Artifact GuideGLOBALETSI EN 319 411-2

ETSI EN 319 411-2 Qualified certificate policies FAQ

A cited answer to which qualified certificate policy applies to a natural person, legal person, QSCD-backed certificate, or qualified website authentication certificate.

This page helps align CP/CPS language, certificate policy OIDs, terms and conditions, and review evidence before claiming an EN 319 411-2 qualified certificate policy.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

ETSI EN 319 411-2 defines each EU qualified for TSPs issuing EU qualified certificates. Choose by intended use first, then subject type, condition, and inherited assurance baseline. A policy identifier records the selected route but does not replace the eIDAS certificate-content, supervisory, or trusted-list checks.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What qualified certificate policies does ETSI EN 319 411-2 define?

ETSI EN 319 411-2 defines seven EU qualified certificate policies. QCP-n covers EU qualified certificates issued to natural persons, and QCP-l covers EU qualified certificates issued to legal persons. QCP-n- and QCP-l-qscd are the corresponding policies when the private key related to the certified public key must reside in a qualified signature or seal creation device.

For qualified website authentication certificates, QEVCP-w is based on EVCP, QNCP-w is based on NCP plus OVCP or IVCP, and QNCP-w-gen is based on NCP plus requirements tagged as WEB in ETSI EN 319 411-1. The selected policy should be visible in the CP/CPS, terms and conditions, certificate profile, and policy identifier evidence.

The ETSI policy OIDs are 0.4.0.194112.1.0 for QCP-n, 0.4.0.194112.1.1 for QCP-l, 0.4.0.194112.1.2 for QCP-n-, 0.4.0.194112.1.3 for QCP-l-qscd, 0.4.0.194112.1.4 for QEVCP-w, 0.4.0.194112.1.5 for QNCP-w, and 0.4.0.194112.1.6 for QNCP-w-gen. EN 319 411-2 also permits an OID allocated by the TSP or another stakeholder, but the policy it identifies must state which EN 319 411-2 policy it uses as its basis.

  • Use QCP-n for natural-person EU qualified certificates and QCP-l for legal-person EU qualified certificates.
  • Use QCP-n- or QCP-l-qscd when the qualified certificate route requires the private key to reside in a QSCD.
  • Use QEVCP-w, QNCP-w, or QNCP-w-gen for qualified website authentication certificates, depending on whether the route relies on EVCP, OVCP or IVCP, or the general WEB-tagged requirements.
  • Do not use the presence of an ETSI as proof of qualified status; verify the provider and the specific service in the applicable trusted list.
Citations
Question 2

How should a QTSP choose the correct EN 319 411-2 policy identifier?

Apply the choice in four steps. First identify the intended use: signature, seal, or website authentication. Second identify the subject as a natural person or legal person. Third decide whether the signature or seal key must reside in a . Fourth, for website authentication, select the EV, organization or individual validation, or general-purpose assurance route. A certificate intended for another use is outside these seven policy profiles.

Then check the device and baseline inheritance. EN 319 411-2 states that QCP-n and QCP-l use NCP unless the TSP terms and conditions require a secure cryptographic device, in which case NCP+ applies. The -specific policies include the corresponding QCP policy plus QSCD provisions. Website routes inherit EVCP, NCP, OVCP or IVCP, and WEB-tagged requirements as applicable.

  • Record the subject category: natural person, legal person, or website authentication certificate subject.
  • Record whether the service requires a and whether the must include a QSCD-specific identifier.
  • Record the inherited baseline: NCP, NCP+, EVCP, OVCP, IVCP, or WEB-tagged EN 319 411-1 requirements.
  • Record the outcome and exclusion: selected policy, rejected alternatives, facts that drove the choice, reviewer, approval date, and the change events that require a new decision.
Citations
Question 3

What evidence should support a qualified certificate policy claim?

The evidence should prove that the selected policy identifier matches the certificate type and the service actually operated. Keep the CP/CPS section that names the policy, the certificate profile showing the , the terms and conditions that determine secure-device use, and issuance or audit evidence showing whether the service follows the inherited EN 319 411-1 requirements. Sample issued certificates and trace each one back through identity validation, approval, profile generation, publication, status service, and revocation handling.

Do not treat Annex A as a legal conformance certificate. EN 319 411-2 says the annex maps policy references to eIDAS requirements, but also warns that the annex is not a definitive statement of conformance to eIDAS and that non-technical legal requirements are outside the standard's scope.

  • Keep the CP/CPS policy section and the exact used in issued certificates.
  • Keep terms and conditions showing whether QCP-n or QCP-l uses NCP or NCP+ because a secure cryptographic device is required.
  • Keep evidence that , EVCP, OVCP, IVCP, or WEB-tagged inherited requirements were applied when the selected policy depends on them.
  • Keep Annex A mapping as supporting traceability, not as a standalone legal-conformance conclusion.
Citations
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • eIDAS is the legal framework referenced by EN 319 411-2 for EU qualified certificates and qualified website authentication certificates.
"electronic identification and trust services"
etsi.org
Referenced sections
  • EN 319 411-2 builds its qualified policies on EN 319 411-1 NCP, NCP+, EVCP, OVCP, IVCP, DVCP, and WEB-tagged requirements.
"Policy and security requirements for Trust Service Providers issuing certificates"
Related guides

Explore more topics

eIDAS QTSP supervision workflow for ETSI EN 319 411-2
Operational workflow for qualified trust service providers using ETSI EN 319 411-2 to manage supervisory-body changes, incidents, termination evidence, trusted-list checks, and assessment records.
ETSI EN 319 411-2 certificate operations
Operational guide for ETSI EN 319 411-2 qualified certificate services: policy identifiers, identity validation, issuance, QSCD handling, revocation status, and relying-party notices.
ETSI EN 319 411-2 compliance checklist
Compliance checklist for ETSI EN 319 411-2 qualified certificate services, covering policy selection, CP/CPS evidence, identity validation, QSCD status, trusted-list reliance, and certificate status services.
ETSI EN 319 411-2 FAQ for EU Qualified Certificates
Answers to common ETSI EN 319 411-2 questions about EU qualified certificate policies, QSCD use, identity validation, trusted lists, and revocation status services.
ETSI EN 319 411-2 Identity Proofing
How EN 319 411-2 applies identity validation for EU qualified certificates, including QCP natural-person, legal-person, website, and evidence-record checks.
ETSI EN 319 411-2 profile selector
Select the right ETSI EN 319 411-2 qualified certificate policy profile for signatures, seals, QSCD use, and website authentication.
ETSI EN 319 411-2 QSCD Route
When QCP-n-qscd or QCP-l-qscd is the right EN 319 411-2 route, what QSCD evidence is needed, and which certificate-profile claims must stay aligned.
ETSI EN 319 411-2 QTSP supervision evidence workflow
Build an assessment-ready QTSP supervision evidence pack for ETSI EN 319 411-2 qualified certificate services, covering policy identifiers, trusted-list checks, incident records, QSCD evidence, and termination controls.
ETSI EN 319 411-2 Qualified Certificate Scope
Use ETSI EN 319 411-2 to scope EU qualified certificate services by certificate policy, subject type, QSCD use, website authentication profile, and eIDAS context.
ETSI EN 319 411-2 requirements map
Map ETSI EN 319 411-2 requirements for EU qualified certificate services across QCP profiles, CP/CPS documentation, QSCD use, certificate profiles, revocation, and eIDAS Annex A references.
ETSI EN 319 411-2 trusted-list evidence
Build EN 319 411-2 trusted-list evidence for EU qualified certificate reliance: relying-party notice text, QTSP service identifiers, validation records, and change triggers.
ETSI EN 319 411-2 trusted-list validation workflow
Validate an EN 319 411-2 EU qualified-certificate claim by mapping the certificate service to the QTSP trusted-list entry, policy profile, relying-party notice, and status evidence.
ETSI EN 319 411-2 vs eIDAS Qualified Trust Services
Compare ETSI EN 319 411-2 certificate policy requirements with the eIDAS qualified-status, supervision, audit, and trusted-list framework.
ETSI EN 319 411-2 vs EN 319 411-1
Compare ETSI EN 319 411-2 EU qualified certificate requirements with EN 319 411-1 general certificate-service requirements, including policy inheritance, QSCD controls, and CP/CPS evidence reuse.
ETSI EN 319 411-2: Certificate Revocation FAQ
Answer the ETSI EN 319 411-2 revocation question for qualified certificate services: CPS procedures, 24-hour publication, CRL or OCSP status, and evidence to retain.
ETSI EN 319 411-2: end-to-end qualified certificate lifecycle management workflow
Lifecycle workflow for ETSI EN 319 411-2 qualified certificate services, from policy selection and identity validation through issuance, renewal, re-key, modification, revocation, status services, and records.
ETSI EN 319 411-2: Legal vs Natural Person Certs
ETSI EN 319 411-2 separates qualified certificate policies for natural persons, legal persons, QSCD use, and website authentication subscribers.
ETSI EN 319 411-2: QCP, QNCP, and QEVCP Profile Selection
Choose the right ETSI EN 319 411-2 qualified certificate policy profile: QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.
How should QTSPs select an ETSI EN 319 411-2 qualified certificate profile?
A focused FAQ on choosing QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen under ETSI EN 319 411-2.
How should relying parties use trusted lists under ETSI EN 319 411-2?
FAQ on EN 319 411-2 trusted-list reliance for EU qualified certificates: relying-party notices, QTSP service identifiers, validation evidence, and source references.
QSCD Requirements in ETSI EN 319 411-2
How ETSI EN 319 411-2 treats QSCD-backed qualified certificates, including QCP-n-qscd and QCP-l-qscd policies, key-use controls, QSCD verification, and certificate profile evidence.
QTSP Supervision and ETSI EN 319 411-2
How ETSI EN 319 411-2 supports QTSP supervision evidence for qualified certificate services, trusted-list reliance, liability responsibility, incident records, and audit preparation.
Qualified certificates under ETSI EN 319 411-2
FAQ answer for QTSPs on how ETSI EN 319 411-2 treats EU qualified certificates, policy identifiers, QSCD variants, website certificates, and lifecycle evidence.
Which QWAC Profile Fits ETSI EN 319 411-2?
Choose between QEVCP-w, QNCP-w, and QNCP-w-gen for qualified website authentication certificates under ETSI EN 319 411-2.