Artifact GuideGLOBALETSI EN 319 411-2

ETSI EN 319 411-2 Identity Proofing

Choose a current eIDAS identity-verification route, then map the policy profile, subject, attributes, domain link, and registration evidence required before issuance.

Use EN 319 411-2 V2.6.1 with the binding adaptations in Regulation (EU) 2025/1943; the identity reference standard in Regulation (EU) 2025/1566 applies from 19 August 2027.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

For a qualified certificate, must establish the person and each certified attribute through a route allowed by current eIDAS Article 24, then retain evidence that the certificate request matches the verified result. Do not treat the unadapted EN 319 411-2 wording about physical presence or equivalent assurance as the complete current-law route list: Regulation (EU) 2025/1943 replaces the relevant signature and seal certificate clauses with references to Article 24(1c) implementing acts.

Section 1

Start with the certificate policy and subject type

Identity proofing depends on the certificate policy and the legal identity route. Identify whether the certificate uses QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen before reviewing the registration file.

The policy identifies what must be bound into the certificate: a natural person, a legal person, a natural person associated with an organization, or a website-authentication subscriber and domain. QSCD status is a separate key and device branch; it does not replace identity or attribute verification.

  • For QCP-n and QCP-n-qscd, prove the natural person's identity and any certificate attributes before issuance.
  • For QCP-l and QCP-l-qscd, prove the legal person's identity and the authority of the representative used for the registration.
  • For QEVCP-w, QNCP-w, and QNCP-w-gen, prove the subscriber identity and the subscriber's link with the domain name to be certified.
  • For a natural person associated with a legal person, keep the natural person as the subject identifier and ensure organization attributes represent the legal person or its sub-entity, as required by the Regulation (EU) 2025/1943 adaptation.
  • For QSCD policy profiles, keep the identity decision aligned with the separate QSCD and certificate-request checks.
Section 2

Choose and document the verification route

Current eIDAS Article 24(1a) allows , directly or through a third party, through an EU Digital Identity Wallet or notified eID means at assurance level high; a qualified signature or seal certificate issued through a permitted underlying route; another method that identifies the person with a high level of confidence and is confirmed by a conformity assessment body; or physical presence with appropriate evidence and procedures under national law. Methods may be combined when needed.

Article 24(1b) has a separate list for attributes, including a qualified electronic attestation of attributes. Record the identity route and attribute route independently when they differ. Regulation (EU) 2025/1566 makes ETSI TS 119 461 V2.1.1 Annex C.3, with adaptations, the reference standard from 19 August 2027; do not present that future application date as a current deadline that has already passed.

  • Record the exact Article 24 route or combination used, the proofing provider, the authoritative or attesting source, the verification result, and any conformity assessment or national-law dependency.
  • For a natural person, retain evidence for the name and each specific attribute that the certificate will contain; do not collect extra identity data merely because the system can.
  • For a legal person, retain the legal-person evidence and, where the route uses a representative, the person's identity and current authority to act.
  • For a website certificate, retain the subscriber-to-domain link in addition to the identity and attribute evidence.
  • For remote or delegated proofing, record impersonation controls, handoffs, failed checks, and the basis for accepting the result.
Section 3

Check the certificate request against the evidence

The proofing result must control issuance. EN 319 411-1 requires the TSP to check that the request is accurate, authorized, and complete against the identity evidence or attestation.

Compare the registration result, request, CP, and certificate profile before signing the certificate. Reject unsupported names, organization identifiers, roles, domains, representative authority, or other attributes. Route QSCD claims to a separate device and key check.

  • Block issuance when the certificate request includes an identity attribute not supported by the registration evidence.
  • Block issuance when a legal-person representative is not supported by mandate, corporate registry, or other authorized-source evidence.
  • Block issuance when a website certificate lacks evidence linking the subscriber to the domain name being certified.
  • Block issuance when the requested identity or attribute route does not meet current Article 24, applicable national law, or the binding adaptation used by the service.
  • Block issuance when a QSCD policy identifier or statement lacks the separate QSCD route evidence.
Section 4

Keep registration records an auditor can replay

The registration record should let an auditor reconstruct the proofing decision. EN 319 411-1 calls for logging registration events and recording the documents or attestations used, unique identification data where applicable, storage location of copies, subscriber agreement choices, the entity accepting the application, validation method, and the receiving TSP or submitting Registration Authority where applicable.

Protect the record as personal data. Store only what the applicable route, policy, law, and evidence purpose require; restrict access; protect confidentiality and integrity; and state the retention period in the practice documentation. A public certificate or artifact should not expose the underlying identity documents.

  • Log each registration event, including certificate re-key or renewal requests when identity evidence is reused or refreshed.
  • Record the type of identity document or authorized attestation presented and the validation method used.
  • Record where application copies, identity documents, and subscriber agreements are stored rather than embedding sensitive material in public-facing artifacts.
  • State the retention period for registration information in the practice statements and identify what would be handed over through a termination plan.
Section 5

Common identity-proofing gaps

The main failures are mismatches: the certificate contains an unsupported attribute, the registration record cannot show the route used, or the service applies old standard wording without the current legal adaptation.

Close each gap in the registration procedure, CPS, subscriber agreement, issuance gate, or evidence-retention process before issuing production certificates.

  • Using a QCP-n or QCP-l profile without recording whether the subject is a natural person, legal person, or natural person associated with a legal person.
  • Treating physical presence and equivalent assurance as the only current legal routes, or accepting a remote route without the Article 24, conformity-assessment, implementing-act, or national-law basis it requires.
  • Approving a website authentication certificate without evidence linking the subscriber identity to the domain name.
  • Keeping copies of identity evidence without a clear storage location, access model, retention period, and privacy control.
  • Publishing broad qualified-certificate claims while the CPS, certificate policy identifier, subscriber agreement, and registration record are not aligned.
Primary sources

References and citations

Related guides

Explore more topics

eIDAS QTSP supervision workflow for ETSI EN 319 411-2
Operational workflow for qualified trust service providers using ETSI EN 319 411-2 to manage supervisory-body changes, incidents, termination evidence, trusted-list checks, and assessment records.
ETSI EN 319 411-2 certificate operations
Operational guide for ETSI EN 319 411-2 qualified certificate services: policy identifiers, identity validation, issuance, QSCD handling, revocation status, and relying-party notices.
ETSI EN 319 411-2 compliance checklist
Compliance checklist for ETSI EN 319 411-2 qualified certificate services, covering policy selection, CP/CPS evidence, identity validation, QSCD status, trusted-list reliance, and certificate status services.
ETSI EN 319 411-2 FAQ for EU Qualified Certificates
Answers to common ETSI EN 319 411-2 questions about EU qualified certificate policies, QSCD use, identity validation, trusted lists, and revocation status services.
ETSI EN 319 411-2 profile selector
Select the right ETSI EN 319 411-2 qualified certificate policy profile for signatures, seals, QSCD use, and website authentication.
ETSI EN 319 411-2 QSCD Route
When QCP-n-qscd or QCP-l-qscd is the right EN 319 411-2 route, what QSCD evidence is needed, and which certificate-profile claims must stay aligned.
ETSI EN 319 411-2 QTSP supervision evidence workflow
Build an assessment-ready QTSP supervision evidence pack for ETSI EN 319 411-2 qualified certificate services, covering policy identifiers, trusted-list checks, incident records, QSCD evidence, and termination controls.
ETSI EN 319 411-2 Qualified Certificate Scope
Use ETSI EN 319 411-2 to scope EU qualified certificate services by certificate policy, subject type, QSCD use, website authentication profile, and eIDAS context.
ETSI EN 319 411-2 requirements map
Map ETSI EN 319 411-2 requirements for EU qualified certificate services across QCP profiles, CP/CPS documentation, QSCD use, certificate profiles, revocation, and eIDAS Annex A references.
ETSI EN 319 411-2 trusted-list evidence
Build EN 319 411-2 trusted-list evidence for EU qualified certificate reliance: relying-party notice text, QTSP service identifiers, validation records, and change triggers.
ETSI EN 319 411-2 trusted-list validation workflow
Validate an EN 319 411-2 EU qualified-certificate claim by mapping the certificate service to the QTSP trusted-list entry, policy profile, relying-party notice, and status evidence.
ETSI EN 319 411-2 vs eIDAS Qualified Trust Services
Compare ETSI EN 319 411-2 certificate policy requirements with the eIDAS qualified-status, supervision, audit, and trusted-list framework.
ETSI EN 319 411-2 vs EN 319 411-1
Compare ETSI EN 319 411-2 EU qualified certificate requirements with EN 319 411-1 general certificate-service requirements, including policy inheritance, QSCD controls, and CP/CPS evidence reuse.
ETSI EN 319 411-2: Certificate Revocation FAQ
Answer the ETSI EN 319 411-2 revocation question for qualified certificate services: CPS procedures, 24-hour publication, CRL or OCSP status, and evidence to retain.
ETSI EN 319 411-2: end-to-end qualified certificate lifecycle management workflow
Lifecycle workflow for ETSI EN 319 411-2 qualified certificate services, from policy selection and identity validation through issuance, renewal, re-key, modification, revocation, status services, and records.
ETSI EN 319 411-2: Legal vs Natural Person Certs
ETSI EN 319 411-2 separates qualified certificate policies for natural persons, legal persons, QSCD use, and website authentication subscribers.
ETSI EN 319 411-2: QCP, QNCP, and QEVCP Profile Selection
Choose the right ETSI EN 319 411-2 qualified certificate policy profile: QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.
How should QTSPs select an ETSI EN 319 411-2 qualified certificate profile?
A focused FAQ on choosing QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen under ETSI EN 319 411-2.
How should relying parties use trusted lists under ETSI EN 319 411-2?
FAQ on EN 319 411-2 trusted-list reliance for EU qualified certificates: relying-party notices, QTSP service identifiers, validation evidence, and source references.
QSCD Requirements in ETSI EN 319 411-2
How ETSI EN 319 411-2 treats QSCD-backed qualified certificates, including QCP-n-qscd and QCP-l-qscd policies, key-use controls, QSCD verification, and certificate profile evidence.
QTSP Supervision and ETSI EN 319 411-2
How ETSI EN 319 411-2 supports QTSP supervision evidence for qualified certificate services, trusted-list reliance, liability responsibility, incident records, and audit preparation.
Qualified certificates under ETSI EN 319 411-2
FAQ answer for QTSPs on how ETSI EN 319 411-2 treats EU qualified certificates, policy identifiers, QSCD variants, website certificates, and lifecycle evidence.
What are the qualified certificate policies in ETSI EN 319 411-2?
FAQ on ETSI EN 319 411-2 qualified certificate policies, including QCP-n, QCP-l, QSCD variants, QEVCP-w, QNCP-w, and policy identifiers.
Which QWAC Profile Fits ETSI EN 319 411-2?
Choose between QEVCP-w, QNCP-w, and QNCP-w-gen for qualified website authentication certificates under ETSI EN 319 411-2.