Use ETSI EN 319 411-2 V2.6.1 for the additional policy and security requirements that apply to EU qualified certificate profiles. Use ETSI EN 319 411-1 V1.5.1 for the general requirements and underlying policy families that Part 2 incorporates. A states the requirements and application boundary for the selected service. Part 2 is not a standalone checklist: its QCP, QSCD-backed, and qualified website certificate policies inherit specified Part 1 requirements and add qualified-certificate conditions. Neither standard, by itself, grants qualified status under eIDAS.
Document comparison
ETSI EN 319 411-2 vs ETSI EN 319 411-1
Decide what EN 319 411-2 adds to the EN 319 411-1 policy, evidence, and assurance controls it incorporates.
Part 2 covers issuance, maintenance, and lifecycle management of EU qualified certificates for natural persons, legal persons, QSCD-backed signature or seal routes, and website authentication.
Part 1 specifies generally applicable policy and security requirements for TSPs issuing public key certificates, including trusted website certificates and general certificate lifecycle management.
Start with the and service scope. A Part 2 profile needs both its additional requirements and the Part 1 controls it incorporates; a general certificate service can remain within Part 1 when no qualified-certificate policy applies.
Part 2 defines QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, and QNCP-w-gen. Each policy states which Part 1 family it builds on and what qualified-certificate provisions it adds.
Part 1 defines NCP, NCP+, LCP, EVCP, DVCP, OVCP, and IVCP. The CP states what applies; the CPS describes how the TSP implements the applicable requirements.
Map the Part 2 policy to its stated Part 1 base, then verify the policy object identifier, certificate profile, subscriber type, and any QSCD or website-authentication condition before reusing evidence.
The unadapted Part 2 text describes physical-presence or equivalent-assurance routes for natural-person and legal-person identity checks, and QWAC routes also verify the subscriber's link with the domain name. For the Regulation (EU) 2025/1943 presumption-of-compliance route for qualified signature and seal certificates, the Regulation replaces those Part 2 identity clauses with verification under the implementing acts adopted pursuant to eIDAS Article 24(1c).
Part 1 covers initial identity validation, naming, subscribers and subjects, registration service responsibilities, certificate applications, and re-key or revocation request authentication for general certificate services.
For qualified signature and seal certificates, map registration evidence to current eIDAS Article 24 and the Regulation (EU) 2025/1943 adaptations; the unadapted physical-presence or equivalent-assurance wording is not the complete presumption-of-compliance route. For a website policy, also retain evidence of the subscriber's link to the domain name.
Part 2 distinguishes QSCD-backed profiles and says the QSCD qcStatement belongs in QCP-n-qscd and QCP-l-qscd certificates, while it must not be included for certificates not issued under those requirements.
Keep the QSCD route as a Part 2 decision. A certificate sample, device-status check, and CP/CPS statement should show when the QSCD-backed profile applies.
Part 2 evidence should include the profile decision, CP/CPS clauses, certificate samples, policy identifiers, applicable qcStatements, QSCD evidence where required, website subscriber-to-domain evidence where relevant, and conformity-assessment findings.
Part 1 evidence should include CP and CPS versions, identifiers, subscriber agreements, identity validation records, RA delegation evidence, issuance logs, CRL or OCSP records, revocation files, repository publication records, audit logs, and records archival evidence.
Part 2 repeatedly incorporates Part 1 lifecycle controls for publication, identity validation, certificate application, issuance, revocation requests, CRL, OCSP, business matters, and policy management, then adds qualified-profile constraints.
Part 1 is the operational backbone for certification services: registration, certificate generation, dissemination, revocation management, revocation status, repositories, and records archival.
Reuse operational evidence where Part 2 points back to Part 1, but keep a Part 2 row showing the qualified profile or qualified-service condition that made the reuse valid.
Part 2 maps EU qualified certificate policies to eIDAS requirements, but its annex is not a definitive legal conformance statement. Regulation (EU) 2025/1943 separately references V2.6.1 with adaptations for qualified signature and seal certificates.
Part 1 is a technical standard for general certificate-service policy and security requirements. Regulation (EU) 2025/1943 also adapts Part 1 provisions incorporated into the qualified signature and seal route.
For the legal presumption-of-compliance route, crosswalk the two ETSI editions together with the implementing regulation's adaptations. Keep supervisory, trusted-list, conformity-assessment, and qualified-status evidence separate.
Part 2 can reuse common PKI evidence after the crosswalk identifies the qualified , the Part 1 provision being incorporated, and any additional website-authentication or QSCD condition.
Part 1 evidence can be reused for common PKI operations, such as lifecycle processing, revocation services, repositories, audit logging, and records archival, when the service boundary and policy profile match.
Reuse the operational artifact, not the conclusion. The same log or CP/CPS section may support both sides, but the qualified-certificate conclusion needs its own cited row.
Do not collapse the standards into one checklist. Start with the qualified profile and public claim, then show exactly which Part 1 controls are reused by the Part 2 qualified certificate claim.
Part 2 covers issuance, maintenance, and lifecycle management of EU qualified certificates for natural persons, legal persons, QSCD-backed signature or seal routes, and website authentication.
Part 1 specifies generally applicable policy and security requirements for TSPs issuing public key certificates, including trusted website certificates and general certificate lifecycle management.
Start with the and service scope. A Part 2 profile needs both its additional requirements and the Part 1 controls it incorporates; a general certificate service can remain within Part 1 when no qualified-certificate policy applies.
Part 2 defines QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, and QNCP-w-gen. Each policy states which Part 1 family it builds on and what qualified-certificate provisions it adds.
Part 1 defines NCP, NCP+, LCP, EVCP, DVCP, OVCP, and IVCP. The CP states what applies; the CPS describes how the TSP implements the applicable requirements.
Map the Part 2 policy to its stated Part 1 base, then verify the policy object identifier, certificate profile, subscriber type, and any QSCD or website-authentication condition before reusing evidence.
The unadapted Part 2 text describes physical-presence or equivalent-assurance routes for natural-person and legal-person identity checks, and QWAC routes also verify the subscriber's link with the domain name. For the Regulation (EU) 2025/1943 presumption-of-compliance route for qualified signature and seal certificates, the Regulation replaces those Part 2 identity clauses with verification under the implementing acts adopted pursuant to eIDAS Article 24(1c).
Part 1 covers initial identity validation, naming, subscribers and subjects, registration service responsibilities, certificate applications, and re-key or revocation request authentication for general certificate services.
For qualified signature and seal certificates, map registration evidence to current eIDAS Article 24 and the Regulation (EU) 2025/1943 adaptations; the unadapted physical-presence or equivalent-assurance wording is not the complete presumption-of-compliance route. For a website policy, also retain evidence of the subscriber's link to the domain name.
Part 2 distinguishes QSCD-backed profiles and says the QSCD qcStatement belongs in QCP-n-qscd and QCP-l-qscd certificates, while it must not be included for certificates not issued under those requirements.
Keep the QSCD route as a Part 2 decision. A certificate sample, device-status check, and CP/CPS statement should show when the QSCD-backed profile applies.
Part 2 evidence should include the profile decision, CP/CPS clauses, certificate samples, policy identifiers, applicable qcStatements, QSCD evidence where required, website subscriber-to-domain evidence where relevant, and conformity-assessment findings.
Part 1 evidence should include CP and CPS versions, identifiers, subscriber agreements, identity validation records, RA delegation evidence, issuance logs, CRL or OCSP records, revocation files, repository publication records, audit logs, and records archival evidence.
Part 2 repeatedly incorporates Part 1 lifecycle controls for publication, identity validation, certificate application, issuance, revocation requests, CRL, OCSP, business matters, and policy management, then adds qualified-profile constraints.
Part 1 is the operational backbone for certification services: registration, certificate generation, dissemination, revocation management, revocation status, repositories, and records archival.
Reuse operational evidence where Part 2 points back to Part 1, but keep a Part 2 row showing the qualified profile or qualified-service condition that made the reuse valid.
Part 2 maps EU qualified certificate policies to eIDAS requirements, but its annex is not a definitive legal conformance statement. Regulation (EU) 2025/1943 separately references V2.6.1 with adaptations for qualified signature and seal certificates.
Part 1 is a technical standard for general certificate-service policy and security requirements. Regulation (EU) 2025/1943 also adapts Part 1 provisions incorporated into the qualified signature and seal route.
For the legal presumption-of-compliance route, crosswalk the two ETSI editions together with the implementing regulation's adaptations. Keep supervisory, trusted-list, conformity-assessment, and qualified-status evidence separate.
Part 2 can reuse common PKI evidence after the crosswalk identifies the qualified , the Part 1 provision being incorporated, and any additional website-authentication or QSCD condition.
Part 1 evidence can be reused for common PKI operations, such as lifecycle processing, revocation services, repositories, audit logging, and records archival, when the service boundary and policy profile match.
Reuse the operational artifact, not the conclusion. The same log or CP/CPS section may support both sides, but the qualified-certificate conclusion needs its own cited row.
Do not collapse the standards into one checklist. Start with the qualified profile and public claim, then show exactly which Part 1 controls are reused by the Part 2 qualified certificate claim.
When should teams compare ETSI EN 319 411-2 with ETSI EN 319 411-1?
Compare the standards before a trust service provider, product team, auditor, or procurement reviewer reuses general certificate-service evidence for an EU qualified certificate claim.
The decision is not which standard replaces the other. Identify the Part 2 policy first, then trace its inherited Part 1 policy requirements and lifecycle clauses. Keep the additional Part 2 conditions visible in the crosswalk. For qualified signature and seal certificates, also apply the adaptations in Commission Implementing Regulation (EU) 2025/1943. Those adaptations change or add requirements in both Part 2 and the Part 1 text it incorporates, so a crosswalk based only on the two published ETSI PDFs is incomplete for the regulation's presumption-of-compliance route.
Start with the qualified profile: QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen belong in the Part 2 analysis.
Separate legal qualified-status proof and trusted-list evidence from the standards crosswalk. Within the crosswalk, separate the Part 2 profile and QSCD or website-certificate conditions from common PKI operations reused from Part 1.
For each reused control, cite the Part 2 clause that calls up Part 1 and the Part 1 clause containing the operational requirement.
Decision rules for qualified and general certificate services
Use Part 2 when the certificate is issued under an EU qualified defined there. Use Part 1 for the general certificate-service requirements and policy families that apply directly to a Part 1 service or are incorporated by a Part 2 policy.
Part 2 expressly builds its policies on Part 1. QCP-n and QCP-l include NCP requirements, or NCP+ where the implementation requires a secure cryptographic device. QCP-n-qscd and QCP-l-qscd include the corresponding QCP requirements and NCP+ requirements. QEVCP-w builds on EVCP; QNCP-w builds on NCP plus IVCP or OVCP; QNCP-w-gen builds on NCP plus selected Part 1 [WEB] requirements.
If the service issues EU qualified certificates, document the Part 2 policy profile and any QSCD or website-certificate route before reusing Part 1 evidence. Keep eIDAS qualified status and trusted-list proof in a separate linked record.
If the service does not issue EU qualified certificates, apply Part 1 or another applicable policy framework without importing Part 2 requirements by acronym or product label.
When Part 2 calls up a Part 1 clause, cite both clauses and record whether Part 2 adds, narrows, or conditions the inherited requirement.
A states what requirements and application boundary apply; a Certification Practice Statement explains how the issuing TSP implements them. Reuse a CP/CPS section only when it covers the same service, policy identifier, certificate profile, participants, operating boundary, and assessment period.
For Part 2, add the selected qualified , its inherited Part 1 policy family, and the Part 2 conditions for identity, certificate content, QSCD, or website authentication that apply. Keep Part 1 evidence for common CA and registration responsibilities, subscribers and subjects, naming, application and issuance, acceptance, revocation, status services, repositories, and records archival.
Name the qualified certificate service, Part 2 profile, , certificate profile, CA, RA or registration service provider, repository, and revocation-status service in scope.
Record whether the certificate is for a natural person, a legal person, a QSCD-backed signature or seal route, or website authentication, then select the matching policy rather than inferring it from the certificate's marketing name.
Separate additional Part 2 evidence from inherited Part 1 evidence so the audit file shows which qualified-certificate condition each artifact supports.
Version evidence by standard version, CP/CPS version, certificate profile, assessment period, and certificate service boundary.
Evidence that belongs on each side of the comparison
Build an evidence map instead of merging the standards into one checklist. A shared operational record can support both, but each mapping should identify the Part 2 clause, the inherited Part 1 clause, any Part 2 addition, and the claim the record proves.
For Part 2, keep the profile decision, policy identifier, certificate sample, applicable qcStatements, identity-route evidence, QSCD evidence for QCP-n-qscd or QCP-l-qscd, and domain-link evidence for website policies. For Part 1, keep CP and CPS versions, subscriber agreements, identity validation records, registration delegation, issuance logs, CRL or OCSP records, revocation files, repository records, key-management records, audit logs, and archival evidence. Keep legal qualified-status and trusted-list proof linked but outside the standards-conformance conclusion.
Mark each evidence item as an additional Part 2 control, an inherited Part 1 control, or a shared artifact, and cite the relevant clauses.
Do not treat a Part 1 artifact as proof of the full Part 2 profile. Record the Part 2 provision that permits reuse and any additional condition that remains to be shown.
Do not include the QSCD qcStatement route unless the certificate is issued under a QCP-n-qscd or QCP-l-qscd profile.
Review the crosswalk after CP/CPS changes, qualified profile changes, RA changes, revocation-service changes, key-management changes, trusted-list changes, or conformity-assessment scope changes.
Comparison checklist for qualified certificate teams
Use this checklist for a CP/CPS update, qualified certificate service review, conformity assessment evidence pack, or procurement response that mentions both standards.
Identify which Part 2 policy profile applies: QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.
List the certificate service, object identifier, CP/CPS version, certificate profile, CA, RA, repository, and status service covered by EN 319 411-1.
Create a row for every shared operation, including identity validation, issuance, acceptance, revocation, status services, records archival, and CA or RA termination.
Attach the evidence artifact to the row: CP/CPS text, subscriber record, validation record, certificate sample, CRL or OCSP record, audit log, or conformity-assessment finding. Link trusted-list proof separately because it supports eIDAS status, not Part 1 or Part 2 conformance by itself.
Flag unsupported reuse where Part 1 evidence proves ordinary certificate-service operation but does not prove the qualified certificate claim.
Comparison mistakes that create qualified-certificate audit gaps
Audit gaps appear when Part 2 is treated as a qualified label on an unchanged Part 1 file. Part 2 is narrower because it addresses EU qualified certificates, but it also depends on Part 1. The crosswalk must show both the inherited control and the additional qualified-certificate condition.
Do not call a service qualified because it satisfies either standard. Part 2 profile evidence is needed for the standards claim, while eIDAS supervisory status and trusted-list evidence support the legal qualified-service claim.
Do not hide QCP, QWAC, or QSCD profile differences behind a vague CP/CPS title.
Do not reuse identity validation, revocation, repository, or audit-log evidence unless the certificate service boundary and policy profile match.
Do not mix CA/Browser Forum web-certificate requirements, qualified website-authentication certificate requirements, and ordinary certificate-policy requirements without a row-level source reference.
Primary ETSI source for general policy, risk assessment, management, security, incident, continuity, and audit evidence requirements for trust service providers.
"General Policy Requirements for Trust Service Providers"