Artifact GuideGLOBALETSI EN 319 411-2

ETSI EN 319 411-2 QSCD Route

Decide whether an EU qualified certificate service should use the QCP-n-qscd or QCP-l-qscd route.

It covers device certification, QSCD key generation and import conditions, remote management qualification, certificate signals, and status-change handling.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use QCP-n- or QCP-l-qscd only when the private key related to the certified public key resides in a certified QSCD and the full device, key, management, certificate, and status evidence supports that claim. A secure cryptographic device, smart card, hardware security module, or remote signing platform is not automatically a qualified signature or seal creation device. For remote QSCD management, apply the additional qualified-service condition in Regulation (EU) 2025/1943.

Section 1

When the QSCD route applies

Start by separating the basic qualified-certificate policies from the policies. QCP-n and QCP-l cover EU qualified certificates for natural and legal persons. QCP-n-qscd and QCP-l-qscd add the requirement that the private key related to the certified public key resides in a QSCD.

The route changes the inherited policy baseline, certificate request checks, subscriber obligations, certificate profile, CPS disclosures, and monitoring for device-status changes. It also separates natural-person signature keys, which are under the subject's sole control, from legal-person seal keys, which are under the subject's control.

  • Use QCP-n- when the subject is a natural person and the qualified certificate is issued on the basis that the private key resides in a QSCD.
  • Use QCP-l- when the subject is a legal person and the qualified certificate is issued on the basis that the private key resides in a QSCD.
  • Do not use the QCP-n- or QCP-l-qscd identifier for qualified website-authentication profiles; QEVCP-w, QNCP-w, and QNCP-w-gen are separate EN 319 411-2 policies.
  • If a QCP-n or QCP-l implementation requires a secure cryptographic device but not the policy route, keep that distinction visible in the terms, CP, CPS, and evidence pack.
Section 2

Evidence before issuing on the QSCD route

Before issuance, verify that the device is certified as a , whether the issuing TSP or another party prepared it. The request process must establish that the public key comes from a key pair generated by a QSCD.

The import clause is conditional, not a general soft-key exception. If a TSP generates the subject key pair in one and imports it into the QSCD used for signing or sealing, the environmental assumptions and security objectives for both certified-device roles must remain satisfied. If the private key moves between devices, identify key-compromise vulnerabilities and apply adequate mitigations.

If a third-party TSP manages the device on behalf of the subject, the issuer must verify the third party's appropriate qualification. Under Regulation (EU) 2025/1943, a TSP that manages the subject's remote must itself provide the corresponding qualified remote signature- or seal-device management service.

  • Keep the certificate or status evidence used to verify the device before issuance.
  • Record how the certificate request process proves that the certified public key belongs to a -generated key pair.
  • For third-party or remote management, keep the managing TSP's qualified-service trusted-list evidence, service scope, and contractual and technical boundary with the issuer.
  • For imported keys, identify the used for generation and the QSCD used for signing or sealing, then document how both certification assumptions remain satisfied.
  • For any private-key movement, document the path, protection, identified compromise risks, mitigations, and approval before issuance.
Section 3

Certificate profile and disclosure checks

The certificate profile must match the selected route. For QCP-n- and QCP-l-qscd certificates, EN 319 411-2 requires the QSCD qcStatement defined in ETSI EN 319 412-5. The same standard says that the QSCD qcStatement must not be included in certificates that are not issued according to QCP-n-qscd or QCP-l-qscd requirements.

The CP and subscriber-facing disclosure should state whether use is required. The certificate's policy identifier and QSCD qcStatement must agree with the CP, CPS, subscriber obligations, device evidence, and trusted-list scope.

  • Check that the certificate contains the policy identifier for the selected route, or an allocated OID tied to a certificate policy built on the EN 319 411-2 route.
  • Include the qcStatement only for QCP-n-qscd or QCP-l-qscd certificates.
  • Remove the qcStatement from certificates issued under non-QSCD routes.
  • Make the CP, CPS, terms and conditions, and PKI disclosure statement consistent with the selected route.
Section 4

Monitoring and change handling

The route needs monitoring after issuance because the device status can change while certificates are still valid. EN 319 411-2 requires the TSP to take appropriate measures when QSCD status changes before the certificate validity period ends and to document those measures in the CPS.

The standard points to Member State notifications on designated bodies and certified QSCDs as a monitoring source. Loss of certification status affects the validity of a non-expired certificate bearing the QSCD qcStatement and triggers the inherited revocation requirement when the TSP becomes aware of the change.

  • Track the status source used for each device or remote signing arrangement.
  • Define in the CPS what happens if the certification status changes before certificate expiry.
  • Connect the change process to certificate revocation handling for certificates that carry the qcStatement.
  • Keep revocation-status service evidence aligned with the certificate lifecycle and the CP/CPS explanation of how status information is made available.
Section 5

QSCD route review checklist

Use this checklist for a new profile, a CP/CPS change, a remote-management arrangement, or an existing evidence pack.

  • Route: confirm that the service is actually issuing under QCP-n- or QCP-l-qscd, not only using a secure cryptographic device under QCP-n or QCP-l.
  • Device evidence: keep proof that each relevant device or remote signing service is certified as a .
  • Key evidence: show that the public key comes from a -generated key pair; for an import between QSCD roles, document both devices' assumptions and the protected transfer.
  • Remote management: verify that the manager provides the applicable qualified remote- management service and that the service scope covers the arrangement.
  • Certificate profile: verify the correct policy identifier or allocated OID and the correct inclusion or exclusion of the qcStatement.
  • Disclosure: align the CP, CPS, terms and conditions, and PKI disclosure statement on whether use is required.
  • Status changes: define who monitors status, where the status source is recorded, and how certificate revocation is handled if status is lost.
Primary sources

References and citations

etsi.org
Referenced sections
  • Supports the issuance evidence needed for QSCD certification status, QSCD-generated key pairs, third-party managed devices, imported keys, and private-key movement.
"verify that the device is certified as a QSCD"
etsi.org
Referenced sections
  • Supports the need to monitor QSCD status, document measures in the CPS, and treat loss of QSCD certification status as a validity-impacting change.
"measures in case of modification of the QSCD status"
etsi.org
Referenced sections
  • Defines QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, and QNCP-w-gen, including the QSCD-specific routes for natural and legal persons.
"private key related to the certified public key resides in the QSCD"
eur-lex.europa.eu
Referenced sections
  • Provides the EU legal context for qualified certificates and qualified signature or seal creation devices referenced by EN 319 411-2.
"electronic identification and trust services"
Related guides

Explore more topics

eIDAS QTSP supervision workflow for ETSI EN 319 411-2
Operational workflow for qualified trust service providers using ETSI EN 319 411-2 to manage supervisory-body changes, incidents, termination evidence, trusted-list checks, and assessment records.
ETSI EN 319 411-2 certificate operations
Operational guide for ETSI EN 319 411-2 qualified certificate services: policy identifiers, identity validation, issuance, QSCD handling, revocation status, and relying-party notices.
ETSI EN 319 411-2 compliance checklist
Compliance checklist for ETSI EN 319 411-2 qualified certificate services, covering policy selection, CP/CPS evidence, identity validation, QSCD status, trusted-list reliance, and certificate status services.
ETSI EN 319 411-2 FAQ for EU Qualified Certificates
Answers to common ETSI EN 319 411-2 questions about EU qualified certificate policies, QSCD use, identity validation, trusted lists, and revocation status services.
ETSI EN 319 411-2 Identity Proofing
How EN 319 411-2 applies identity validation for EU qualified certificates, including QCP natural-person, legal-person, website, and evidence-record checks.
ETSI EN 319 411-2 profile selector
Select the right ETSI EN 319 411-2 qualified certificate policy profile for signatures, seals, QSCD use, and website authentication.
ETSI EN 319 411-2 QTSP supervision evidence workflow
Build an assessment-ready QTSP supervision evidence pack for ETSI EN 319 411-2 qualified certificate services, covering policy identifiers, trusted-list checks, incident records, QSCD evidence, and termination controls.
ETSI EN 319 411-2 Qualified Certificate Scope
Use ETSI EN 319 411-2 to scope EU qualified certificate services by certificate policy, subject type, QSCD use, website authentication profile, and eIDAS context.
ETSI EN 319 411-2 requirements map
Map ETSI EN 319 411-2 requirements for EU qualified certificate services across QCP profiles, CP/CPS documentation, QSCD use, certificate profiles, revocation, and eIDAS Annex A references.
ETSI EN 319 411-2 trusted-list evidence
Build EN 319 411-2 trusted-list evidence for EU qualified certificate reliance: relying-party notice text, QTSP service identifiers, validation records, and change triggers.
ETSI EN 319 411-2 trusted-list validation workflow
Validate an EN 319 411-2 EU qualified-certificate claim by mapping the certificate service to the QTSP trusted-list entry, policy profile, relying-party notice, and status evidence.
ETSI EN 319 411-2 vs eIDAS Qualified Trust Services
Compare ETSI EN 319 411-2 certificate policy requirements with the eIDAS qualified-status, supervision, audit, and trusted-list framework.
ETSI EN 319 411-2 vs EN 319 411-1
Compare ETSI EN 319 411-2 EU qualified certificate requirements with EN 319 411-1 general certificate-service requirements, including policy inheritance, QSCD controls, and CP/CPS evidence reuse.
ETSI EN 319 411-2: Certificate Revocation FAQ
Answer the ETSI EN 319 411-2 revocation question for qualified certificate services: CPS procedures, 24-hour publication, CRL or OCSP status, and evidence to retain.
ETSI EN 319 411-2: end-to-end qualified certificate lifecycle management workflow
Lifecycle workflow for ETSI EN 319 411-2 qualified certificate services, from policy selection and identity validation through issuance, renewal, re-key, modification, revocation, status services, and records.
ETSI EN 319 411-2: Legal vs Natural Person Certs
ETSI EN 319 411-2 separates qualified certificate policies for natural persons, legal persons, QSCD use, and website authentication subscribers.
ETSI EN 319 411-2: QCP, QNCP, and QEVCP Profile Selection
Choose the right ETSI EN 319 411-2 qualified certificate policy profile: QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.
How should QTSPs select an ETSI EN 319 411-2 qualified certificate profile?
A focused FAQ on choosing QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen under ETSI EN 319 411-2.
How should relying parties use trusted lists under ETSI EN 319 411-2?
FAQ on EN 319 411-2 trusted-list reliance for EU qualified certificates: relying-party notices, QTSP service identifiers, validation evidence, and source references.
QSCD Requirements in ETSI EN 319 411-2
How ETSI EN 319 411-2 treats QSCD-backed qualified certificates, including QCP-n-qscd and QCP-l-qscd policies, key-use controls, QSCD verification, and certificate profile evidence.
QTSP Supervision and ETSI EN 319 411-2
How ETSI EN 319 411-2 supports QTSP supervision evidence for qualified certificate services, trusted-list reliance, liability responsibility, incident records, and audit preparation.
Qualified certificates under ETSI EN 319 411-2
FAQ answer for QTSPs on how ETSI EN 319 411-2 treats EU qualified certificates, policy identifiers, QSCD variants, website certificates, and lifecycle evidence.
What are the qualified certificate policies in ETSI EN 319 411-2?
FAQ on ETSI EN 319 411-2 qualified certificate policies, including QCP-n, QCP-l, QSCD variants, QEVCP-w, QNCP-w, and policy identifiers.
Which QWAC Profile Fits ETSI EN 319 411-2?
Choose between QEVCP-w, QNCP-w, and QNCP-w-gen for qualified website authentication certificates under ETSI EN 319 411-2.