Artifact GuideGLOBALETSI EN 319 411-2

ETSI EN 319 411-2 How QSCD fits qualified certificate issuance

ETSI EN 319 411-2 uses QSCD-specific qualified certificate policies when the private key related to the certified public key resides in a qualified signature or seal creation device.

This FAQ helps separate QCP-n-qscd and QCP-l-qscd evidence from ordinary qualified certificate evidence.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Under ETSI EN 319 411-2, status changes the certificate policy route, key-use controls, certificate profile, and CPS evidence for certificates issued under QCP-n-qscd or QCP-l-qscd.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

How should qualified trust service providers handle QSCD under ETSI EN 319 411-2?

A TSP should handle by first selecting the right ETSI EN 319 411-2 qualified certificate policy. QCP-n-qscd applies to qualified certificates for natural persons where the private key corresponding to the certified public key resides in a QSCD. QCP-l-qscd applies to qualified certificates for legal persons under the same private-key-in-QSCD condition. Whether the provider and service have qualified status remains a separate eIDAS and trusted-list question.

The route brings in the ordinary QCP-n or QCP-l requirements and the NCP+ baseline, then adds QSCD-specific provisions. The standard ties those provisions to subject device provisioning, key pair and certificate usage, key generation and installation, certificate profile statements, and terms and conditions.

  • Record whether the certificate is QCP-n- or QCP-l-qscd, not just that it is an EU qualified certificate.
  • Show that the private key related to the certified public key resides in the for the selected policy route.
  • Keep CPS and certificate profile evidence aligned with the route, including the required QSCD only for QCP-n-qscd or QCP-l-qscd certificates.
Citations
Question 2

What QSCD controls does ETSI EN 319 411-2 call out?

When the TSP manages the for the subject, ETSI EN 319 411-2 restricts use of the private key for signing to the QSCD and distinguishes natural-person sole control from legal-person control. The same area of the standard ties natural-person QSCD keys to electronic signatures and legal-person QSCD keys to electronic seals.

For key generation and installation, the TSP has to verify that the device is certified as a and ensure that the public key to be certified comes from a key pair generated by a QSCD. If a TSP generates the key pair and imports it into the signing or sealing QSCD, it must meet the certified devices' environmental assumptions and security objectives. If a private key moves between devices, it must identify compromise risks and implement adequate mitigations. The CPS must also state the measures taken when QSCD status changes during certificate validity.

Remote management has a separate legal service boundary. Under the amended eIDAS Articles 29, 29a, and 39a, generating or managing signature or seal creation data for a remote is a qualified trust service carried out by a that meets the remote-device management requirements. The transition that allowed other QTSPs to manage remote devices ended on 21 May 2026. The certificate issuer should therefore verify both the device certification and the current qualified status of any separate remote-QSCD management service.

  • For QCP-n-, preserve evidence that the subject's private key is used under the subject's sole control.
  • For QCP-l-, preserve evidence that the subject's private key is used under the subject's control.
  • For certificate issuance, preserve proof of certification status, key-generation route, third-party and qualified-service status where used, and CPS handling of QSCD status changes.
  • Treat loss of certification as a reassessment trigger: identify every non-expired certificate carrying the QSCD , decide whether revocation is required, publish status within the applicable deadline, and retain the device-status notice, affected-certificate list, decision, and publication evidence.
Citations
Question 3

What mistakes should QTSP teams avoid with QSCD evidence?

Treat as a certificate-policy condition. If the service claims QCP-n-qscd or QCP-l-qscd, trace the evidence from the policy identifier through device certification, key generation, subject control, certificate profile, CPS text, and revocation or status-change handling.

Apply the only to the correct certificates. ETSI EN 319 411-2 requires it for QCP-n-qscd and QCP-l-qscd certificates and prohibits it on certificates not issued under those requirements.

  • Do not cite QCP-n or QCP-l evidence alone as proof of a -backed policy route.
  • Do not rely on a device name or supplier assertion without evidence that the device is certified as a for the relevant use.
  • Do not leave the CPS silent on measures for status changes before certificate expiry.
  • Do not treat the qualification of the certificate-issuing service as proof that a separate remote- management service is also qualified.
Citations
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Provides the EU legal context for qualified trust services and QSCD certification that ETSI EN 319 411-2 maps into certificate policy requirements.
"electronic identification and trust services"
etsi.org
Referenced sections
  • Supplies the underlying certificate lifecycle and revocation framework that ETSI EN 319 411-2 references when QSCD status changes can affect non-expired certificates.
"Policy and security requirements for Trust Service Providers issuing certificates"
etsi.org
Referenced sections
  • Supports the warning against misplaced QSCD claims by requiring the QSCD qcStatement only on certificates issued under QCP-n-qscd or QCP-l-qscd requirements.
"shall not be included in certificates that are not issued according to"
Related guides

Explore more topics

eIDAS QTSP supervision workflow for ETSI EN 319 411-2
Operational workflow for qualified trust service providers using ETSI EN 319 411-2 to manage supervisory-body changes, incidents, termination evidence, trusted-list checks, and assessment records.
ETSI EN 319 411-2 certificate operations
Operational guide for ETSI EN 319 411-2 qualified certificate services: policy identifiers, identity validation, issuance, QSCD handling, revocation status, and relying-party notices.
ETSI EN 319 411-2 compliance checklist
Compliance checklist for ETSI EN 319 411-2 qualified certificate services, covering policy selection, CP/CPS evidence, identity validation, QSCD status, trusted-list reliance, and certificate status services.
ETSI EN 319 411-2 FAQ for EU Qualified Certificates
Answers to common ETSI EN 319 411-2 questions about EU qualified certificate policies, QSCD use, identity validation, trusted lists, and revocation status services.
ETSI EN 319 411-2 Identity Proofing
How EN 319 411-2 applies identity validation for EU qualified certificates, including QCP natural-person, legal-person, website, and evidence-record checks.
ETSI EN 319 411-2 profile selector
Select the right ETSI EN 319 411-2 qualified certificate policy profile for signatures, seals, QSCD use, and website authentication.
ETSI EN 319 411-2 QSCD Route
When QCP-n-qscd or QCP-l-qscd is the right EN 319 411-2 route, what QSCD evidence is needed, and which certificate-profile claims must stay aligned.
ETSI EN 319 411-2 QTSP supervision evidence workflow
Build an assessment-ready QTSP supervision evidence pack for ETSI EN 319 411-2 qualified certificate services, covering policy identifiers, trusted-list checks, incident records, QSCD evidence, and termination controls.
ETSI EN 319 411-2 Qualified Certificate Scope
Use ETSI EN 319 411-2 to scope EU qualified certificate services by certificate policy, subject type, QSCD use, website authentication profile, and eIDAS context.
ETSI EN 319 411-2 requirements map
Map ETSI EN 319 411-2 requirements for EU qualified certificate services across QCP profiles, CP/CPS documentation, QSCD use, certificate profiles, revocation, and eIDAS Annex A references.
ETSI EN 319 411-2 trusted-list evidence
Build EN 319 411-2 trusted-list evidence for EU qualified certificate reliance: relying-party notice text, QTSP service identifiers, validation records, and change triggers.
ETSI EN 319 411-2 trusted-list validation workflow
Validate an EN 319 411-2 EU qualified-certificate claim by mapping the certificate service to the QTSP trusted-list entry, policy profile, relying-party notice, and status evidence.
ETSI EN 319 411-2 vs eIDAS Qualified Trust Services
Compare ETSI EN 319 411-2 certificate policy requirements with the eIDAS qualified-status, supervision, audit, and trusted-list framework.
ETSI EN 319 411-2 vs EN 319 411-1
Compare ETSI EN 319 411-2 EU qualified certificate requirements with EN 319 411-1 general certificate-service requirements, including policy inheritance, QSCD controls, and CP/CPS evidence reuse.
ETSI EN 319 411-2: Certificate Revocation FAQ
Answer the ETSI EN 319 411-2 revocation question for qualified certificate services: CPS procedures, 24-hour publication, CRL or OCSP status, and evidence to retain.
ETSI EN 319 411-2: end-to-end qualified certificate lifecycle management workflow
Lifecycle workflow for ETSI EN 319 411-2 qualified certificate services, from policy selection and identity validation through issuance, renewal, re-key, modification, revocation, status services, and records.
ETSI EN 319 411-2: Legal vs Natural Person Certs
ETSI EN 319 411-2 separates qualified certificate policies for natural persons, legal persons, QSCD use, and website authentication subscribers.
ETSI EN 319 411-2: QCP, QNCP, and QEVCP Profile Selection
Choose the right ETSI EN 319 411-2 qualified certificate policy profile: QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.
How should QTSPs select an ETSI EN 319 411-2 qualified certificate profile?
A focused FAQ on choosing QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen under ETSI EN 319 411-2.
How should relying parties use trusted lists under ETSI EN 319 411-2?
FAQ on EN 319 411-2 trusted-list reliance for EU qualified certificates: relying-party notices, QTSP service identifiers, validation evidence, and source references.
QTSP Supervision and ETSI EN 319 411-2
How ETSI EN 319 411-2 supports QTSP supervision evidence for qualified certificate services, trusted-list reliance, liability responsibility, incident records, and audit preparation.
Qualified certificates under ETSI EN 319 411-2
FAQ answer for QTSPs on how ETSI EN 319 411-2 treats EU qualified certificates, policy identifiers, QSCD variants, website certificates, and lifecycle evidence.
What are the qualified certificate policies in ETSI EN 319 411-2?
FAQ on ETSI EN 319 411-2 qualified certificate policies, including QCP-n, QCP-l, QSCD variants, QEVCP-w, QNCP-w, and policy identifiers.
Which QWAC Profile Fits ETSI EN 319 411-2?
Choose between QEVCP-w, QNCP-w, and QNCP-w-gen for qualified website authentication certificates under ETSI EN 319 411-2.