FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
27of27items
Across 9 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
QTSP Supervision and ETSI EN 319 411-2

Does ETSI EN 319 411-2 make a TSP qualified?

No. ETSI EN 319 411-2 expressly warns that conformance to the standard alone does not mean that the TSP or its certificates are qualified. A supervision answer should therefore avoid treating an EN 319 411-2 audit result as a substitute for qualified status.

For a QTSP issuing EU qualified certificates, the standard is still central evidence. It incorporates EN 319 411-1 general policy and security requirements, then adds requirements for EU qualified certificates for signatures, seals, and website authentication.

Current eIDAS Article 20 requires an audit by a conformity assessment body at the QTSP's expense at least every 24 months. The QTSP must notify the supervisory body at least one month before a planned audit and submit the resulting report within three working days after receiving it. The supervisory body may also audit the QTSP or request another assessment at any time. Article 21 governs the supervisory decision for a new qualified service; the service may begin only after qualified status appears in the trusted list. Commission Implementing Regulation (EU) 2025/2162 supplies the current accreditation, assessment-scheme, and report rules.

  • Keep the qualified-status decision separate from EN 319 411-2 conformance evidence.
  • Identify the exact qualified certificate policy in scope, such as QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.
  • Show how EN 319 411-2 adds EU qualified certificate requirements on top of the EN 319 411-1 certificate policy baseline.
  • Calendar the recurring assessment from the last applicable assessment, the one-month pre-audit notice, and the three-working-day report submission; retain proof for each date rather than recording only the final report.
Citations
QTSP Supervision and ETSI EN 319 411-2

What should a QTSP supervision file contain?

A useful supervision file should start with the certificate service and policy identifier, then link the CPS, certificate profile, repository, identity proofing, revocation, status service, incident, and termination evidence to the relevant EN 319 411-2 and incorporated EN 319 411-1 requirements.

The record should also prove the relying-party path. EN 319 411-2 says relying-party notices for EU qualified certificates need to explain that the trust anchor is identified in the service digital identifier of an appropriate EU trusted-list entry for the QTSP. Record the provider, the specific qualified service, its status and status history, and the certificates or other service identifiers carried by that entry. Keep subcontracted operations in the same map: the QTSP identified in the trusted list retains overall responsibility for issuing the certificates even when another party performs a component activity.

  • Preserve the selected policy identifier and the certificate profile evidence used to signal that policy.
  • Attach CPS sections for issuance, maintenance, revocation, status services, records, and service termination.
  • Keep the QTSP trusted-list service digital identifier and the trust anchor it identifies as separate evidence fields.
  • Track supervisory findings through owner, remedy, due date, evidence of completion, and closure; a standards cross-reference does not prove that an operational deficiency was corrected.
Citations
QTSP Supervision and ETSI EN 319 411-2

What are the most common supervision mistakes?

The most common mistakes are to blur qualified-status evidence with standards conformance, omit the trusted-list reliance path, or leave the supervision file without a traceable link from the selected certificate policy to the operational records.

Another common problem is treating incident, revocation, and records-retention evidence as optional. EN 319 411-2 and EN 319 411-1 map those topics into the qualified-certificate supervision file, while eIDAS Article 46b gives the supervisory body powers to request conformity assessments, grant or withdraw qualified status, require remediation, and verify termination plans.

  • Do not claim qualified status from EN 319 411-2 conformance alone.
  • Do not omit the trusted-list service digital identifier or the notice to relying parties.
  • Do not leave revocation, incident, and records-retention evidence outside the supervision pack.
Citations
Qualified certificates under ETSI EN 319 411-2

How should qualified trust service providers handle qualified certificates under ETSI EN 319 411-2?

Start by separating ETSI policy conformance from EU qualification status. EN 319 411-2 incorporates the general certificate policy and security requirements from EN 319 411-1 and adds requirements for EU qualified certificate services, but conformance to the standard alone does not imply that the TSP or its certificates are qualified.

Under current eIDAS, qualified status follows conformity assessment, supervisory verification, and entry of the provider and service in the national trusted list. The certificate must also contain the data required by Annex I for signatures, Annex III for seals, or Annex IV for website authentication. Those Annexes require a machine-readable qualified-certificate indication, issuer and subject identity data, validity dates, a unique certificate code, issuer signature or seal, and status-service information, with type-specific data such as domain names for website certificates and a QSCD indication where applicable. Check all three layers before describing a certificate as qualified.

For each certificate service, identify which EN 319 411-2 policy family is being used: QCP-n for qualified certificates issued to natural persons, QCP-l for legal persons, QCP-n-qscd or QCP-l-qscd when the related private key resides in a QSCD, and QEVCP-w, QNCP-w, or QNCP-w-gen for qualified website authentication certificates. The selected policy drives the certificate-policy statement, CPS controls, certificate profile, subscriber obligations, and evidence set.

  • Do not describe a generic certificate as qualified unless the service, certificate policy, trusted-list status, and eIDAS qualification context support that claim.
  • For signature and seal certificates, distinguish natural-person, legal-person, and QSCD-backed routes before choosing the QCP identifier or local policy OID.
  • For website authentication certificates, distinguish the EVCP-based QEVCP-w route, the BRG and OVCP or IVCP based QNCP-w route, and the general-purpose QNCP-w-gen route.
  • Exclude a certificate from the qualified claim when the exact issuing service lacks qualified trusted-list status, required Annex data is missing, the policy route does not match the subject or use, or the certificate was invalid or revoked at the relevant time.
Citations
Qualified certificates under ETSI EN 319 411-2

What evidence should support qualified certificates under ETSI EN 319 411-2?

Prove that the certificate was issued and managed under the claimed EN 319 411-2 policy. Keep the certificate policy, Certification Practice Statement (CPS), terms and conditions, certificate profile, identity-verification record, status-service evidence, and revocation records aligned to the selected QCP route.

For QSCD-backed QCP-n-qscd and QCP-l-qscd certificates, the evidence needs to show the QSCD basis, including the certificate profile treatment of the ETSI EN 319 412-5 QSCD qcStatement and the standard's rule that the QSCD statement is not included in certificates outside those QSCD policies.

  • Map each public certificate or service claim to QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.
  • Retain the policy identifier or policy OID mapping used in issued certificates, including any locally allocated OID and the EN 319 411-2 policy it adopts as the basis.
  • Keep certificate database, validity-status, revocation, and records-retention evidence because eIDAS article 24 duties are mapped in EN 319 411-2 to certificate lifecycle and recordkeeping controls.
  • Retain a sample-based trace from application through identity and attribute validation, approval, issuance, subscriber acceptance, repository publication, status response, and any revocation; record who performed and approved each step.
Citations
Qualified certificates under ETSI EN 319 411-2

What checklist should teams use before claiming EN 319 411-2 qualified certificate coverage?

Use the checklist to prevent the common error of treating all certificates, all certificate policies, or all QTSP services as interchangeable. The useful review is certificate-policy specific and should be repeated when the certificate profile, CPS, QSCD route, website certificate route, trusted-list status, or relevant ETSI/eIDAS source changes.

  • Confirm that the service is an EU qualified certificate service for electronic signatures, electronic seals, or website authentication before applying EN 319 411-2 as the qualified-certificate policy layer.
  • Check that the certificate includes at least one allowed policy identifier or policy OID for the selected EN 319 411-2 route.
  • Verify that any QSCD claim is limited to QCP-n-qscd or QCP-l-qscd certificates and is reflected consistently in CPS controls, subscriber obligations, and certificate-profile evidence.
  • Confirm that lifecycle evidence covers issuance, maintenance, revocation, per-certificate validity-status publication beyond expiry, certificate database handling, and records kept accessible for as long as necessary after the QTSP ceases activity.
Citations
What are the qualified certificate policies in ETSI EN 319 411-2?

What qualified certificate policies does ETSI EN 319 411-2 define?

ETSI EN 319 411-2 defines seven EU qualified certificate policies. QCP-n covers EU qualified certificates issued to natural persons, and QCP-l covers EU qualified certificates issued to legal persons. QCP-n-qscd and QCP-l-qscd are the corresponding policies when the private key related to the certified public key must reside in a qualified signature or seal creation device.

For qualified website authentication certificates, QEVCP-w is based on EVCP, QNCP-w is based on NCP plus OVCP or IVCP, and QNCP-w-gen is based on NCP plus requirements tagged as WEB in ETSI EN 319 411-1. The selected policy should be visible in the CP/CPS, terms and conditions, certificate profile, and policy identifier evidence.

The ETSI policy OIDs are 0.4.0.194112.1.0 for QCP-n, 0.4.0.194112.1.1 for QCP-l, 0.4.0.194112.1.2 for QCP-n-qscd, 0.4.0.194112.1.3 for QCP-l-qscd, 0.4.0.194112.1.4 for QEVCP-w, 0.4.0.194112.1.5 for QNCP-w, and 0.4.0.194112.1.6 for QNCP-w-gen. EN 319 411-2 also permits an OID allocated by the TSP or another stakeholder, but the policy it identifies must state which EN 319 411-2 policy it uses as its basis.

  • Use QCP-n for natural-person EU qualified certificates and QCP-l for legal-person EU qualified certificates.
  • Use QCP-n-qscd or QCP-l-qscd when the qualified certificate route requires the private key to reside in a QSCD.
  • Use QEVCP-w, QNCP-w, or QNCP-w-gen for qualified website authentication certificates, depending on whether the route relies on EVCP, OVCP or IVCP, or the general WEB-tagged requirements.
  • Do not use the presence of an ETSI policy OID as proof of qualified status; verify the provider and the specific service in the applicable trusted list.
Citations
What are the qualified certificate policies in ETSI EN 319 411-2?

How should a QTSP choose the correct EN 319 411-2 policy identifier?

Apply the choice in four steps. First identify the intended use: signature, seal, or website authentication. Second identify the subject as a natural person or legal person. Third decide whether the signature or seal key must reside in a QSCD. Fourth, for website authentication, select the EV, organization or individual validation, or general-purpose assurance route. A certificate intended for another use is outside these seven policy profiles.

Then check the device and baseline inheritance. EN 319 411-2 states that QCP-n and QCP-l use NCP unless the TSP terms and conditions require a secure cryptographic device, in which case NCP+ applies. The QSCD-specific policies include the corresponding QCP policy plus QSCD provisions. Website routes inherit EVCP, NCP, OVCP or IVCP, and WEB-tagged requirements as applicable.

  • Record the subject category: natural person, legal person, or website authentication certificate subject.
  • Record whether the service requires a QSCD and whether the certificate policy must include a QSCD-specific identifier.
  • Record the inherited baseline: NCP, NCP+, EVCP, OVCP, IVCP, or WEB-tagged EN 319 411-1 requirements.
  • Record the outcome and exclusion: selected policy, rejected alternatives, facts that drove the choice, reviewer, approval date, and the change events that require a new decision.
Citations
What are the qualified certificate policies in ETSI EN 319 411-2?

What evidence should support a qualified certificate policy claim?

The evidence should prove that the selected policy identifier matches the certificate type and the service actually operated. Keep the CP/CPS section that names the policy, the certificate profile showing the policy OID, the terms and conditions that determine secure-device use, and issuance or audit evidence showing whether the service follows the inherited EN 319 411-1 requirements. Sample issued certificates and trace each one back through identity validation, approval, profile generation, publication, status service, and revocation handling.

Do not treat Annex A as a legal conformance certificate. EN 319 411-2 says the annex maps policy references to eIDAS requirements, but also warns that the annex is not a definitive statement of conformance to eIDAS and that non-technical legal requirements are outside the standard's scope.

  • Keep the CP/CPS policy section and the exact policy OID used in issued certificates.
  • Keep terms and conditions showing whether QCP-n or QCP-l uses NCP or NCP+ because a secure cryptographic device is required.
  • Keep evidence that QSCD, EVCP, OVCP, IVCP, or WEB-tagged inherited requirements were applied when the selected policy depends on them.
  • Keep Annex A mapping as supporting traceability, not as a standalone legal-conformance conclusion.
Citations
Which QWAC Profile Fits ETSI EN 319 411-2?

How do the three QWAC profiles differ?

ETSI EN 319 411-2 defines three EU qualified website authentication certificate policy profiles: QEVCP-w, QNCP-w, and QNCP-w-gen. The selected policy determines which EN 319 411-1 baseline, CA/Browser Forum dependency, and qualified-certificate additions must appear in the CP, CPS, certificate profile, and evidence pack.

Apply three tests in order. First, confirm the certificate is for website authentication rather than signature or seal use. Second, identify the subscriber as a natural or legal person. Third, identify the assurance package. Choose QEVCP-w only for a legal person under the Extended Validation Certificate Policy and EVCG route. Choose QNCP-w for a natural or legal person under NCP plus OVCP or IVCP and the Baseline Requirements. Choose QNCP-w-gen for the general-purpose route based on NCP plus selected WEB-tagged requirements in EN 319 411-1.

Profile selection is only one layer. Current eIDAS Article 45 requires a qualified website authentication certificate to meet Annex IV, and qualified status still depends on the issuing service's trusted-list entry. Annex IV requires, among other data, the subject's identity, address elements, operated domain names, validity period, unique certificate code, issuer signature or seal, and validity-status service information. From 6 January 2027, Commission Implementing Regulation (EU) 2025/2527 lists EN 319 411-2 V2.6.1 with QEVCP-w, QNCP-w, or QNCP-w-gen as a reference-standards route for QWACs used in transport layer security authentication outside a web-browser. It lists ETSI TS 119 411-5 V2.1.1 for other QWACs, including browser use.

  • QEVCP-w: legal-person QWAC route based on EVCP and the CA/Browser Forum Extended Validation Guidelines.
  • QNCP-w: natural-person or legal-person QWAC route based on NCP plus OVCP or IVCP and the CA/Browser Forum Baseline Requirements.
  • QNCP-w-gen: general-purpose QWAC route based on NCP plus selected web-authentication requirements in EN 319 411-1.
  • Outside these routes: a generic TLS certificate, domain-validation-only certificate, signature certificate, or seal certificate is not a QWAC merely because a QTSP issued it.
Citations
Which QWAC Profile Fits ETSI EN 319 411-2?

What must be proven before issuing a QWAC?

For QEVCP-w, QNCP-w, and QNCP-w-gen, EN 319 411-2 ties initial validation to the subscriber type and the domain name. If the subscriber is a natural person, verify the subscriber identity and link with the domain name using the QCP-n route. If the subscriber is a legal person, verify the legal-person identity, authorized-representative route, and link with the domain name using the QCP-l route.

That means the evidence pack should not stop at a domain-control check. It should show the selected QWAC policy identifier, subscriber type, identity route, authority to request the certificate, link to each certified domain, applicable CA/Browser Forum or WEB-tagged dependency, Annex IV certificate contents, and the issuing service's trusted-list status. Retain the source used for the identity and domain-link check, validation time, reviewer or automated control, result, approval, issued certificate, and later revocation or renewal record.

  • Record the selected policy identifier: QEVCP-w, QNCP-w, or QNCP-w-gen.
  • Keep separate evidence for subscriber identity, authority to request the certificate, and the subscriber's link with the domain name.
  • For QEVCP-w and QNCP-w, track conflicts or updates in the applicable BRG or EVCG route because EN 319 411-2 gives those requirements precedence in conflict cases.
  • Revalidate the subscriber's link to every added or changed domain and repeat the profile decision when the subscriber type, validation method, assurance route, policy OID, or issuing-service scope changes.
Citations
Which QWAC Profile Fits ETSI EN 319 411-2?

What review checks keep the QWAC profile defensible?

Review the QWAC profile whenever the QTSP changes its CP/CPS, certificate profile, subscriber validation workflow, CA/RA responsibility split, repository publication process, or CA/Browser Forum dependency. The review should confirm that the public certificate policy OID and the evidence trail still describe the same qualified website authentication route.

The most useful audit file is a profile matrix: one row for each QWAC profile offered, with the policy identifier, subscriber type, EN 319 411-1 dependency, CA/Browser Forum or web-authentication dependency, identity-validation route, domain-link evidence, certificate-profile checks, and repository/status-service evidence.

  • Do not describe a certificate as a QWAC unless the EN 319 411-2 profile, Annex IV contents, issuing service's trusted-list status, and certificate-policy evidence all line up.
  • Do not reuse a generic TLS certificate checklist when the qualified website authentication route requires a specific EN 319 411-2 policy identifier.
  • Do not merge QEVCP-w, QNCP-w, and QNCP-w-gen findings into one control row; each route has different dependencies and evidence.
Citations
Page 2 of 2