How do the three QWAC profiles differ?
ETSI EN 319 411-2 defines three EU qualified website authentication certificate policy profiles: , QNCP-w, and . The selected policy determines which EN 319 411-1 baseline, CA/Browser Forum dependency, and qualified-certificate additions must appear in the CP, CPS, certificate profile, and evidence pack.
Apply three tests in order. First, confirm the certificate is for website authentication rather than signature or seal use. Second, identify the subscriber as a natural or legal person. Third, identify the assurance package. Choose only for a legal person under the Extended Validation Certificate Policy and EVCG route. Choose QNCP-w for a natural or legal person under NCP plus OVCP or IVCP and the Baseline Requirements. Choose for the general-purpose route based on NCP plus selected WEB-tagged requirements in EN 319 411-1.
Profile selection is only one layer. Current eIDAS Article 45 requires a qualified website authentication certificate to meet Annex IV, and qualified status still depends on the issuing service's trusted-list entry. Annex IV requires, among other data, the subject's identity, address elements, operated domain names, validity period, unique certificate code, issuer signature or seal, and validity-status service information. From 6 January 2027, Commission Implementing Regulation (EU) 2025/2527 lists EN 319 411-2 V2.6.1 with , QNCP-w, or as a reference-standards route for QWACs used in transport layer security authentication outside a web-browser. It lists for other QWACs, including browser use.
- : legal-person route based on EVCP and the CA/Browser Forum Extended Validation Guidelines.
- QNCP-w: natural-person or legal-person route based on NCP plus OVCP or IVCP and the CA/Browser Forum Baseline Requirements.
- : general-purpose route based on NCP plus selected web-authentication requirements in EN 319 411-1.
- Outside these routes: a generic TLS certificate, domain-validation-only certificate, signature certificate, or seal certificate is not a merely because a QTSP issued it.
Clauses 4.2.2, 5.1, and 5.3 define QEVCP-w, QNCP-w, and QNCP-w-gen and map them to EVCP, NCP, OVCP, IVCP, BRG, EVCG, and web-authentication dependencies.
EN 319 411-1 supplies the EVCP, OVCP, IVCP, NCP, and web-authentication requirements that EN 319 411-2 builds on for qualified website authentication profiles.
Applies from 6 January 2027 and lists EN 319 411-2 V2.6.1 with QEVCP-w, QNCP-w, or QNCP-w-gen for transport layer security authentication outside a web-browser; it lists ETSI TS 119 411-5 V2.1.1 for other QWACs, including browser use.
Defines the ETSI implementation requirements for QWACs assigned to this specification by Regulation (EU) 2025/2527.