FAQGLOBALETSI EN 319 411-2

ETSI EN 319 411-2 Which QWAC profile should a QTSP use?

A cited answer for selecting the ETSI EN 319 411-2 qualified website authentication certificate profile.

Use it to separate QEVCP-w, QNCP-w, and QNCP-w-gen evidence before updating a CP, CPS, certificate profile, or audit pack.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 26, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 26, 2026
Overview

Choose the profile from the subscriber and assurance route, not from the word qualified alone. is the EVCP and EVCG route for legal persons, QNCP-w is the NCP plus OVCP or IVCP and Baseline Requirements route for natural or legal persons, and is the general-purpose NCP plus WEB-tagged route. Every route still requires Annex IV content, subscriber and domain-link validation, and a qualified trusted-list service entry. From 6 January 2027, Regulation (EU) 2025/2527 uses these EN 319 411-2 profiles as a reference-standards route only for QWACs used in transport layer security authentication outside a web-browser. It lists for other QWACs, including those used in a web-browser.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

How do the three QWAC profiles differ?

ETSI EN 319 411-2 defines three EU qualified website authentication certificate policy profiles: , QNCP-w, and . The selected policy determines which EN 319 411-1 baseline, CA/Browser Forum dependency, and qualified-certificate additions must appear in the CP, CPS, certificate profile, and evidence pack.

Apply three tests in order. First, confirm the certificate is for website authentication rather than signature or seal use. Second, identify the subscriber as a natural or legal person. Third, identify the assurance package. Choose only for a legal person under the Extended Validation Certificate Policy and EVCG route. Choose QNCP-w for a natural or legal person under NCP plus OVCP or IVCP and the Baseline Requirements. Choose for the general-purpose route based on NCP plus selected WEB-tagged requirements in EN 319 411-1.

Profile selection is only one layer. Current eIDAS Article 45 requires a qualified website authentication certificate to meet Annex IV, and qualified status still depends on the issuing service's trusted-list entry. Annex IV requires, among other data, the subject's identity, address elements, operated domain names, validity period, unique certificate code, issuer signature or seal, and validity-status service information. From 6 January 2027, Commission Implementing Regulation (EU) 2025/2527 lists EN 319 411-2 V2.6.1 with , QNCP-w, or as a reference-standards route for QWACs used in transport layer security authentication outside a web-browser. It lists for other QWACs, including browser use.

  • : legal-person route based on EVCP and the CA/Browser Forum Extended Validation Guidelines.
  • QNCP-w: natural-person or legal-person route based on NCP plus OVCP or IVCP and the CA/Browser Forum Baseline Requirements.
  • : general-purpose route based on NCP plus selected web-authentication requirements in EN 319 411-1.
  • Outside these routes: a generic TLS certificate, domain-validation-only certificate, signature certificate, or seal certificate is not a merely because a QTSP issued it.
Citations
Question 2

What must be proven before issuing a QWAC?

For , QNCP-w, and , EN 319 411-2 ties initial validation to the subscriber type and the domain name. If the subscriber is a natural person, verify the subscriber identity and link with the domain name using the QCP-n route. If the subscriber is a legal person, verify the legal-person identity, authorized-representative route, and link with the domain name using the QCP-l route.

That means the evidence pack should not stop at a domain-control check. It should show the selected policy identifier, subscriber type, identity route, authority to request the certificate, link to each certified domain, applicable CA/Browser Forum or WEB-tagged dependency, Annex IV certificate contents, and the issuing service's trusted-list status. Retain the source used for the identity and domain-link check, validation time, reviewer or automated control, result, approval, issued certificate, and later revocation or renewal record.

  • Record the selected policy identifier: , QNCP-w, or .
  • Keep separate evidence for subscriber identity, authority to request the certificate, and the subscriber's link with the domain name.
  • For and QNCP-w, track conflicts or updates in the applicable BRG or EVCG route because EN 319 411-2 gives those requirements precedence in conflict cases.
  • Revalidate the subscriber's link to every added or changed domain and repeat the profile decision when the subscriber type, validation method, assurance route, policy OID, or issuing-service scope changes.
Citations
Question 3

What review checks keep the QWAC profile defensible?

Review the profile whenever the QTSP changes its CP/CPS, certificate profile, subscriber validation workflow, CA/RA responsibility split, repository publication process, or CA/Browser Forum dependency. The review should confirm that the public certificate policy OID and the evidence trail still describe the same qualified website authentication route.

The most useful audit file is a profile matrix: one row for each profile offered, with the policy identifier, subscriber type, EN 319 411-1 dependency, CA/Browser Forum or web-authentication dependency, identity-validation route, domain-link evidence, certificate-profile checks, and repository/status-service evidence.

  • Do not describe a certificate as a unless the EN 319 411-2 profile, Annex IV contents, issuing service's trusted-list status, and certificate-policy evidence all line up.
  • Do not reuse a generic TLS certificate checklist when the qualified website authentication route requires a specific EN 319 411-2 policy identifier.
  • Do not merge , QNCP-w, and findings into one control row; each route has different dependencies and evidence.
Citations
Primary sources

References and citations

Related guides

Explore more topics

eIDAS QTSP supervision workflow for ETSI EN 319 411-2
Operational workflow for qualified trust service providers using ETSI EN 319 411-2 to manage supervisory-body changes, incidents, termination evidence, trusted-list checks, and assessment records.
ETSI EN 319 411-2 certificate operations
Operational guide for ETSI EN 319 411-2 qualified certificate services: policy identifiers, identity validation, issuance, QSCD handling, revocation status, and relying-party notices.
ETSI EN 319 411-2 compliance checklist
Compliance checklist for ETSI EN 319 411-2 qualified certificate services, covering policy selection, CP/CPS evidence, identity validation, QSCD status, trusted-list reliance, and certificate status services.
ETSI EN 319 411-2 FAQ for EU Qualified Certificates
Answers to common ETSI EN 319 411-2 questions about EU qualified certificate policies, QSCD use, identity validation, trusted lists, and revocation status services.
ETSI EN 319 411-2 Identity Proofing
How EN 319 411-2 applies identity validation for EU qualified certificates, including QCP natural-person, legal-person, website, and evidence-record checks.
ETSI EN 319 411-2 profile selector
Select the right ETSI EN 319 411-2 qualified certificate policy profile for signatures, seals, QSCD use, and website authentication.
ETSI EN 319 411-2 QSCD Route
When QCP-n-qscd or QCP-l-qscd is the right EN 319 411-2 route, what QSCD evidence is needed, and which certificate-profile claims must stay aligned.
ETSI EN 319 411-2 QTSP supervision evidence workflow
Build an assessment-ready QTSP supervision evidence pack for ETSI EN 319 411-2 qualified certificate services, covering policy identifiers, trusted-list checks, incident records, QSCD evidence, and termination controls.
ETSI EN 319 411-2 Qualified Certificate Scope
Use ETSI EN 319 411-2 to scope EU qualified certificate services by certificate policy, subject type, QSCD use, website authentication profile, and eIDAS context.
ETSI EN 319 411-2 requirements map
Map ETSI EN 319 411-2 requirements for EU qualified certificate services across QCP profiles, CP/CPS documentation, QSCD use, certificate profiles, revocation, and eIDAS Annex A references.
ETSI EN 319 411-2 trusted-list evidence
Build EN 319 411-2 trusted-list evidence for EU qualified certificate reliance: relying-party notice text, QTSP service identifiers, validation records, and change triggers.
ETSI EN 319 411-2 trusted-list validation workflow
Validate an EN 319 411-2 EU qualified-certificate claim by mapping the certificate service to the QTSP trusted-list entry, policy profile, relying-party notice, and status evidence.
ETSI EN 319 411-2 vs eIDAS Qualified Trust Services
Compare ETSI EN 319 411-2 certificate policy requirements with the eIDAS qualified-status, supervision, audit, and trusted-list framework.
ETSI EN 319 411-2 vs EN 319 411-1
Compare ETSI EN 319 411-2 EU qualified certificate requirements with EN 319 411-1 general certificate-service requirements, including policy inheritance, QSCD controls, and CP/CPS evidence reuse.
ETSI EN 319 411-2: Certificate Revocation FAQ
Answer the ETSI EN 319 411-2 revocation question for qualified certificate services: CPS procedures, 24-hour publication, CRL or OCSP status, and evidence to retain.
ETSI EN 319 411-2: end-to-end qualified certificate lifecycle management workflow
Lifecycle workflow for ETSI EN 319 411-2 qualified certificate services, from policy selection and identity validation through issuance, renewal, re-key, modification, revocation, status services, and records.
ETSI EN 319 411-2: Legal vs Natural Person Certs
ETSI EN 319 411-2 separates qualified certificate policies for natural persons, legal persons, QSCD use, and website authentication subscribers.
ETSI EN 319 411-2: QCP, QNCP, and QEVCP Profile Selection
Choose the right ETSI EN 319 411-2 qualified certificate policy profile: QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.
How should QTSPs select an ETSI EN 319 411-2 qualified certificate profile?
A focused FAQ on choosing QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen under ETSI EN 319 411-2.
How should relying parties use trusted lists under ETSI EN 319 411-2?
FAQ on EN 319 411-2 trusted-list reliance for EU qualified certificates: relying-party notices, QTSP service identifiers, validation evidence, and source references.
QSCD Requirements in ETSI EN 319 411-2
How ETSI EN 319 411-2 treats QSCD-backed qualified certificates, including QCP-n-qscd and QCP-l-qscd policies, key-use controls, QSCD verification, and certificate profile evidence.
QTSP Supervision and ETSI EN 319 411-2
How ETSI EN 319 411-2 supports QTSP supervision evidence for qualified certificate services, trusted-list reliance, liability responsibility, incident records, and audit preparation.
Qualified certificates under ETSI EN 319 411-2
FAQ answer for QTSPs on how ETSI EN 319 411-2 treats EU qualified certificates, policy identifiers, QSCD variants, website certificates, and lifecycle evidence.
What are the qualified certificate policies in ETSI EN 319 411-2?
FAQ on ETSI EN 319 411-2 qualified certificate policies, including QCP-n, QCP-l, QSCD variants, QEVCP-w, QNCP-w, and policy identifiers.