Artifact GuideGLOBALETSI EN 319 411-2

ETSI EN 319 411-2 Trusted-list reliance FAQ

A direct answer to what EN 319 411-2 expects a QTSP to tell relying parties about EU trusted lists and qualified-certificate validation.

This page helps review relying-party notices, CP/CPS language, validation procedures, and trusted-list evidence before making an EU qualified-certificate reliance claim.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

A relying party should verify the specific qualified service and its status in the relevant national , then use the identified by that service entry. A provider name, certificate chain, or policy OID on its own does not establish qualified status.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What does EN 319 411-2 require for trusted-list reliance?

ETSI EN 319 411-2 requires the relying-party notice to state that, as one condition for relying on the certificate as an EU Qualified Certificate, the validation is identified in the of the appropriate EU trusted-list entry for the QTSP. This is a condition of the qualified-certificate reliance path, not a general statement that every certificate chaining to the provider is qualified.

That means the public reliance message should name the trusted-list dependency clearly. Under eIDAS Articles 21 and 22, a provider may begin a qualified service only after its qualified status appears in the , and each national list identifies both the QTSP and its qualified services. A certificate policy OID, CA certificate, repository page, or provider claim is not enough by itself.

  • Put the trusted-list condition in the relying-party notice or the terms and conditions referenced by that notice.
  • Tie the claim to the QTSP and qualified trust service entry, not only to a generic provider name or certificate chain.
  • Keep the certificate policy identifier visible because EN 319 411-2 says policy identifiers help relying parties assess suitability and trustworthiness under eIDAS.
  • Reject the qualified-certificate conclusion when the listed service type does not cover the certificate, the relevant service status was not qualified at the validation time, the chain does not connect through the listed service identity, or certificate validity and revocation checks fail.
Citations
Question 2

What should a QTSP publish or retain for relying parties?

The practical evidence set should show that relying parties were told how qualified-certificate reliance depends on the relevant EU trusted-list entry. Keep the public notice text, the CP/CPS or terms section it points to, and a mapping from the certificate service to the trusted-list .

For operational review, retain a dated validation record showing the trusted-list source checked, list signature or seal authentication result, QTSP name, service type and identifier, service status and status history considered, certificate profile or policy OID, path-validation result, revocation result, validation time, and procedure version. For a signature or certificate created in the past, validate status at the relevant time rather than relying only on the entry's current status. The record documents the reliance process; it does not replace the signed or sealed .

  • Relying-party notice: the exact wording that explains the EU trusted-list condition.
  • Service mapping: QTSP, qualified trust service, , certificate profile, and policy OID.
  • Validation record: trusted-list source, date checked, result, reviewer or system owner, and exception handling if the entry or status changes.
  • Change trigger: recheck after trusted-list updates, QTSP service-status changes, CP/CPS changes, certificate-profile changes, or validation failures.
  • Exception record: preserve the certificate, trusted-list snapshot or reference, failed condition, system decision, reviewer, and disposition; do not silently fall back to an unlisted root.
Citations
Question 3

How should validation teams use trusted-list standards?

Use EN 319 411-2 to identify the relying-party notice obligation, then use the current trusted-list standards for the validation method. ETSI TS 119 612 V2.4.1 defines the trusted-list format and . ETSI TS 119 615 V1.3.1 specifies procedures for obtaining, authenticating, using, and interpreting EU Member State national trusted lists, including status at a specified date and time. Pin the procedure and trusted-list version used so a later reviewer can reproduce the result.

If the validation question is about whether a signature or seal qualifies, keep that separate from merely checking a certificate. EN 319 411-2 points to ETSI TS 119 172-4 for a signature validation policy that describes validation against EU trusted lists for European qualified electronic signatures or seals.

  • Use TS 119 612 terminology when documenting the and trusted-list entry.
  • Use TS 119 615-aligned procedures when deciding whether a certificate can be considered an EU qualified certificate from trusted-list data.
  • Use TS 119 172-4-aligned validation policy evidence when the relying-party outcome concerns a qualified electronic signature or seal.
Citations
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Consolidated Articles 21 and 22 establish when a qualified service may begin and require national trusted lists to identify qualified providers and their qualified services.
etsi.org
Referenced sections
  • OVR-6.3.5-12 requires the notice to relying parties to explain that the validation trust anchor is identified in the service digital identifier of an appropriate EU trusted-list entry.
"service digital identifier of an appropriate EU trusted list entry"
etsi.org
Referenced sections
  • The notes below OVR-6.3.5-12 reference Implementing Decision 2015/1505 for trusted-list formats and ETSI TS 119 615 for validating a certificate against EU trusted lists.
"validate a digital certificate against the EU trusted lists"
etsi.org
Referenced sections
  • Referenced by EN 319 411-2 for the service digital identifier of the appropriate EU trusted-list entry.
"Trusted Lists"
etsi.org
Referenced sections
  • Current ETSI procedures for obtaining, authenticating, using, and interpreting EU Member State trusted lists and determining status at a specified date and time.
"Procedures for using and interpreting European Union Member States national trusted lists"
Related guides

Explore more topics

eIDAS QTSP supervision workflow for ETSI EN 319 411-2
Operational workflow for qualified trust service providers using ETSI EN 319 411-2 to manage supervisory-body changes, incidents, termination evidence, trusted-list checks, and assessment records.
ETSI EN 319 411-2 certificate operations
Operational guide for ETSI EN 319 411-2 qualified certificate services: policy identifiers, identity validation, issuance, QSCD handling, revocation status, and relying-party notices.
ETSI EN 319 411-2 compliance checklist
Compliance checklist for ETSI EN 319 411-2 qualified certificate services, covering policy selection, CP/CPS evidence, identity validation, QSCD status, trusted-list reliance, and certificate status services.
ETSI EN 319 411-2 FAQ for EU Qualified Certificates
Answers to common ETSI EN 319 411-2 questions about EU qualified certificate policies, QSCD use, identity validation, trusted lists, and revocation status services.
ETSI EN 319 411-2 Identity Proofing
How EN 319 411-2 applies identity validation for EU qualified certificates, including QCP natural-person, legal-person, website, and evidence-record checks.
ETSI EN 319 411-2 profile selector
Select the right ETSI EN 319 411-2 qualified certificate policy profile for signatures, seals, QSCD use, and website authentication.
ETSI EN 319 411-2 QSCD Route
When QCP-n-qscd or QCP-l-qscd is the right EN 319 411-2 route, what QSCD evidence is needed, and which certificate-profile claims must stay aligned.
ETSI EN 319 411-2 QTSP supervision evidence workflow
Build an assessment-ready QTSP supervision evidence pack for ETSI EN 319 411-2 qualified certificate services, covering policy identifiers, trusted-list checks, incident records, QSCD evidence, and termination controls.
ETSI EN 319 411-2 Qualified Certificate Scope
Use ETSI EN 319 411-2 to scope EU qualified certificate services by certificate policy, subject type, QSCD use, website authentication profile, and eIDAS context.
ETSI EN 319 411-2 requirements map
Map ETSI EN 319 411-2 requirements for EU qualified certificate services across QCP profiles, CP/CPS documentation, QSCD use, certificate profiles, revocation, and eIDAS Annex A references.
ETSI EN 319 411-2 trusted-list evidence
Build EN 319 411-2 trusted-list evidence for EU qualified certificate reliance: relying-party notice text, QTSP service identifiers, validation records, and change triggers.
ETSI EN 319 411-2 trusted-list validation workflow
Validate an EN 319 411-2 EU qualified-certificate claim by mapping the certificate service to the QTSP trusted-list entry, policy profile, relying-party notice, and status evidence.
ETSI EN 319 411-2 vs eIDAS Qualified Trust Services
Compare ETSI EN 319 411-2 certificate policy requirements with the eIDAS qualified-status, supervision, audit, and trusted-list framework.
ETSI EN 319 411-2 vs EN 319 411-1
Compare ETSI EN 319 411-2 EU qualified certificate requirements with EN 319 411-1 general certificate-service requirements, including policy inheritance, QSCD controls, and CP/CPS evidence reuse.
ETSI EN 319 411-2: Certificate Revocation FAQ
Answer the ETSI EN 319 411-2 revocation question for qualified certificate services: CPS procedures, 24-hour publication, CRL or OCSP status, and evidence to retain.
ETSI EN 319 411-2: end-to-end qualified certificate lifecycle management workflow
Lifecycle workflow for ETSI EN 319 411-2 qualified certificate services, from policy selection and identity validation through issuance, renewal, re-key, modification, revocation, status services, and records.
ETSI EN 319 411-2: Legal vs Natural Person Certs
ETSI EN 319 411-2 separates qualified certificate policies for natural persons, legal persons, QSCD use, and website authentication subscribers.
ETSI EN 319 411-2: QCP, QNCP, and QEVCP Profile Selection
Choose the right ETSI EN 319 411-2 qualified certificate policy profile: QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.
How should QTSPs select an ETSI EN 319 411-2 qualified certificate profile?
A focused FAQ on choosing QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen under ETSI EN 319 411-2.
QSCD Requirements in ETSI EN 319 411-2
How ETSI EN 319 411-2 treats QSCD-backed qualified certificates, including QCP-n-qscd and QCP-l-qscd policies, key-use controls, QSCD verification, and certificate profile evidence.
QTSP Supervision and ETSI EN 319 411-2
How ETSI EN 319 411-2 supports QTSP supervision evidence for qualified certificate services, trusted-list reliance, liability responsibility, incident records, and audit preparation.
Qualified certificates under ETSI EN 319 411-2
FAQ answer for QTSPs on how ETSI EN 319 411-2 treats EU qualified certificates, policy identifiers, QSCD variants, website certificates, and lifecycle evidence.
What are the qualified certificate policies in ETSI EN 319 411-2?
FAQ on ETSI EN 319 411-2 qualified certificate policies, including QCP-n, QCP-l, QSCD variants, QEVCP-w, QNCP-w, and policy identifiers.
Which QWAC Profile Fits ETSI EN 319 411-2?
Choose between QEVCP-w, QNCP-w, and QNCP-w-gen for qualified website authentication certificates under ETSI EN 319 411-2.