ETSI EN 319 411-2 vs eIDAS qualified trust services
A comparison of the ETSI certificate-policy standard used for EU qualified certificates and the eIDAS legal framework that grants and supervises qualified trust-service status.
Separate standard-conformance evidence from qualified-status, trusted-list, and supervisory evidence.
Use both sources for an EU qualified certificate service, but do not treat them as interchangeable. ETSI EN 319 411-2 V2.6.1 specifies policy and security requirements for issuing, maintaining, and managing the lifecycle of EU qualified certificates. The current eIDAS Regulation, as amended by Regulation (EU) 2024/1183, controls , supervision, conformity assessment, trusted lists, and legal effects. Meeting the ETSI standard can support a conformity assessment; only the supervisory process and trusted-list entry establish that the provider and service hold qualified status.
Side-by-side comparison
ETSI EN 319 411-2 vs eIDAS qualified trust services: what changes?
Compare certificate-policy conformance with the separate qualified-status and trusted-list checks under eIDAS.
EN 319 411-2 covers policy and security requirements for TSPs issuing EU qualified certificates, including named qualified certificate policy profiles.
eIDAS covers qualified trust services as a legal category, including qualified certificates for signatures, seals, and website authentication plus the provider status framework around them.
Start by naming both the certificate policy profile and the eIDAS service status being claimed; the standard scope and the legal qualified-service scope are related but not identical.
The eIDAS owners include the trust service provider seeking or holding , the conformity assessment body, the supervisory body, and the Member State trusted-list function.
Assign standard evidence to certificate-service operators and legal status evidence to the qualified-service governance team; one generic compliance owner will miss handoffs.
EN 319 411-2 is triggered when a TSP issues, or claims conformance for issuing, EU qualified certificates under one of the standard's qualified certificate policy profiles.
Do not wait until public launch copy is drafted; trigger both reviews when the certificate profile and the intended qualified-service status are selected.
eIDAS obligations include notification, conformity assessment, supervisory verification, ongoing audits, change and cessation notices, remedy where required, possible status withdrawal, and trusted-list publication.
EN 319 411-2 evidence is the CP/CPS, certificate policy identifier, subscriber and subject validation, certificate issuance, revocation, suspension, certificate status, repository, QSCD indication, and records material.
eIDAS evidence is the conformity assessment report, notification to the supervisory body, supervisory verification, qualified-status grant, and trusted-list entry.
EN 319 411-2 timing is driven by certificate lifecycle events such as application, issuance, acceptance, renewal, re-key, modification, revocation, suspension, status service operation, and records archival.
eIDAS timing includes an audit at least every 24 months, at least one month's advance notice of a planned audit, report submission within three working days of receipt, supervisory verification, and the trusted-list update before qualified service provision begins.
EN 319 411-2 can supply requirements for an assessment, contract, or procurement scope. For qualified signature and seal certificates, Regulation (EU) 2025/1943 references V2.6.1 with adaptations as a presumption-of-compliance route, but the standard does not grant legal status.
eIDAS and its implementing acts control the legal effect of referenced standards. Supervisory bodies grant status, can audit, require remedy, and withdraw where the Regulation's requirements are not met.
Use the adapted standard text where an implementing act references it, then keep the conformity assessment, supervisory decision, and trusted-list status as separate evidence. Escalate any standard finding that could affect legal compliance or .
Reuse EN 319 411-2 controls where the same certificate service, policy profile, CP/CPS, CA/RA process, revocation service, and records boundary are unchanged.
Reuse eIDAS qualified-service evidence only where the same provider, service, Member State supervision, qualified-status decision, and trusted-list entry are in scope.
A shared control can reduce duplication, but status evidence, certificate-profile evidence, and trusted-list evidence must remain traceable to the exact source that supports the claim.
Use EN 319 411-2 when the question is whether certificate-policy, CP/CPS, lifecycle, QSCD, QWAC, or CA/RA evidence meets the qualified-certificate standard.
Use eIDAS when the question is whether the provider and service have , supervisory verification, conformity assessment evidence, and a trusted-list entry.
EN 319 411-2 covers policy and security requirements for TSPs issuing EU qualified certificates, including named qualified certificate policy profiles.
eIDAS covers qualified trust services as a legal category, including qualified certificates for signatures, seals, and website authentication plus the provider status framework around them.
Start by naming both the certificate policy profile and the eIDAS service status being claimed; the standard scope and the legal qualified-service scope are related but not identical.
The eIDAS owners include the trust service provider seeking or holding , the conformity assessment body, the supervisory body, and the Member State trusted-list function.
Assign standard evidence to certificate-service operators and legal status evidence to the qualified-service governance team; one generic compliance owner will miss handoffs.
EN 319 411-2 is triggered when a TSP issues, or claims conformance for issuing, EU qualified certificates under one of the standard's qualified certificate policy profiles.
Do not wait until public launch copy is drafted; trigger both reviews when the certificate profile and the intended qualified-service status are selected.
eIDAS obligations include notification, conformity assessment, supervisory verification, ongoing audits, change and cessation notices, remedy where required, possible status withdrawal, and trusted-list publication.
EN 319 411-2 evidence is the CP/CPS, certificate policy identifier, subscriber and subject validation, certificate issuance, revocation, suspension, certificate status, repository, QSCD indication, and records material.
eIDAS evidence is the conformity assessment report, notification to the supervisory body, supervisory verification, qualified-status grant, and trusted-list entry.
EN 319 411-2 timing is driven by certificate lifecycle events such as application, issuance, acceptance, renewal, re-key, modification, revocation, suspension, status service operation, and records archival.
eIDAS timing includes an audit at least every 24 months, at least one month's advance notice of a planned audit, report submission within three working days of receipt, supervisory verification, and the trusted-list update before qualified service provision begins.
EN 319 411-2 can supply requirements for an assessment, contract, or procurement scope. For qualified signature and seal certificates, Regulation (EU) 2025/1943 references V2.6.1 with adaptations as a presumption-of-compliance route, but the standard does not grant legal status.
eIDAS and its implementing acts control the legal effect of referenced standards. Supervisory bodies grant status, can audit, require remedy, and withdraw where the Regulation's requirements are not met.
Use the adapted standard text where an implementing act references it, then keep the conformity assessment, supervisory decision, and trusted-list status as separate evidence. Escalate any standard finding that could affect legal compliance or .
Reuse EN 319 411-2 controls where the same certificate service, policy profile, CP/CPS, CA/RA process, revocation service, and records boundary are unchanged.
Reuse eIDAS qualified-service evidence only where the same provider, service, Member State supervision, qualified-status decision, and trusted-list entry are in scope.
A shared control can reduce duplication, but status evidence, certificate-profile evidence, and trusted-list evidence must remain traceable to the exact source that supports the claim.
Use EN 319 411-2 when the question is whether certificate-policy, CP/CPS, lifecycle, QSCD, QWAC, or CA/RA evidence meets the qualified-certificate standard.
Use eIDAS when the question is whether the provider and service have , supervisory verification, conformity assessment evidence, and a trusted-list entry.
Use EN 319 411-2 when the decision is about certificate policy, CP/CPS, certificate lifecycle operations, QSCD indication, or qualified certificate profile evidence.
Use eIDAS when the decision is about , supervisory verification, conformity assessment reports, trusted-list publication, or legal qualified-service wording.
Use both only when a specific qualified certificate service needs both standard-conformance evidence and eIDAS qualified-status evidence.
Use EN 319 411-2 V2.6.1 when the question is whether a certificate-issuing trust service provider has implemented the policy and security requirements for EU qualified certificates. Its scope covers issuance, maintenance, and lifecycle management. It defines qualified certificate policy families and incorporates requirements from EN 319 411-1 for common CA, registration, repository, revocation, and certificate lifecycle operations.
Use eIDAS when the question is whether a trust service is legally qualified in the EU. Under Article 21, the provider notifies the supervisory body with a conformity assessment report. The supervisory body verifies the provider and service, grants if the requirements are met, and triggers the trusted-list update. The service may begin as a qualified trust service only after that status appears in the trusted list. Commission Implementing Regulation (EU) 2025/1943 gives adapted EN 319 411-2 V2.6.1 requirements a specific legal role for qualified signature and seal certificates: following the referenced standards and adaptations supports a presumption of compliance, while another practice may still be used to demonstrate compliance. That presumption does not replace the Article 21 status process.
EN 319 411-2 is evidence for certificate policy and CA operations; it is not the legal act that grants .
eIDAS controls supervisory verification, qualified-status grant or withdrawal, trusted-list publication, and qualified-service legal effects.
A procurement claim such as "eIDAS qualified" should identify the exact provider and service, then be checked against the relevant national trusted list. An EN 319 411-2 assessment or certificate does not replace that status check.
Certificate policy evidence vs qualified-status evidence
EN 319 411-2 evidence should identify the selected qualified certificate policy, its policy object identifier, the certificate profile, and the relevant CP/CPS clauses. Operational evidence should cover the applicable identity validation, issuance, acceptance, revocation or suspension, certificate status, repository, records, and QSCD controls. Because Part 2 incorporates many Part 1 requirements, the crosswalk should cite both standards where a Part 1 control is reused.
eIDAS evidence should show the separate legal-status path: the conformity assessment report, notification to the supervisory body, supervisory verification, the decision granting , and the national trusted-list entry for the exact provider and service. A certificate sample or CP/CPS cannot establish those facts.
Keep CP/CPS, registration, identity proofing, certificate profile, QSCD indication, revocation, and certificate status evidence in the EN 319 411-2 file.
Keep the conformity assessment report, supervisory notification and correspondence, qualified-status decision, and dated trusted-list verification in the eIDAS qualified-service file.
Do not describe a service as qualified until the eIDAS status evidence exists; an ETSI standards audit alone is not enough.
EN 319 411-2 defines seven reference policies. QCP-n and QCP-l cover qualified certificates for natural and legal persons. QCP-n-qscd and QCP-l-qscd add the requirement that the private key related to the certified public key resides on a qualified signature or seal creation device. QEVCP-w and QNCP-w are qualified website certificate policies tied to CA/Browser Forum EV or Baseline Requirements; QNCP-w-gen is the general-purpose qualified website authentication policy with selected [WEB] requirements.
eIDAS determines whether the issuing provider and certificate service are qualified and sets the Annex requirements for qualified certificates for electronic signatures, electronic seals, and website authentication. The standard profile and the legal service category must both match the claim. For website authentication, Commission Implementing Regulation (EU) 2025/2527 applies from 6 January 2027: it permits EN 319 411-2 V2.6.1 or ETSI TS 119 495 for transport-layer-security authentication outside a web-browser, but points other QWACs, including browser-context certificates, to ETSI TS 119 411-5.
For signature or seal certificates, use the QSCD-backed policy only when the private key and related certificate meet the profile's QSCD condition, and retain the required certificate qcStatement and device-status evidence.
For website authentication certificates, keep the QEVCP-w, QNCP-w, or QNCP-w-gen policy evidence separate from the eIDAS qualified website authentication service status. EN 319 411-2 also warns that browser vendors or other relying parties may impose additional CA/Browser Forum requirements.
Use the trusted list to confirm the provider, service type, service status, and applicable service history. Do not infer current from the provider's name alone.
An EN 319 411-2 assessment can support conformity evidence, but eIDAS supervision has separate legal requirements. Article 20 requires qualified trust service providers to be audited at their own expense at least every 24 months by a conformity assessment body. Under the current text, the provider must submit the report to the supervisory body within three working days of receipt and inform that body at least one month before a planned audit.
The supervisory body may also audit the provider or request another conformity assessment. If the provider fails to meet eIDAS requirements, the body requires a remedy within a set time where applicable and may withdraw when the failure is not remedied. The provider must therefore manage an ongoing supervised status, not a one-time certificate-policy review.
Map EN 319 411-2 findings to the conformity assessment report, but keep the supervisory decision and trusted-list update as separate artifacts.
Track the 24-month audit cadence, the one-month advance audit notice, and the three-working-day report-submission deadline in the eIDAS evidence calendar.
Article 24 also requires at least one month's notice before a change to a qualified service and at least three months' notice before planned cessation. Escalate material CP/CPS, certificate-profile, revocation, QSCD, or service-boundary changes to determine whether either notice applies.
This checklist is relevant when a product page, RFP answer, audit pack, or relying-party document uses both EN 319 411-2 and eIDAS qualified-service language.
Identify the exact certificate service, subscriber type, intended use, and policy profile: QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.
Map the CP/CPS, identity validation, issuance, revocation, certificate status, repository, and records evidence to EN 319 411-2 and EN 319 411-1 clauses.
Verify the eIDAS qualified-status path for the exact provider and service: conformity assessment report, supervisory notification and verification, qualified-status grant, and trusted-list entry.
Match public wording to the evidence. State the EN 319 411-2 edition and assessment scope for a standards claim; use "qualified trust service" only when the current trusted-list status supports that provider and service.
Review both files after certificate-profile, QSCD, CA/RA, revocation, repository, supervisory, or trusted-list changes.
Errors arise when the technical standard and legal status are collapsed into one label. Keep the evidence split so a reader can see whether a claim concerns certificate-policy conformance, qualified-service status, or both.
Do not imply that EN 319 411-2 certification automatically makes the provider or service qualified under eIDAS.
Do not cite a CP/CPS or audit report as a substitute for the trusted-list status check.
Do not mix non-qualified EN 319 411-1 certificate evidence into a qualified-service claim without a clear bridge to EN 319 411-2 and eIDAS.
Do not use QWAC, QSCD, QCP, or QTSP as interchangeable labels. State whether the claim concerns a certificate policy, a creation device, a certificate type, a provider, or a qualified service.