Artifact GuideGLOBALETSI EN 319 411-2

ETSI EN 319 411-2 How should QTSPs choose the right qualified certificate profile

A standalone answer for certificate policy teams deciding which EN 319 411-2 policy identifier fits a qualified signature, seal, QSCD, or website authentication certificate.

Based on ETSI EN 319 411-2, ETSI EN 319 411-1, and eIDAS source material.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Select the EN 319 411-2 from the intended qualified use, not from a template name. Use QCP-n for natural-person signature certificates, QCP-l for legal-person seal certificates, the - variants when the private key must reside in a QSCD, and one of the three website profiles for a . Then verify the inherited baseline, certificate contents, issuing-service status, and operating evidence.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

How should a QTSP choose between QCP-n, QCP-l, QSCD, and website profiles?

Use five inputs: intended use, subject type, condition, website assurance route, and issuing service scope. EN 319 411-2 defines separate policy identifiers for qualified certificates issued to natural persons, qualified certificates issued to legal persons, qualified certificates tied to a QSCD, and a . If the intended use is outside signature, seal, or website authentication, these seven profiles do not answer the certificate-policy question.

For signatures, the natural-person route is QCP-n, and QCP-n- is used where the private key related to the certified public key resides in a QSCD. For seals, the legal-person route is QCP-l, and QCP-l-qscd is used where the private key resides in a QSCD. For website authentication, EN 319 411-2 separates QEVCP-w, QNCP-w, and QNCP-w-gen depending on the certificate route and the assurance model behind it. QEVCP-w follows EVCG-based requirements, QNCP-w follows BRG-based requirements for natural or legal persons, and QNCP-w-gen is the general-purpose website-authentication route.

Use the subject and assurance model together. A natural-person signature route points to QCP-n or QCP-n-, and a legal-person seal route points to QCP-l or QCP-l-qscd. For website authentication, QEVCP-w applies only to the EVCP and EVCG route for a legal person; QNCP-w applies to a natural or legal person under NCP plus IVCP or OVCP and the Baseline Requirements; QNCP-w-gen is the general-purpose NCP and WEB-tagged route. Do not choose QEVCP-w merely because the subscriber is a legal person.

  • Use QCP-n when the qualified certificate is issued to a natural person for advanced electronic signatures based on a qualified certificate.
  • Use QCP-l when the qualified certificate is issued to a legal person for advanced electronic seals based on a qualified certificate.
  • Use QCP-n- or QCP-l-qscd only when the selected signature or seal route requires the private key to reside in a QSCD.
  • Use QEVCP-w for the EVCP and EVCG route, QNCP-w for the NCP plus IVCP or OVCP and BRG route, and QNCP-w-gen for the NCP plus WEB-tagged general-purpose route.
  • Record the rejected profiles and why they do not fit. For example, a legal-person website subscriber does not by itself select QEVCP-w; the service also needs the EVCP and EVCG assurance route.
Citations
Question 2

What should the profile-selection record show?

The record should show why the certificate policy and certificate contents match the qualified service being offered. EN 319 411-2 says that including one of its policy identifiers indicates the certificate is issued and managed according to that policy. The identifier does not replace the separate eIDAS checks for certificate contents and trusted-list status. Retain the decision inputs, approver, effective date, sample certificate, automated profile test result, and link to the CP, CPS, terms, identity workflow, and issuance configuration.

For a profile, record why the service uses the -qscd route, how the certificate policy or CPS expresses the QSCD condition, and how the certificate includes the required QSCD statement.

  • Identify the selected EN 319 411-2 profile and the exact policy identifier or TSP-allocated policy OID used in the certificate.
  • Record whether the subject is a natural person, a legal person, or a website-authentication subject, because the profile families are split on that basis.
  • For QCP-n- and QCP-l-qscd, keep evidence that the QSCD route is intended and that the required QSCD qcStatement is included only for those profiles.
  • For website authentication, record whether the route is QEVCP-w, QNCP-w, or QNCP-w-gen and how that route relates to EVCP, OVCP, IVCP, or EN 319 411-1 WEB-tagged requirements.
Citations
Question 3

When should the selected profile be reviewed?

Review the selected profile before first issuance and whenever the certificate purpose, subject population, handling, website-authentication route, policy OID, CPS wording, certificate content, inherited standard, CA/Browser Forum requirement, or trusted-list service scope changes. A profile that was correct for a non-QSCD natural-person certificate may be wrong after a QSCD service launch, and a signature or seal profile does not substitute for a website-authentication profile.

The review should compare the certificate policy, CPS, terms and conditions, , and issuance process against the selected EN 319 411-2 policy family before new certificates are issued under the changed route.

  • Reassess when moving between natural-person and legal-person certificates, because QCP-n and QCP-l point to different subject contexts.
  • Reassess before adding or removing reliance, because the -qscd profiles carry extra QSCD-specific requirements and certificate-content implications.
  • Reassess when changing a website certificate route between QEVCP-w, QNCP-w, and QNCP-w-gen, because the underlying assurance model differs.
  • Reassess when using a TSP-allocated policy OID, because EN 319 411-2 expects the referred policy to clearly identify which EN 319 411-2 policy it adopts as the basis.
Citations
Primary sources

References and citations

Related guides

Explore more topics

eIDAS QTSP supervision workflow for ETSI EN 319 411-2
Operational workflow for qualified trust service providers using ETSI EN 319 411-2 to manage supervisory-body changes, incidents, termination evidence, trusted-list checks, and assessment records.
ETSI EN 319 411-2 certificate operations
Operational guide for ETSI EN 319 411-2 qualified certificate services: policy identifiers, identity validation, issuance, QSCD handling, revocation status, and relying-party notices.
ETSI EN 319 411-2 compliance checklist
Compliance checklist for ETSI EN 319 411-2 qualified certificate services, covering policy selection, CP/CPS evidence, identity validation, QSCD status, trusted-list reliance, and certificate status services.
ETSI EN 319 411-2 FAQ for EU Qualified Certificates
Answers to common ETSI EN 319 411-2 questions about EU qualified certificate policies, QSCD use, identity validation, trusted lists, and revocation status services.
ETSI EN 319 411-2 Identity Proofing
How EN 319 411-2 applies identity validation for EU qualified certificates, including QCP natural-person, legal-person, website, and evidence-record checks.
ETSI EN 319 411-2 profile selector
Select the right ETSI EN 319 411-2 qualified certificate policy profile for signatures, seals, QSCD use, and website authentication.
ETSI EN 319 411-2 QSCD Route
When QCP-n-qscd or QCP-l-qscd is the right EN 319 411-2 route, what QSCD evidence is needed, and which certificate-profile claims must stay aligned.
ETSI EN 319 411-2 QTSP supervision evidence workflow
Build an assessment-ready QTSP supervision evidence pack for ETSI EN 319 411-2 qualified certificate services, covering policy identifiers, trusted-list checks, incident records, QSCD evidence, and termination controls.
ETSI EN 319 411-2 Qualified Certificate Scope
Use ETSI EN 319 411-2 to scope EU qualified certificate services by certificate policy, subject type, QSCD use, website authentication profile, and eIDAS context.
ETSI EN 319 411-2 requirements map
Map ETSI EN 319 411-2 requirements for EU qualified certificate services across QCP profiles, CP/CPS documentation, QSCD use, certificate profiles, revocation, and eIDAS Annex A references.
ETSI EN 319 411-2 trusted-list evidence
Build EN 319 411-2 trusted-list evidence for EU qualified certificate reliance: relying-party notice text, QTSP service identifiers, validation records, and change triggers.
ETSI EN 319 411-2 trusted-list validation workflow
Validate an EN 319 411-2 EU qualified-certificate claim by mapping the certificate service to the QTSP trusted-list entry, policy profile, relying-party notice, and status evidence.
ETSI EN 319 411-2 vs eIDAS Qualified Trust Services
Compare ETSI EN 319 411-2 certificate policy requirements with the eIDAS qualified-status, supervision, audit, and trusted-list framework.
ETSI EN 319 411-2 vs EN 319 411-1
Compare ETSI EN 319 411-2 EU qualified certificate requirements with EN 319 411-1 general certificate-service requirements, including policy inheritance, QSCD controls, and CP/CPS evidence reuse.
ETSI EN 319 411-2: Certificate Revocation FAQ
Answer the ETSI EN 319 411-2 revocation question for qualified certificate services: CPS procedures, 24-hour publication, CRL or OCSP status, and evidence to retain.
ETSI EN 319 411-2: end-to-end qualified certificate lifecycle management workflow
Lifecycle workflow for ETSI EN 319 411-2 qualified certificate services, from policy selection and identity validation through issuance, renewal, re-key, modification, revocation, status services, and records.
ETSI EN 319 411-2: Legal vs Natural Person Certs
ETSI EN 319 411-2 separates qualified certificate policies for natural persons, legal persons, QSCD use, and website authentication subscribers.
ETSI EN 319 411-2: QCP, QNCP, and QEVCP Profile Selection
Choose the right ETSI EN 319 411-2 qualified certificate policy profile: QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.
How should relying parties use trusted lists under ETSI EN 319 411-2?
FAQ on EN 319 411-2 trusted-list reliance for EU qualified certificates: relying-party notices, QTSP service identifiers, validation evidence, and source references.
QSCD Requirements in ETSI EN 319 411-2
How ETSI EN 319 411-2 treats QSCD-backed qualified certificates, including QCP-n-qscd and QCP-l-qscd policies, key-use controls, QSCD verification, and certificate profile evidence.
QTSP Supervision and ETSI EN 319 411-2
How ETSI EN 319 411-2 supports QTSP supervision evidence for qualified certificate services, trusted-list reliance, liability responsibility, incident records, and audit preparation.
Qualified certificates under ETSI EN 319 411-2
FAQ answer for QTSPs on how ETSI EN 319 411-2 treats EU qualified certificates, policy identifiers, QSCD variants, website certificates, and lifecycle evidence.
What are the qualified certificate policies in ETSI EN 319 411-2?
FAQ on ETSI EN 319 411-2 qualified certificate policies, including QCP-n, QCP-l, QSCD variants, QEVCP-w, QNCP-w, and policy identifiers.
Which QWAC Profile Fits ETSI EN 319 411-2?
Choose between QEVCP-w, QNCP-w, and QNCP-w-gen for qualified website authentication certificates under ETSI EN 319 411-2.