WorkflowGLOBALETSI EN 319 411-2

ETSI EN 319 411-2 QTSP supervision evidence workflow

A workflow for assembling EN 319 411-2 qualified certificate obligations and records into a supervision evidence pack for assessment leads, compliance owners, and supervisory-body liaisons.

Use it to organize operational evidence. Confirm jurisdiction-specific legal, contractual, and policy requirements before implementation; the evidence pack does not prove qualified status by itself.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

This workflow is relevant when a needs to show how an EU qualified certificate service is controlled, monitored, and ready for assessment or supervisory follow-up. The page focuses on evidence that EN 319 411-2 actually supports: qualified certificate policy identifiers, CP/CPS and disclosure material, inherited EN 319 411-1 controls, QSCD checks, trusted-list reliance, incident escalation, status services, record retention, and termination planning.

Section 1

1. Start the evidence pack with the qualified service boundary

Open one evidence pack per qualified certificate service, not one pack for an entire PKI estate. Name the issuing qualified TSP, CA or RA components in scope, certificate policy identifier, CP and CPS versions, PKI disclosure statement, subscriber terms, repository location, and certificate population covered by the review.

EN 319 411-2 defines qualified certificate policies for natural persons, legal persons, QSCD-backed certificates, and qualified website authentication certificates. The supervision file should therefore show exactly which profile is claimed and which EN 319 411-1 baseline controls are inherited.

  • Input: service name, issuing TSP, CA hierarchy, RA route, repository URL, CP/CPS versions, terms and conditions, and assessment period.
  • Profile field: QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.
  • Boundary rule: keep non-qualified certificate evidence separate unless the pack identifies the inherited EN 319 411-1 requirement being reused.
  • Output: a scoped supervision evidence index with owner, source clause, evidence artifact, last review result, and open gaps.
Section 2

2. Triage supervision triggers before the evidence pack changes

Use a trigger log so changes do not disappear into policy edits. A trigger should be opened when the qualified certificate service changes, when the QSCD route changes, when a trusted-list or status-service dependency changes, when a breach or loss of integrity may affect the service, when termination is planned, or when an assessor raises a finding.

The log should separate three decisions: whether the CP/CPS or disclosure material must be updated, whether assessment evidence must be refreshed, and whether the event triggers an eIDAS notification. The amended Article 24 requires at least one month's advance notice before a change in qualified-service provision and at least three months' advance notice before cessation. Commission Implementing Regulation (EU) 2025/2530 identifies significant changes to policies, terms, architecture, hosting, cryptography, registration, governance, termination, financial resources or insurance, trusted-list data, and third-party arrangements. The notice record should contain the change, planned date and time, reasons and supporting evidence where applicable, and updated documents where applicable. Record the national filing channel as a local compliance field.

  • Change trigger: new policy identifier, certificate profile, CA hierarchy, RA process, repository practice, subscriber terms, or relying-party notice.
  • QSCD trigger: new QSCD supplier, third-party TSP involvement, device status change, or missing proof that the certified public key came from a QSCD-generated key pair.
  • Operational trigger: breach or loss of integrity, revocation or status-service issue, last-CRL or beyond-validity status gap, or planned termination.
  • Output: trigger record with owner, affected policy, source clause, evidence to refresh, external action needed, legal notice date, and release decision.
Section 3

3. Build row-level evidence for the supervision file

Treat the supervision pack as a row-level evidence register. Each row should name the claim, source requirement, evidence artifact, owner, review result, and assessor or supervisory relevance. This prevents a CP/CPS statement such as 'qualified certificate' from standing alone without the policy identifier, trusted-list evidence, QSCD route, or status-service proof behind it.

A useful register has enough detail to be reviewed without opening internal systems first. For example, a QSCD-backed QCP-n-qscd row should point to the QSCD certification evidence, key-pair generation evidence, certificate request control, CPS measure for QSCD status changes, and the certificate qcStatement evidence where relevant.

  • Policy row: policy identifier, subject type, baseline inherited from EN 319 411-1, CP/CPS section, terms and conditions, and approval date.
  • Identity row: natural-person, legal-person, or website-authentication route; verification method; RA evidence; and exception handling.
  • QSCD row: device certification evidence, third-party TSP qualification check where applicable, public-key origin proof, status monitoring, and CPS response measure.
  • Trusted-list row: service digital identifier, QTSP entry, relying-party notice, validation date, and owner of follow-up when the entry changes.
  • Status-service row: certificate database, revocation publication evidence, CRL or OCSP availability, beyond-validity handling, and expired-certificate status evidence.
Section 4

4. Preserve incident, record-retention, and termination evidence

Supervision evidence should include more than normal certificate issuance records. EN 319 411-2 maps eIDAS incident, record-accessibility, certificate-database, revocation, status-information, and termination requirements to standard clauses, while warning that its Annex A is informative and not a definitive legal conformance statement.

For incidents, keep the incident time and awareness time separately, affected service, certificate population, integrity impact, personal-data impact, notification assessment, sent notices, containment result, and post-incident control changes. Current Article 24 measures the 24-hour outer limit from the incident when the significant-impact threshold is met. For retention and termination, Commission Implementing Regulation (EU) 2025/2530 requires a plan for each qualified trust service, review at least every two years and whenever provider or service changes are implemented, coverage of anticipated, unanticipated, partial, and complete termination, and records that remain accessible for legal evidence and validation.

  • Incident evidence: incident and awareness timestamps, significant-impact assessment, notification recipients, 24-hour-from-incident deadline assessment, notices sent, and remediation owner.
  • Retention evidence: archive index for data issued and received by the QTSP, legal-proceeding evidence path, and continuity-of-service access path.
  • Termination evidence: service-specific plan, last review and two-year due date, change-triggered review, subscriber and relying-party notices, third-party arrangements, funding or insurance, last-status-service handling, certificate revocation or uninterrupted transfer route, accessible records, and supervisory-body verification point.
  • Caveat: do not present EN 319 411-2 Annex A as complete eIDAS legal conformance; record legal or national-law questions separately.
Section 5

5. Close the workflow with assessor-ready outputs

Close the workflow only when each open trigger has a decision and each material claim has evidence. The closeout should be short enough for an assessment lead to use, but specific enough to show which requirement, certificate policy, evidence artifact, and owner support each claim.

EN 319 411-2 references ETSI TR 119 411-4 as a checklist supporting audit of TSPs against EN 319 411-1 or EN 319 411-2. Keep requirement identifiers visible in the evidence register so the assessor can trace from the finding back to the CP/CPS, repository, log, certificate record, or change decision.

  • Closeout field: service boundary, policy identifier, CP/CPS version, repository evidence, trusted-list evidence, and assessment period.
  • Closeout field: trigger type, source clause or requirement identifier, evidence artifact, owner, review result, and unresolved gap.
  • Closeout field: required external action, such as supervisory-body liaison review, conformity-assessment follow-up, subscriber notice, relying-party notice, or CP/CPS publication update.
  • Stop condition: the pack cannot show the qualified profile, trusted-list basis, QSCD basis where claimed, status-service basis, or owner for a material open gap.
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Binding current source for one-month advance notice of changes, three-month advance notice of cessation, and supervisory review of intended changes.
"at least three months in case of an intention to cease those activities"
etsi.org
Referenced sections
  • Supports inherited certificate-service evidence for CP/CPS, subscribers, repositories, revocation, records, and assessment preparation.
"Policy and security requirements for Trust Service Providers issuing certificates"
etsi.org
Referenced sections
  • Supports the incident, retention, certificate database, revocation, status-service, termination, and Annex A limitation checks used in this workflow.
"should not be taken as definitive statement of conformance"
eur-lex.europa.eu
Referenced sections
  • Consolidated legal framework for the current incident recipients and deadline, advance notice of cessation, record accessibility, and termination planning.
"within 24 hours of the incident"
Related guides

Explore more topics

eIDAS QTSP supervision workflow for ETSI EN 319 411-2
Operational workflow for qualified trust service providers using ETSI EN 319 411-2 to manage supervisory-body changes, incidents, termination evidence, trusted-list checks, and assessment records.
ETSI EN 319 411-2 certificate operations
Operational guide for ETSI EN 319 411-2 qualified certificate services: policy identifiers, identity validation, issuance, QSCD handling, revocation status, and relying-party notices.
ETSI EN 319 411-2 compliance checklist
Compliance checklist for ETSI EN 319 411-2 qualified certificate services, covering policy selection, CP/CPS evidence, identity validation, QSCD status, trusted-list reliance, and certificate status services.
ETSI EN 319 411-2 FAQ for EU Qualified Certificates
Answers to common ETSI EN 319 411-2 questions about EU qualified certificate policies, QSCD use, identity validation, trusted lists, and revocation status services.
ETSI EN 319 411-2 Identity Proofing
How EN 319 411-2 applies identity validation for EU qualified certificates, including QCP natural-person, legal-person, website, and evidence-record checks.
ETSI EN 319 411-2 profile selector
Select the right ETSI EN 319 411-2 qualified certificate policy profile for signatures, seals, QSCD use, and website authentication.
ETSI EN 319 411-2 QSCD Route
When QCP-n-qscd or QCP-l-qscd is the right EN 319 411-2 route, what QSCD evidence is needed, and which certificate-profile claims must stay aligned.
ETSI EN 319 411-2 Qualified Certificate Scope
Use ETSI EN 319 411-2 to scope EU qualified certificate services by certificate policy, subject type, QSCD use, website authentication profile, and eIDAS context.
ETSI EN 319 411-2 requirements map
Map ETSI EN 319 411-2 requirements for EU qualified certificate services across QCP profiles, CP/CPS documentation, QSCD use, certificate profiles, revocation, and eIDAS Annex A references.
ETSI EN 319 411-2 trusted-list evidence
Build EN 319 411-2 trusted-list evidence for EU qualified certificate reliance: relying-party notice text, QTSP service identifiers, validation records, and change triggers.
ETSI EN 319 411-2 trusted-list validation workflow
Validate an EN 319 411-2 EU qualified-certificate claim by mapping the certificate service to the QTSP trusted-list entry, policy profile, relying-party notice, and status evidence.
ETSI EN 319 411-2 vs eIDAS Qualified Trust Services
Compare ETSI EN 319 411-2 certificate policy requirements with the eIDAS qualified-status, supervision, audit, and trusted-list framework.
ETSI EN 319 411-2 vs EN 319 411-1
Compare ETSI EN 319 411-2 EU qualified certificate requirements with EN 319 411-1 general certificate-service requirements, including policy inheritance, QSCD controls, and CP/CPS evidence reuse.
ETSI EN 319 411-2: Certificate Revocation FAQ
Answer the ETSI EN 319 411-2 revocation question for qualified certificate services: CPS procedures, 24-hour publication, CRL or OCSP status, and evidence to retain.
ETSI EN 319 411-2: end-to-end qualified certificate lifecycle management workflow
Lifecycle workflow for ETSI EN 319 411-2 qualified certificate services, from policy selection and identity validation through issuance, renewal, re-key, modification, revocation, status services, and records.
ETSI EN 319 411-2: Legal vs Natural Person Certs
ETSI EN 319 411-2 separates qualified certificate policies for natural persons, legal persons, QSCD use, and website authentication subscribers.
ETSI EN 319 411-2: QCP, QNCP, and QEVCP Profile Selection
Choose the right ETSI EN 319 411-2 qualified certificate policy profile: QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.
How should QTSPs select an ETSI EN 319 411-2 qualified certificate profile?
A focused FAQ on choosing QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen under ETSI EN 319 411-2.
How should relying parties use trusted lists under ETSI EN 319 411-2?
FAQ on EN 319 411-2 trusted-list reliance for EU qualified certificates: relying-party notices, QTSP service identifiers, validation evidence, and source references.
QSCD Requirements in ETSI EN 319 411-2
How ETSI EN 319 411-2 treats QSCD-backed qualified certificates, including QCP-n-qscd and QCP-l-qscd policies, key-use controls, QSCD verification, and certificate profile evidence.
QTSP Supervision and ETSI EN 319 411-2
How ETSI EN 319 411-2 supports QTSP supervision evidence for qualified certificate services, trusted-list reliance, liability responsibility, incident records, and audit preparation.
Qualified certificates under ETSI EN 319 411-2
FAQ answer for QTSPs on how ETSI EN 319 411-2 treats EU qualified certificates, policy identifiers, QSCD variants, website certificates, and lifecycle evidence.
What are the qualified certificate policies in ETSI EN 319 411-2?
FAQ on ETSI EN 319 411-2 qualified certificate policies, including QCP-n, QCP-l, QSCD variants, QEVCP-w, QNCP-w, and policy identifiers.
Which QWAC Profile Fits ETSI EN 319 411-2?
Choose between QEVCP-w, QNCP-w, and QNCP-w-gen for qualified website authentication certificates under ETSI EN 319 411-2.