Artifact GuideGLOBALETSI EN 319 411-2

ETSI EN 319 411-2 vs ETSI EN 319 411-1

A focused comparison of Part 2 requirements for EU qualified certificates and Part 1 general certificate-service policy requirements.

Use it to identify what Part 2 adds, which Part 1 policy family it inherits, and when shared CP/CPS or lifecycle evidence can be reused.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
6

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Use ETSI EN 319 411-2 V2.6.1 for the additional policy and security requirements that apply to EU qualified certificate profiles. Use ETSI EN 319 411-1 V1.5.1 for the general requirements and underlying policy families that Part 2 incorporates. A states the requirements and application boundary for the selected service. Part 2 is not a standalone checklist: its QCP, QSCD-backed, and qualified website certificate policies inherit specified Part 1 requirements and add qualified-certificate conditions. Neither standard, by itself, grants qualified status under eIDAS.

Document comparison

ETSI EN 319 411-2 vs ETSI EN 319 411-1

Decide what EN 319 411-2 adds to the EN 319 411-1 policy, evidence, and assurance controls it incorporates.

Review all sources
First framework
ETSI EN 319 411-2

Part 2 defines EU qualified certificate policies and adds requirements to the Part 1 controls those policies inherit.

Second framework
ETSI EN 319 411-1

Part 1 covers general certificate-service policy and security requirements for TSPs.

Comparison row 1

Primary scope

ETSI EN 319 411-1

Part 1 specifies generally applicable policy and security requirements for TSPs issuing public key certificates, including trusted website certificates and general certificate lifecycle management.

Operational implication

Start with the and service scope. A Part 2 profile needs both its additional requirements and the Part 1 controls it incorporates; a general certificate service can remain within Part 1 when no qualified-certificate policy applies.

Comparison row 2

Policy families

ETSI EN 319 411-2

Part 2 defines QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, and QNCP-w-gen. Each policy states which Part 1 family it builds on and what qualified-certificate provisions it adds.

ETSI EN 319 411-1

Part 1 defines NCP, NCP+, LCP, EVCP, DVCP, OVCP, and IVCP. The CP states what applies; the CPS describes how the TSP implements the applicable requirements.

Operational implication

Map the Part 2 policy to its stated Part 1 base, then verify the policy object identifier, certificate profile, subscriber type, and any QSCD or website-authentication condition before reusing evidence.

Comparison row 3

Identity validation

ETSI EN 319 411-2

The unadapted Part 2 text describes physical-presence or equivalent-assurance routes for natural-person and legal-person identity checks, and QWAC routes also verify the subscriber's link with the domain name. For the Regulation (EU) 2025/1943 presumption-of-compliance route for qualified signature and seal certificates, the Regulation replaces those Part 2 identity clauses with verification under the implementing acts adopted pursuant to eIDAS Article 24(1c).

ETSI EN 319 411-1

Part 1 covers initial identity validation, naming, subscribers and subjects, registration service responsibilities, certificate applications, and re-key or revocation request authentication for general certificate services.

Operational implication

For qualified signature and seal certificates, map registration evidence to current eIDAS Article 24 and the Regulation (EU) 2025/1943 adaptations; the unadapted physical-presence or equivalent-assurance wording is not the complete presumption-of-compliance route. For a website policy, also retain evidence of the subscriber's link to the domain name.

Comparison row 4

Core obligations

ETSI EN 319 411-2

Part 2 distinguishes QSCD-backed profiles and says the QSCD qcStatement belongs in QCP-n-qscd and QCP-l-qscd certificates, while it must not be included for certificates not issued under those requirements.

ETSI EN 319 411-1

Part 1 supplies the underlying NCP+ and device-related controls, but it does not establish a Part 2 QSCD-backed profile by itself.

Operational implication

Keep the QSCD route as a Part 2 decision. A certificate sample, device-status check, and CP/CPS statement should show when the QSCD-backed profile applies.

Comparison row 5

Evidence and records

ETSI EN 319 411-2

Part 2 evidence should include the profile decision, CP/CPS clauses, certificate samples, policy identifiers, applicable qcStatements, QSCD evidence where required, website subscriber-to-domain evidence where relevant, and conformity-assessment findings.

ETSI EN 319 411-1

Part 1 evidence should include CP and CPS versions, identifiers, subscriber agreements, identity validation records, RA delegation evidence, issuance logs, CRL or OCSP records, revocation files, repository publication records, audit logs, and records archival evidence.

Operational implication

Keep a traceable evidence matrix: source, claim, profile, owner, artifact, review date, and whether the artifact supports Part 2, Part 1, or both.

Comparison row 6

Lifecycle controls

ETSI EN 319 411-2

Part 2 repeatedly incorporates Part 1 lifecycle controls for publication, identity validation, certificate application, issuance, revocation requests, CRL, OCSP, business matters, and policy management, then adds qualified-profile constraints.

ETSI EN 319 411-1

Part 1 is the operational backbone for certification services: registration, certificate generation, dissemination, revocation management, revocation status, repositories, and records archival.

Operational implication

Reuse operational evidence where Part 2 points back to Part 1, but keep a Part 2 row showing the qualified profile or qualified-service condition that made the reuse valid.

Comparison row 7

Assessment and legal boundary

ETSI EN 319 411-2

Part 2 maps EU qualified certificate policies to eIDAS requirements, but its annex is not a definitive legal conformance statement. Regulation (EU) 2025/1943 separately references V2.6.1 with adaptations for qualified signature and seal certificates.

ETSI EN 319 411-1

Part 1 is a technical standard for general certificate-service policy and security requirements. Regulation (EU) 2025/1943 also adapts Part 1 provisions incorporated into the qualified signature and seal route.

Operational implication

For the legal presumption-of-compliance route, crosswalk the two ETSI editions together with the implementing regulation's adaptations. Keep supervisory, trusted-list, conformity-assessment, and qualified-status evidence separate.

Comparison row 8

Overlap and reuse

ETSI EN 319 411-2

Part 2 can reuse common PKI evidence after the crosswalk identifies the qualified , the Part 1 provision being incorporated, and any additional website-authentication or QSCD condition.

ETSI EN 319 411-1

Part 1 evidence can be reused for common PKI operations, such as lifecycle processing, revocation services, repositories, audit logging, and records archival, when the service boundary and policy profile match.

Operational implication

Reuse the operational artifact, not the conclusion. The same log or CP/CPS section may support both sides, but the qualified-certificate conclusion needs its own cited row.

Comparison row 9

Practical decision rule

ETSI EN 319 411-1

Use EN 319 411-1 as the controlling side when the claim is that a TSP certificate service meets the general Part 1 and security requirements.

Operational implication

Do not collapse the standards into one checklist. Start with the qualified profile and public claim, then show exactly which Part 1 controls are reused by the Part 2 qualified certificate claim.

Practical decision rule

How to choose between ETSI EN 319 411-2 and ETSI EN 319 411-1

  • Start with the certificate service and policy profile, not with the standard title alone.
  • Use EN 319 411-2 when the certificate is issued under a Part 2 qualified , including a website-authentication or QSCD-backed profile.
  • Use EN 319 411-1 for general certificate-service CP/CPS, lifecycle, repository, revocation, and CA/RA operational evidence.
Section 1

When should teams compare ETSI EN 319 411-2 with ETSI EN 319 411-1?

Compare the standards before a trust service provider, product team, auditor, or procurement reviewer reuses general certificate-service evidence for an EU qualified certificate claim.

The decision is not which standard replaces the other. Identify the Part 2 policy first, then trace its inherited Part 1 policy requirements and lifecycle clauses. Keep the additional Part 2 conditions visible in the crosswalk. For qualified signature and seal certificates, also apply the adaptations in Commission Implementing Regulation (EU) 2025/1943. Those adaptations change or add requirements in both Part 2 and the Part 1 text it incorporates, so a crosswalk based only on the two published ETSI PDFs is incomplete for the regulation's presumption-of-compliance route.

  • Start with the qualified profile: QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen belong in the Part 2 analysis.
  • Separate legal qualified-status proof and trusted-list evidence from the standards crosswalk. Within the crosswalk, separate the Part 2 profile and QSCD or website-certificate conditions from common PKI operations reused from Part 1.
  • For each reused control, cite the Part 2 clause that calls up Part 1 and the Part 1 clause containing the operational requirement.
Section 2

Decision rules for qualified and general certificate services

Use Part 2 when the certificate is issued under an EU qualified defined there. Use Part 1 for the general certificate-service requirements and policy families that apply directly to a Part 1 service or are incorporated by a Part 2 policy.

Part 2 expressly builds its policies on Part 1. QCP-n and QCP-l include NCP requirements, or NCP+ where the implementation requires a secure cryptographic device. QCP-n-qscd and QCP-l-qscd include the corresponding QCP requirements and NCP+ requirements. QEVCP-w builds on EVCP; QNCP-w builds on NCP plus IVCP or OVCP; QNCP-w-gen builds on NCP plus selected Part 1 [WEB] requirements.

  • If the service issues EU qualified certificates, document the Part 2 policy profile and any QSCD or website-certificate route before reusing Part 1 evidence. Keep eIDAS qualified status and trusted-list proof in a separate linked record.
  • If the service does not issue EU qualified certificates, apply Part 1 or another applicable policy framework without importing Part 2 requirements by acronym or product label.
  • When Part 2 calls up a Part 1 clause, cite both clauses and record whether Part 2 adds, narrows, or conditions the inherited requirement.
Section 3

What to decide before reusing CP/CPS evidence

A states what requirements and application boundary apply; a Certification Practice Statement explains how the issuing TSP implements them. Reuse a CP/CPS section only when it covers the same service, policy identifier, certificate profile, participants, operating boundary, and assessment period.

For Part 2, add the selected qualified , its inherited Part 1 policy family, and the Part 2 conditions for identity, certificate content, QSCD, or website authentication that apply. Keep Part 1 evidence for common CA and registration responsibilities, subscribers and subjects, naming, application and issuance, acceptance, revocation, status services, repositories, and records archival.

  • Name the qualified certificate service, Part 2 profile, , certificate profile, CA, RA or registration service provider, repository, and revocation-status service in scope.
  • Record whether the certificate is for a natural person, a legal person, a QSCD-backed signature or seal route, or website authentication, then select the matching policy rather than inferring it from the certificate's marketing name.
  • Separate additional Part 2 evidence from inherited Part 1 evidence so the audit file shows which qualified-certificate condition each artifact supports.
  • Version evidence by standard version, CP/CPS version, certificate profile, assessment period, and certificate service boundary.
Section 4

Evidence that belongs on each side of the comparison

Build an evidence map instead of merging the standards into one checklist. A shared operational record can support both, but each mapping should identify the Part 2 clause, the inherited Part 1 clause, any Part 2 addition, and the claim the record proves.

For Part 2, keep the profile decision, policy identifier, certificate sample, applicable qcStatements, identity-route evidence, QSCD evidence for QCP-n-qscd or QCP-l-qscd, and domain-link evidence for website policies. For Part 1, keep CP and CPS versions, subscriber agreements, identity validation records, registration delegation, issuance logs, CRL or OCSP records, revocation files, repository records, key-management records, audit logs, and archival evidence. Keep legal qualified-status and trusted-list proof linked but outside the standards-conformance conclusion.

  • Mark each evidence item as an additional Part 2 control, an inherited Part 1 control, or a shared artifact, and cite the relevant clauses.
  • Do not treat a Part 1 artifact as proof of the full Part 2 profile. Record the Part 2 provision that permits reuse and any additional condition that remains to be shown.
  • Do not include the QSCD qcStatement route unless the certificate is issued under a QCP-n-qscd or QCP-l-qscd profile.
  • Review the crosswalk after CP/CPS changes, qualified profile changes, RA changes, revocation-service changes, key-management changes, trusted-list changes, or conformity-assessment scope changes.
Section 5

Comparison checklist for qualified certificate teams

Use this checklist for a CP/CPS update, qualified certificate service review, conformity assessment evidence pack, or procurement response that mentions both standards.

  • Identify which Part 2 policy profile applies: QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.
  • List the certificate service, object identifier, CP/CPS version, certificate profile, CA, RA, repository, and status service covered by EN 319 411-1.
  • Create a row for every shared operation, including identity validation, issuance, acceptance, revocation, status services, records archival, and CA or RA termination.
  • Attach the evidence artifact to the row: CP/CPS text, subscriber record, validation record, certificate sample, CRL or OCSP record, audit log, or conformity-assessment finding. Link trusted-list proof separately because it supports eIDAS status, not Part 1 or Part 2 conformance by itself.
  • Flag unsupported reuse where Part 1 evidence proves ordinary certificate-service operation but does not prove the qualified certificate claim.
Section 6

Comparison mistakes that create qualified-certificate audit gaps

Audit gaps appear when Part 2 is treated as a qualified label on an unchanged Part 1 file. Part 2 is narrower because it addresses EU qualified certificates, but it also depends on Part 1. The crosswalk must show both the inherited control and the additional qualified-certificate condition.

  • Do not call a service qualified because it satisfies either standard. Part 2 profile evidence is needed for the standards claim, while eIDAS supervisory status and trusted-list evidence support the legal qualified-service claim.
  • Do not hide QCP, QWAC, or QSCD profile differences behind a vague CP/CPS title.
  • Do not reuse identity validation, revocation, repository, or audit-log evidence unless the certificate service boundary and policy profile match.
  • Do not mix CA/Browser Forum web-certificate requirements, qualified website-authentication certificate requirements, and ordinary certificate-policy requirements without a row-level source reference.
Primary sources

References and citations

etsi.org
Referenced sections
  • Primary ETSI source for general policy, risk assessment, management, security, incident, continuity, and audit evidence requirements for trust service providers.
"General Policy Requirements for Trust Service Providers"
Related guides

Explore more topics

eIDAS QTSP supervision workflow for ETSI EN 319 411-2
Operational workflow for qualified trust service providers using ETSI EN 319 411-2 to manage supervisory-body changes, incidents, termination evidence, trusted-list checks, and assessment records.
ETSI EN 319 411-2 certificate operations
Operational guide for ETSI EN 319 411-2 qualified certificate services: policy identifiers, identity validation, issuance, QSCD handling, revocation status, and relying-party notices.
ETSI EN 319 411-2 compliance checklist
Compliance checklist for ETSI EN 319 411-2 qualified certificate services, covering policy selection, CP/CPS evidence, identity validation, QSCD status, trusted-list reliance, and certificate status services.
ETSI EN 319 411-2 FAQ for EU Qualified Certificates
Answers to common ETSI EN 319 411-2 questions about EU qualified certificate policies, QSCD use, identity validation, trusted lists, and revocation status services.
ETSI EN 319 411-2 Identity Proofing
How EN 319 411-2 applies identity validation for EU qualified certificates, including QCP natural-person, legal-person, website, and evidence-record checks.
ETSI EN 319 411-2 profile selector
Select the right ETSI EN 319 411-2 qualified certificate policy profile for signatures, seals, QSCD use, and website authentication.
ETSI EN 319 411-2 QSCD Route
When QCP-n-qscd or QCP-l-qscd is the right EN 319 411-2 route, what QSCD evidence is needed, and which certificate-profile claims must stay aligned.
ETSI EN 319 411-2 QTSP supervision evidence workflow
Build an assessment-ready QTSP supervision evidence pack for ETSI EN 319 411-2 qualified certificate services, covering policy identifiers, trusted-list checks, incident records, QSCD evidence, and termination controls.
ETSI EN 319 411-2 Qualified Certificate Scope
Use ETSI EN 319 411-2 to scope EU qualified certificate services by certificate policy, subject type, QSCD use, website authentication profile, and eIDAS context.
ETSI EN 319 411-2 requirements map
Map ETSI EN 319 411-2 requirements for EU qualified certificate services across QCP profiles, CP/CPS documentation, QSCD use, certificate profiles, revocation, and eIDAS Annex A references.
ETSI EN 319 411-2 trusted-list evidence
Build EN 319 411-2 trusted-list evidence for EU qualified certificate reliance: relying-party notice text, QTSP service identifiers, validation records, and change triggers.
ETSI EN 319 411-2 trusted-list validation workflow
Validate an EN 319 411-2 EU qualified-certificate claim by mapping the certificate service to the QTSP trusted-list entry, policy profile, relying-party notice, and status evidence.
ETSI EN 319 411-2 vs eIDAS Qualified Trust Services
Compare ETSI EN 319 411-2 certificate policy requirements with the eIDAS qualified-status, supervision, audit, and trusted-list framework.
ETSI EN 319 411-2: Certificate Revocation FAQ
Answer the ETSI EN 319 411-2 revocation question for qualified certificate services: CPS procedures, 24-hour publication, CRL or OCSP status, and evidence to retain.
ETSI EN 319 411-2: end-to-end qualified certificate lifecycle management workflow
Lifecycle workflow for ETSI EN 319 411-2 qualified certificate services, from policy selection and identity validation through issuance, renewal, re-key, modification, revocation, status services, and records.
ETSI EN 319 411-2: Legal vs Natural Person Certs
ETSI EN 319 411-2 separates qualified certificate policies for natural persons, legal persons, QSCD use, and website authentication subscribers.
ETSI EN 319 411-2: QCP, QNCP, and QEVCP Profile Selection
Choose the right ETSI EN 319 411-2 qualified certificate policy profile: QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.
How should QTSPs select an ETSI EN 319 411-2 qualified certificate profile?
A focused FAQ on choosing QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen under ETSI EN 319 411-2.
How should relying parties use trusted lists under ETSI EN 319 411-2?
FAQ on EN 319 411-2 trusted-list reliance for EU qualified certificates: relying-party notices, QTSP service identifiers, validation evidence, and source references.
QSCD Requirements in ETSI EN 319 411-2
How ETSI EN 319 411-2 treats QSCD-backed qualified certificates, including QCP-n-qscd and QCP-l-qscd policies, key-use controls, QSCD verification, and certificate profile evidence.
QTSP Supervision and ETSI EN 319 411-2
How ETSI EN 319 411-2 supports QTSP supervision evidence for qualified certificate services, trusted-list reliance, liability responsibility, incident records, and audit preparation.
Qualified certificates under ETSI EN 319 411-2
FAQ answer for QTSPs on how ETSI EN 319 411-2 treats EU qualified certificates, policy identifiers, QSCD variants, website certificates, and lifecycle evidence.
What are the qualified certificate policies in ETSI EN 319 411-2?
FAQ on ETSI EN 319 411-2 qualified certificate policies, including QCP-n, QCP-l, QSCD variants, QEVCP-w, QNCP-w, and policy identifiers.
Which QWAC Profile Fits ETSI EN 319 411-2?
Choose between QEVCP-w, QNCP-w, and QNCP-w-gen for qualified website authentication certificates under ETSI EN 319 411-2.