vs eIDAS qualified trust services: what changes?

Compare certificate-policy conformance with the separate qualified-status and trusted-list checks under eIDAS.

Review all sources
First framework
ETSI EN 319 411-2

A European standard for policy and security requirements for TSPs issuing EU qualified certificates.

Second framework
eIDAS qualified trust services

The EU legal framework for qualified trust services, qualified trust service providers, supervision, conformity assessment, and trusted lists.

Comparison row 1

Scope and covered activity

ETSI EN 319 411-2

EN 319 411-2 covers policy and security requirements for TSPs issuing EU qualified certificates, including named qualified certificate policy profiles.

eIDAS qualified trust services

eIDAS covers qualified trust services as a legal category, including qualified certificates for signatures, seals, and website authentication plus the provider status framework around them.

Operational implication

Start by naming both the certificate policy profile and the eIDAS service status being claimed; the standard scope and the legal qualified-service scope are related but not identical.

Comparison row 2

Who must act

ETSI EN 319 411-2

The EN 319 411-2 owner is the certificate-issuing TSP and its CA, RA, repository, revocation, certificate status, CP/CPS, and security-control owners.

eIDAS qualified trust services

The eIDAS owners include the trust service provider seeking or holding , the conformity assessment body, the supervisory body, and the Member State trusted-list function.

Operational implication

Assign standard evidence to certificate-service operators and legal status evidence to the qualified-service governance team; one generic compliance owner will miss handoffs.

Comparison row 3

Trigger or threshold

ETSI EN 319 411-2

EN 319 411-2 is triggered when a TSP issues, or claims conformance for issuing, EU qualified certificates under one of the standard's qualified certificate policy profiles.

eIDAS qualified trust services

eIDAS qualified-service work is triggered when a provider intends to provide a qualified trust service or needs to maintain after it has been granted.

Operational implication

Do not wait until public launch copy is drafted; trigger both reviews when the certificate profile and the intended qualified-service status are selected.

Comparison row 4

Core obligations

ETSI EN 319 411-2

EN 319 411-2 requirements are implemented through certificate policy selection, CP/CPS controls, identity validation, issuance, acceptance, revocation, suspension, certificate status, repository, and QSCD-related evidence where applicable.

eIDAS qualified trust services

eIDAS obligations include notification, conformity assessment, supervisory verification, ongoing audits, change and cessation notices, remedy where required, possible status withdrawal, and trusted-list publication.

Operational implication

Maintain two linked workstreams: certificate-service controls and qualified-status lifecycle controls.

Comparison row 5

Evidence and records

ETSI EN 319 411-2

EN 319 411-2 evidence is the CP/CPS, certificate policy identifier, subscriber and subject validation, certificate issuance, revocation, suspension, certificate status, repository, QSCD indication, and records material.

eIDAS qualified trust services

eIDAS evidence is the conformity assessment report, notification to the supervisory body, supervisory verification, qualified-status grant, and trusted-list entry.

Operational implication

Keep a traceable matrix with separate columns for standard conformance artifacts and legal qualified-status artifacts.

Comparison row 6

Timing and cadence

ETSI EN 319 411-2

EN 319 411-2 timing is driven by certificate lifecycle events such as application, issuance, acceptance, renewal, re-key, modification, revocation, suspension, status service operation, and records archival.

eIDAS qualified trust services

eIDAS timing includes an audit at least every 24 months, at least one month's advance notice of a planned audit, report submission within three working days of receipt, supervisory verification, and the trusted-list update before qualified service provision begins.

Operational implication

Track certificate lifecycle clocks separately from qualified-status audit and supervisory clocks.

Comparison row 7

Assessment or legal route

ETSI EN 319 411-2

EN 319 411-2 can supply requirements for an assessment, contract, or procurement scope. For qualified signature and seal certificates, Regulation (EU) 2025/1943 references V2.6.1 with adaptations as a presumption-of-compliance route, but the standard does not grant legal status.

eIDAS qualified trust services

eIDAS and its implementing acts control the legal effect of referenced standards. Supervisory bodies grant status, can audit, require remedy, and withdraw where the Regulation's requirements are not met.

Operational implication

Use the adapted standard text where an implementing act references it, then keep the conformity assessment, supervisory decision, and trusted-list status as separate evidence. Escalate any standard finding that could affect legal compliance or .

Comparison row 8

Overlap and reuse

ETSI EN 319 411-2

Reuse EN 319 411-2 controls where the same certificate service, policy profile, CP/CPS, CA/RA process, revocation service, and records boundary are unchanged.

eIDAS qualified trust services

Reuse eIDAS qualified-service evidence only where the same provider, service, Member State supervision, qualified-status decision, and trusted-list entry are in scope.

Operational implication

A shared control can reduce duplication, but status evidence, certificate-profile evidence, and trusted-list evidence must remain traceable to the exact source that supports the claim.

Comparison row 9

Practical decision rule

ETSI EN 319 411-2

Use EN 319 411-2 when the question is whether certificate-policy, CP/CPS, lifecycle, QSCD, QWAC, or CA/RA evidence meets the qualified-certificate standard.

eIDAS qualified trust services

Use eIDAS when the question is whether the provider and service have , supervisory verification, conformity assessment evidence, and a trusted-list entry.

Operational implication

Use both only when the same qualified certificate service needs standard-conformance evidence and eIDAS qualified-status evidence.

Practical decision rule

How to choose the controlling source

  • Use EN 319 411-2 when the decision is about certificate policy, CP/CPS, certificate lifecycle operations, QSCD indication, or qualified certificate profile evidence.
  • Use eIDAS when the decision is about , supervisory verification, conformity assessment reports, trusted-list publication, or legal qualified-service wording.
  • Use both only when a specific qualified certificate service needs both standard-conformance evidence and eIDAS qualified-status evidence.
Section 1

What each source controls

Use EN 319 411-2 V2.6.1 when the question is whether a certificate-issuing trust service provider has implemented the policy and security requirements for EU qualified certificates. Its scope covers issuance, maintenance, and lifecycle management. It defines qualified certificate policy families and incorporates requirements from EN 319 411-1 for common CA, registration, repository, revocation, and certificate lifecycle operations.

Use eIDAS when the question is whether a trust service is legally qualified in the EU. Under Article 21, the provider notifies the supervisory body with a conformity assessment report. The supervisory body verifies the provider and service, grants if the requirements are met, and triggers the trusted-list update. The service may begin as a qualified trust service only after that status appears in the trusted list. Commission Implementing Regulation (EU) 2025/1943 gives adapted EN 319 411-2 V2.6.1 requirements a specific legal role for qualified signature and seal certificates: following the referenced standards and adaptations supports a presumption of compliance, while another practice may still be used to demonstrate compliance. That presumption does not replace the Article 21 status process.

  • EN 319 411-2 is evidence for certificate policy and CA operations; it is not the legal act that grants .
  • eIDAS controls supervisory verification, qualified-status grant or withdrawal, trusted-list publication, and qualified-service legal effects.
  • A procurement claim such as "eIDAS qualified" should identify the exact provider and service, then be checked against the relevant national trusted list. An EN 319 411-2 assessment or certificate does not replace that status check.
Section 2

Certificate policy evidence vs qualified-status evidence

EN 319 411-2 evidence should identify the selected qualified certificate policy, its policy object identifier, the certificate profile, and the relevant CP/CPS clauses. Operational evidence should cover the applicable identity validation, issuance, acceptance, revocation or suspension, certificate status, repository, records, and QSCD controls. Because Part 2 incorporates many Part 1 requirements, the crosswalk should cite both standards where a Part 1 control is reused.

eIDAS evidence should show the separate legal-status path: the conformity assessment report, notification to the supervisory body, supervisory verification, the decision granting , and the national trusted-list entry for the exact provider and service. A certificate sample or CP/CPS cannot establish those facts.

  • Keep CP/CPS, registration, identity proofing, certificate profile, QSCD indication, revocation, and certificate status evidence in the EN 319 411-2 file.
  • Keep the conformity assessment report, supervisory notification and correspondence, qualified-status decision, and dated trusted-list verification in the eIDAS qualified-service file.
  • Do not describe a service as qualified until the eIDAS status evidence exists; an ETSI standards audit alone is not enough.
Section 3

Where QCP, QSCD, and QWAC details fit

EN 319 411-2 defines seven reference policies. QCP-n and QCP-l cover qualified certificates for natural and legal persons. QCP-n-qscd and QCP-l-qscd add the requirement that the private key related to the certified public key resides on a qualified signature or seal creation device. QEVCP-w and QNCP-w are qualified website certificate policies tied to CA/Browser Forum EV or Baseline Requirements; QNCP-w-gen is the general-purpose qualified website authentication policy with selected [WEB] requirements.

eIDAS determines whether the issuing provider and certificate service are qualified and sets the Annex requirements for qualified certificates for electronic signatures, electronic seals, and website authentication. The standard profile and the legal service category must both match the claim. For website authentication, Commission Implementing Regulation (EU) 2025/2527 applies from 6 January 2027: it permits EN 319 411-2 V2.6.1 or ETSI TS 119 495 for transport-layer-security authentication outside a web-browser, but points other QWACs, including browser-context certificates, to ETSI TS 119 411-5.

  • For signature or seal certificates, use the QSCD-backed policy only when the private key and related certificate meet the profile's QSCD condition, and retain the required certificate qcStatement and device-status evidence.
  • For website authentication certificates, keep the QEVCP-w, QNCP-w, or QNCP-w-gen policy evidence separate from the eIDAS qualified website authentication service status. EN 319 411-2 also warns that browser vendors or other relying parties may impose additional CA/Browser Forum requirements.
  • Use the trusted list to confirm the provider, service type, service status, and applicable service history. Do not infer current from the provider's name alone.
Section 4

Audit and supervision are not the same control

An EN 319 411-2 assessment can support conformity evidence, but eIDAS supervision has separate legal requirements. Article 20 requires qualified trust service providers to be audited at their own expense at least every 24 months by a conformity assessment body. Under the current text, the provider must submit the report to the supervisory body within three working days of receipt and inform that body at least one month before a planned audit.

The supervisory body may also audit the provider or request another conformity assessment. If the provider fails to meet eIDAS requirements, the body requires a remedy within a set time where applicable and may withdraw when the failure is not remedied. The provider must therefore manage an ongoing supervised status, not a one-time certificate-policy review.

  • Map EN 319 411-2 findings to the conformity assessment report, but keep the supervisory decision and trusted-list update as separate artifacts.
  • Track the 24-month audit cadence, the one-month advance audit notice, and the three-working-day report-submission deadline in the eIDAS evidence calendar.
  • Article 24 also requires at least one month's notice before a change to a qualified service and at least three months' notice before planned cessation. Escalate material CP/CPS, certificate-profile, revocation, QSCD, or service-boundary changes to determine whether either notice applies.
Section 5

Implementation checklist

This checklist is relevant when a product page, RFP answer, audit pack, or relying-party document uses both EN 319 411-2 and eIDAS qualified-service language.

  • Identify the exact certificate service, subscriber type, intended use, and policy profile: QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.
  • Map the CP/CPS, identity validation, issuance, revocation, certificate status, repository, and records evidence to EN 319 411-2 and EN 319 411-1 clauses.
  • Verify the eIDAS qualified-status path for the exact provider and service: conformity assessment report, supervisory notification and verification, qualified-status grant, and trusted-list entry.
  • Match public wording to the evidence. State the EN 319 411-2 edition and assessment scope for a standards claim; use "qualified trust service" only when the current trusted-list status supports that provider and service.
  • Review both files after certificate-profile, QSCD, CA/RA, revocation, repository, supervisory, or trusted-list changes.
Section 6

Common mistakes to avoid

Errors arise when the technical standard and legal status are collapsed into one label. Keep the evidence split so a reader can see whether a claim concerns certificate-policy conformance, qualified-service status, or both.

  • Do not imply that EN 319 411-2 certification automatically makes the provider or service qualified under eIDAS.
  • Do not cite a CP/CPS or audit report as a substitute for the trusted-list status check.
  • Do not mix non-qualified EN 319 411-1 certificate evidence into a qualified-service claim without a clear bridge to EN 319 411-2 and eIDAS.
  • Do not use QWAC, QSCD, QCP, or QTSP as interchangeable labels. State whether the claim concerns a certificate policy, a creation device, a certificate type, a provider, or a qualified service.
Primary sources

References and citations

etsi.org
Referenced sections
  • Grounds the lifecycle and records controls that should be checked before reusing certificate-service evidence.
"Records archival"
etsi.org
Referenced sections
  • Grounds when EN 319 411-2 controls the certificate-policy side of the decision.
"Certificate Policy"
eur-lex.europa.eu
Referenced sections
  • Grounds that qualified service provision begins after qualified status appears in the trusted lists.
"after the qualified status has been indicated"
eur-lex.europa.eu
Referenced sections
  • Grounds the provider-and-service trusted-list boundary for eIDAS evidence reuse.
"information related to the qualified trust services"
eur-lex.europa.eu
Referenced sections
  • Grounds the legal definition of a qualified trust service provider.
"granted the qualified status by the supervisory body"
eur-lex.europa.eu
Referenced sections
  • Grounds the supervisory body's role in ensuring qualified services meet eIDAS requirements.
"supervise qualified trust service providers"
eur-lex.europa.eu
Referenced sections
  • Article 20 grounds the 24-month audit cadence, one-month advance audit notice, three-working-day report submission, supervisory powers, remedy, and status-withdrawal rules. Article 24 grounds the advance notices for changing or ceasing a qualified service.
"audited at their own expense at least every 24 months"
eur-lex.europa.eu
Referenced sections
  • Grounds the conformity assessment, supervisory verification, qualified-status grant, and trusted-list evidence.
"establish, maintain and publish trusted lists"
eur-lex.europa.eu
Referenced sections
  • Grounds eIDAS requirements for qualified certificates for electronic signatures, electronic seals, and website authentication.
"qualified certificate for website authentication"
Related guides

Explore more topics

eIDAS QTSP supervision workflow for ETSI EN 319 411-2
Operational workflow for qualified trust service providers using ETSI EN 319 411-2 to manage supervisory-body changes, incidents, termination evidence, trusted-list checks, and assessment records.
ETSI EN 319 411-2 certificate operations
Operational guide for ETSI EN 319 411-2 qualified certificate services: policy identifiers, identity validation, issuance, QSCD handling, revocation status, and relying-party notices.
ETSI EN 319 411-2 compliance checklist
Compliance checklist for ETSI EN 319 411-2 qualified certificate services, covering policy selection, CP/CPS evidence, identity validation, QSCD status, trusted-list reliance, and certificate status services.
ETSI EN 319 411-2 FAQ for EU Qualified Certificates
Answers to common ETSI EN 319 411-2 questions about EU qualified certificate policies, QSCD use, identity validation, trusted lists, and revocation status services.
ETSI EN 319 411-2 Identity Proofing
How EN 319 411-2 applies identity validation for EU qualified certificates, including QCP natural-person, legal-person, website, and evidence-record checks.
ETSI EN 319 411-2 profile selector
Select the right ETSI EN 319 411-2 qualified certificate policy profile for signatures, seals, QSCD use, and website authentication.
ETSI EN 319 411-2 QSCD Route
When QCP-n-qscd or QCP-l-qscd is the right EN 319 411-2 route, what QSCD evidence is needed, and which certificate-profile claims must stay aligned.
ETSI EN 319 411-2 QTSP supervision evidence workflow
Build an assessment-ready QTSP supervision evidence pack for ETSI EN 319 411-2 qualified certificate services, covering policy identifiers, trusted-list checks, incident records, QSCD evidence, and termination controls.
ETSI EN 319 411-2 Qualified Certificate Scope
Use ETSI EN 319 411-2 to scope EU qualified certificate services by certificate policy, subject type, QSCD use, website authentication profile, and eIDAS context.
ETSI EN 319 411-2 requirements map
Map ETSI EN 319 411-2 requirements for EU qualified certificate services across QCP profiles, CP/CPS documentation, QSCD use, certificate profiles, revocation, and eIDAS Annex A references.
ETSI EN 319 411-2 trusted-list evidence
Build EN 319 411-2 trusted-list evidence for EU qualified certificate reliance: relying-party notice text, QTSP service identifiers, validation records, and change triggers.
ETSI EN 319 411-2 trusted-list validation workflow
Validate an EN 319 411-2 EU qualified-certificate claim by mapping the certificate service to the QTSP trusted-list entry, policy profile, relying-party notice, and status evidence.
ETSI EN 319 411-2 vs EN 319 411-1
Compare ETSI EN 319 411-2 EU qualified certificate requirements with EN 319 411-1 general certificate-service requirements, including policy inheritance, QSCD controls, and CP/CPS evidence reuse.
ETSI EN 319 411-2: Certificate Revocation FAQ
Answer the ETSI EN 319 411-2 revocation question for qualified certificate services: CPS procedures, 24-hour publication, CRL or OCSP status, and evidence to retain.
ETSI EN 319 411-2: end-to-end qualified certificate lifecycle management workflow
Lifecycle workflow for ETSI EN 319 411-2 qualified certificate services, from policy selection and identity validation through issuance, renewal, re-key, modification, revocation, status services, and records.
ETSI EN 319 411-2: Legal vs Natural Person Certs
ETSI EN 319 411-2 separates qualified certificate policies for natural persons, legal persons, QSCD use, and website authentication subscribers.
ETSI EN 319 411-2: QCP, QNCP, and QEVCP Profile Selection
Choose the right ETSI EN 319 411-2 qualified certificate policy profile: QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.
How should QTSPs select an ETSI EN 319 411-2 qualified certificate profile?
A focused FAQ on choosing QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen under ETSI EN 319 411-2.
How should relying parties use trusted lists under ETSI EN 319 411-2?
FAQ on EN 319 411-2 trusted-list reliance for EU qualified certificates: relying-party notices, QTSP service identifiers, validation evidence, and source references.
QSCD Requirements in ETSI EN 319 411-2
How ETSI EN 319 411-2 treats QSCD-backed qualified certificates, including QCP-n-qscd and QCP-l-qscd policies, key-use controls, QSCD verification, and certificate profile evidence.
QTSP Supervision and ETSI EN 319 411-2
How ETSI EN 319 411-2 supports QTSP supervision evidence for qualified certificate services, trusted-list reliance, liability responsibility, incident records, and audit preparation.
Qualified certificates under ETSI EN 319 411-2
FAQ answer for QTSPs on how ETSI EN 319 411-2 treats EU qualified certificates, policy identifiers, QSCD variants, website certificates, and lifecycle evidence.
What are the qualified certificate policies in ETSI EN 319 411-2?
FAQ on ETSI EN 319 411-2 qualified certificate policies, including QCP-n, QCP-l, QSCD variants, QEVCP-w, QNCP-w, and policy identifiers.
Which QWAC Profile Fits ETSI EN 319 411-2?
Choose between QEVCP-w, QNCP-w, and QNCP-w-gen for qualified website authentication certificates under ETSI EN 319 411-2.