- Binding future reference-standard source for qualified-certificate identity and attribute verification; it applies from 19 August 2027.
References and citations
- Binding source that references EN 319 411-2 V2.6.1 with adaptations for the presumption-of-compliance route for qualified signature and seal certificates.
- Provides the inherited audit logging, records archival, CA or RA termination, and lifecycle records controls referenced by EN 319 411-2.
"Records Archival"
- Supports the lifecycle gate requiring registration, current attribute checks, authorized applications, and a secure link between registration and certificate issuance.
"Certificate application"
- Referenced base standard for certificate application, issuance, renewal, re-key, modification, revocation, certificate status services, audit logging, and records archival controls incorporated by EN 319 411-2.
"Certificate Life-Cycle"
- Provides the inherited certificate-policy and lifecycle requirements that EN 319 411-2 builds on for NCP, NCP+, EVCP, OVCP, IVCP, and WEB-tagged controls.
"certificate policy"
- Supports the distinction between renewal, re-key, and modification and the application-processing controls inherited by EN 319 411-2.
"Certificate modification"
- Supports the CPS revocation procedure, authenticated requests, 24-hour maximum status update delay, UTC synchronization, non-reinstatement, and CRL or OCSP status-service controls.
"revocation status"
- Supports issuance checks for policy identifiers, QSCD-specific qcStatement handling, terms-and-conditions statements, and the relying-party notice tying the validation trust anchor to an appropriate EU trusted-list entry.
"qcStatements"
- Supports the separate identity-validation routes for natural persons, legal persons, and website-authentication subscribers under qualified certificate policies.
"Initial Identity Validation"
- Supports the policy-profile gate by listing the EU qualified certificate policy identifiers and their natural-person, legal-person, QSCD, and website-authentication routes.
"policy identifiers"
- Primary source for EN 319 411-2 policy profiles, qualified certificate lifecycle scope, identity validation additions, QSCD controls, certificate profiles, status beyond expiry, records, disclosure, and conformance caveats.
"life-cycle management"
- Supports the qualified-certificate requirement to keep revocation status information available beyond certificate validity and to document the method in practices statements and terms.
"beyond the validity period"
- Supports the record-retention, PKI disclosure, terms-and-conditions, and conformance-boundary guidance for EU qualified certificate services.
"does not imply"
- Supports the EN 319 411-2 gates for renewal, re-key, modification, QEVCP-w reuse limits, QSCD verification, QSCD-generated public keys, and QSCD status changes.
"Certificate Re-key"
- Supports the qualified trust-service context for identity verification, records, revocation, certificate databases, and status information mapped in EN 319 411-2 Annex A.
"qualified certificates"