How should qualified trust service providers handle qualified certificates under ETSI EN 319 411-2?
Start by separating ETSI policy conformance from EU qualification status. EN 319 411-2 incorporates the general certificate policy and security requirements from EN 319 411-1 and adds requirements for EU services, but conformance to the standard alone does not imply that the TSP or its certificates are qualified.
Under current eIDAS, qualified status follows conformity assessment, supervisory verification, and entry of the provider and service in the national . The certificate must also contain the data required by Annex I for signatures, Annex III for seals, or Annex IV for website authentication. Those Annexes require a machine-readable qualified-certificate indication, issuer and subject identity data, validity dates, a unique certificate code, issuer signature or seal, and status-service information, with type-specific data such as domain names for website certificates and a QSCD indication where applicable. Check all three layers before describing a certificate as qualified.
For each certificate service, identify which EN 319 411-2 policy family is being used: QCP-n for qualified certificates issued to natural persons, QCP-l for legal persons, QCP-n-qscd or QCP-l-qscd when the related private key resides in a QSCD, and QEVCP-w, QNCP-w, or QNCP-w-gen for qualified website authentication certificates. The selected policy drives the certificate-policy statement, controls, certificate profile, subscriber obligations, and evidence set.
- Do not describe a generic certificate as qualified unless the service, certificate policy, trusted-list status, and eIDAS qualification context support that claim.
- For signature and seal certificates, distinguish natural-person, legal-person, and QSCD-backed routes before choosing the QCP identifier or local policy OID.
- For website authentication certificates, distinguish the EVCP-based QEVCP-w route, the BRG and OVCP or IVCP based QNCP-w route, and the general-purpose QNCP-w-gen route.
- Exclude a certificate from the qualified claim when the exact issuing service lacks qualified trusted-list status, required Annex data is missing, the policy route does not match the subject or use, or the certificate was invalid or revoked at the relevant time.
Primary source for qualified certificate policy profiles, QSCD-related routes, qualified website authentication certificates, and QTSP certificate operations.
Primary source for non-qualified certificate policy, CPS, subscriber identity, revocation, repository, CA/RA, and certificate lifecycle requirements.
Consolidated Articles 20 to 22 and Annexes I, III, and IV establish the qualified-status process, trusted-list publication, and required certificate contents.