- Adds the qualified remote-QSCD management condition and adapted cryptographic obligations.
References and citations
- Binding significant-change notification content, risk management, service-specific termination planning, two-year review, and continuity requirements.
- Sets the one-month service-change and three-month intended-cessation notification periods.
- Defines certificate renewal, re-key, and modification and supplies their general processing requirements.
- Supports the distinction between Certificate Policy, Certification Practice Statement, subscriber terms, and disclosure material used in certificate operations.
"Certification Practice Statement"
- Provides the general certificate policy, CPS, repository, CA, RA, subscriber, revocation, and certificate life-cycle requirements incorporated by EN 319 411-2.
"Part 1: General requirements"
- Supports the inherited revocation management, certificate status service, repository, and relying-party status-checking controls referenced by EN 319 411-2.
"Certificate revocation and suspension"
- Supports the operational checks for policy identifiers, TSP-allocated OIDs, subscriber agreement handling, qcStatements, and QSCD qcStatement restrictions.
"certificate policy identifier"
- Supports the operational requirements for revocation status beyond certificate validity, CRL and OCSP evidence, CPS status-service disclosure, and relying-party trusted-list notices.
"Revocation status information shall be made available"
- Grounds the natural-person, legal-person, authorized-representative, equivalent-assurance, and domain-link validation requirements for qualified certificate operations.
"Initial Identity Validation"
- Supports QSCD certification, QSCD-generated key-pair checks, private-key use restrictions, subject control, and CPS measures for QSCD status changes.
"certified as a QSCD"
- Imports the Part 1 lifecycle requirements and sets QEVCP-w substitutions for evidence reuse and maximum validity.
- Supports the operating scope for EU qualified certificate issuance, maintenance, life-cycle management, policy identifiers, and the warning that standard conformance alone is not qualified status.
"issuance, maintenance and life-cycle management"
- Explains that qualified status attaches to the provider's specific listed service, not every service the provider operates.
- Current Article 24 identity and attribute routes and qualified trust service provider duties.
"qualified trust service"