Artifact GuideGLOBALETSI EN 319 411-2

ETSI EN 319 411-2 Qualified Certificate Scope

A scope guide for deciding which EU qualified certificate policy profile applies before drafting CP/CPS text or issuing certificates.

Use the standard with its current EU adaptations and the trusted-list entry for the specific service; the standard alone does not establish qualified status.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Define each service by certificate purpose, subject type, policy profile, route, and qualified-status evidence before drafting the CP or CPS. EN 319 411-2 V2.6.1 supplies seven policy profiles, but current implementation also requires the applicable eIDAS text and EU implementing regulations. A provider and service are qualified only when that service appears as qualified in the relevant .

Section 1

What EN 319 411-2 adds to the scope

ETSI EN 319 411-2 is not a general PKI checklist. It addresses issuance, maintenance, and lifecycle management of EU qualified certificates. It imports general policy and security requirements from ETSI EN 319 411-1 and adds requirements for qualified signature, seal, and website authentication certificate policies.

The scope record should name the issuing trust service provider (TSP), the certification service components, the certificate population, the claimed policy identifier, and the relying-party use. Keep three layers separate: conformance to the standard, compliance with the binding eIDAS framework and applicable implementing regulations, and the qualified status of the particular service shown in the .

  • Name the issuing TSP and the certificate service components covered by the .
  • State whether the certificate is intended to support an electronic signature, electronic seal, or website-authentication use case, and whether the selected route is intended to support a qualified signature or seal.
  • Link the EN 319 411-2 scope to the corresponding EN 319 411-1 baseline requirements instead of treating Part 2 as a standalone control set.
  • Record the qualified status evidence separately from the standards-conformance evidence.
Section 2

Choose the qualified policy profile

Select one EN 319 411-2 policy before mapping requirements. The choice determines the subject, intended certificate use, inherited EN 319 411-1 policy family, conditions, and any CA/Browser Forum dependency.

For signature and seal certificates, Regulation (EU) 2025/1943 references EN 319 411-2 V2.6.1 with binding adaptations, including changes to identity validation, remote management, cryptographic controls, and certificate issuance. For qualified website authentication certificates issued for transport layer security authentication outside a web-browser, Regulation (EU) 2025/2527 lists QEVCP-w, QNCP-w, and QNCP-w-gen as reference routes and applies from 6 January 2027; until then, teams must keep that future application date distinct from the standard's publication.

  • Use QCP-n for EU qualified certificates issued to natural persons.
  • Use QCP-l for EU qualified certificates issued to legal persons.
  • Use QCP-n- or QCP-l-qscd only when the private key related to the certified public key resides in a QSCD.
  • Use QEVCP-w for qualified website authentication certificates based on the EVCP profile.
  • Use QNCP-w for qualified website authentication certificates based on NCP plus OVCP or IVCP; use QNCP-w-gen for the NCP plus web-tagged requirement route.
Section 3

Scope questions to answer before issuance

Answer each question that changes the requirement set before issuance. The CP, CPS, terms and conditions, subscriber obligations, certificate profile, and relying-party notice should give consistent answers.

Keep a profile matrix with the subject type, policy identifier, inherited Part 1 family, applicable EU adaptation, dependency, certificate purpose, website-authentication route, trusted-list service identifier, and owner for each evidence record.

  • Is the subject a natural person, a legal person, or a website-authentication subscriber whose identity and domain link must be verified?
  • Do the terms and conditions require a secure cryptographic device, causing the NCP+ route to apply for QCP-n or QCP-l?
  • For a profile, who manages the device and how is the device certification, key generation route, and QSCD status monitored?
  • If the TSP manages a remote for the subject, does it hold the qualified status required for that remote QSCD management service under the adapted requirements in Regulation (EU) 2025/1943?
  • For QEVCP-w or QNCP-w, which BRG or EVCG dependency applies, and how will conflicts with the ETSI profile be handled?
  • What notice tells relying parties that the trust anchor must be identified through an appropriate EU trusted-list entry for a ?
Section 4

Evidence that makes the scope reviewable

The scope decision should be reviewable without asking the reader to infer why a profile was chosen. Keep evidence at the level of the actual service: the clause, the certificate policy identifier, the terms and conditions, the subscriber or subject identity record, the evidence where applicable, the certificate profile, and the relying-party notice.

For profiles, the evidence must show more than an internal design preference. EN 319 411-2 includes requirements for verifying QSCD certification, ensuring the public key to be certified is from a QSCD-generated key pair, handling QSCD status changes, and including or excluding the QSCD qcStatement according to the selected policy.

  • Profile matrix: policy identifier, subject type, inherited EN 319 411-1 policy family, applicable EN 319 411-2 additions, and binding EU adaptations.
  • extract: the clauses that identify the certificate policy, certificate usage, PKI participants, and service responsibilities.
  • Identity and domain evidence: records showing the verified subject and, for website authentication, the subject's link to the domain name.
  • evidence: device certification, management responsibility, key-pair generation route, status monitoring, and qcStatement handling.
  • Qualified-status record: the national trusted-list service entry, service digital identifier, current service status, certificate population covered, and date checked.
  • Relying-party notice: the statement connecting qualified-certificate reliance to the appropriate EU trusted-list service entry.
Section 5

Scope mistakes that create audit rework

Profile mixing and generic qualified-status claims create avoidable review failures. Resolve profile-specific assumptions before the CP, CPS, certificate profile, and service evidence diverge.

A scope file should establish why the selected policy route fits the service and identify the next evidence set. It cannot by itself prove eIDAS compliance or qualified status.

  • Do not label a service as qualified only because it maps to EN 319 411-2; keep supervisory and trusted-list evidence explicit.
  • Do not use a policy identifier unless the private key and certificate route meet the QSCD-specific requirements.
  • Do not mix QEVCP-w, QNCP-w, and QNCP-w-gen evidence because their inherited baseline requirements differ.
  • Do not omit the EN 319 411-1 baseline; EN 319 411-2 builds on it instead of replacing it.
  • Do not apply the unadapted standard where a binding implementing regulation changes or supplements the cited requirement.
  • Do not let the relying-party notice skip the EU trusted-list dependency for qualified-certificate reliance.
Primary sources

References and citations

digital-strategy.ec.europa.eu
Referenced sections
  • Explains the constitutive effect of national trusted lists: the provider and specific service are qualified only when listed as qualified.
eur-lex.europa.eu
Referenced sections
  • Provides the eIDAS context for qualified certificates for signatures, seals, website authentication, and qualified trust service providers.
"qualified trust service"
eur-lex.europa.eu
Referenced sections
  • Supports the distinction between standards scoping and the eIDAS legal framework for qualified certificates and qualified trust services.
"electronic identification"
Related guides

Explore more topics

eIDAS QTSP supervision workflow for ETSI EN 319 411-2
Operational workflow for qualified trust service providers using ETSI EN 319 411-2 to manage supervisory-body changes, incidents, termination evidence, trusted-list checks, and assessment records.
ETSI EN 319 411-2 certificate operations
Operational guide for ETSI EN 319 411-2 qualified certificate services: policy identifiers, identity validation, issuance, QSCD handling, revocation status, and relying-party notices.
ETSI EN 319 411-2 compliance checklist
Compliance checklist for ETSI EN 319 411-2 qualified certificate services, covering policy selection, CP/CPS evidence, identity validation, QSCD status, trusted-list reliance, and certificate status services.
ETSI EN 319 411-2 FAQ for EU Qualified Certificates
Answers to common ETSI EN 319 411-2 questions about EU qualified certificate policies, QSCD use, identity validation, trusted lists, and revocation status services.
ETSI EN 319 411-2 Identity Proofing
How EN 319 411-2 applies identity validation for EU qualified certificates, including QCP natural-person, legal-person, website, and evidence-record checks.
ETSI EN 319 411-2 profile selector
Select the right ETSI EN 319 411-2 qualified certificate policy profile for signatures, seals, QSCD use, and website authentication.
ETSI EN 319 411-2 QSCD Route
When QCP-n-qscd or QCP-l-qscd is the right EN 319 411-2 route, what QSCD evidence is needed, and which certificate-profile claims must stay aligned.
ETSI EN 319 411-2 QTSP supervision evidence workflow
Build an assessment-ready QTSP supervision evidence pack for ETSI EN 319 411-2 qualified certificate services, covering policy identifiers, trusted-list checks, incident records, QSCD evidence, and termination controls.
ETSI EN 319 411-2 requirements map
Map ETSI EN 319 411-2 requirements for EU qualified certificate services across QCP profiles, CP/CPS documentation, QSCD use, certificate profiles, revocation, and eIDAS Annex A references.
ETSI EN 319 411-2 trusted-list evidence
Build EN 319 411-2 trusted-list evidence for EU qualified certificate reliance: relying-party notice text, QTSP service identifiers, validation records, and change triggers.
ETSI EN 319 411-2 trusted-list validation workflow
Validate an EN 319 411-2 EU qualified-certificate claim by mapping the certificate service to the QTSP trusted-list entry, policy profile, relying-party notice, and status evidence.
ETSI EN 319 411-2 vs eIDAS Qualified Trust Services
Compare ETSI EN 319 411-2 certificate policy requirements with the eIDAS qualified-status, supervision, audit, and trusted-list framework.
ETSI EN 319 411-2 vs EN 319 411-1
Compare ETSI EN 319 411-2 EU qualified certificate requirements with EN 319 411-1 general certificate-service requirements, including policy inheritance, QSCD controls, and CP/CPS evidence reuse.
ETSI EN 319 411-2: Certificate Revocation FAQ
Answer the ETSI EN 319 411-2 revocation question for qualified certificate services: CPS procedures, 24-hour publication, CRL or OCSP status, and evidence to retain.
ETSI EN 319 411-2: end-to-end qualified certificate lifecycle management workflow
Lifecycle workflow for ETSI EN 319 411-2 qualified certificate services, from policy selection and identity validation through issuance, renewal, re-key, modification, revocation, status services, and records.
ETSI EN 319 411-2: Legal vs Natural Person Certs
ETSI EN 319 411-2 separates qualified certificate policies for natural persons, legal persons, QSCD use, and website authentication subscribers.
ETSI EN 319 411-2: QCP, QNCP, and QEVCP Profile Selection
Choose the right ETSI EN 319 411-2 qualified certificate policy profile: QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.
How should QTSPs select an ETSI EN 319 411-2 qualified certificate profile?
A focused FAQ on choosing QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen under ETSI EN 319 411-2.
How should relying parties use trusted lists under ETSI EN 319 411-2?
FAQ on EN 319 411-2 trusted-list reliance for EU qualified certificates: relying-party notices, QTSP service identifiers, validation evidence, and source references.
QSCD Requirements in ETSI EN 319 411-2
How ETSI EN 319 411-2 treats QSCD-backed qualified certificates, including QCP-n-qscd and QCP-l-qscd policies, key-use controls, QSCD verification, and certificate profile evidence.
QTSP Supervision and ETSI EN 319 411-2
How ETSI EN 319 411-2 supports QTSP supervision evidence for qualified certificate services, trusted-list reliance, liability responsibility, incident records, and audit preparation.
Qualified certificates under ETSI EN 319 411-2
FAQ answer for QTSPs on how ETSI EN 319 411-2 treats EU qualified certificates, policy identifiers, QSCD variants, website certificates, and lifecycle evidence.
What are the qualified certificate policies in ETSI EN 319 411-2?
FAQ on ETSI EN 319 411-2 qualified certificate policies, including QCP-n, QCP-l, QSCD variants, QEVCP-w, QNCP-w, and policy identifiers.
Which QWAC Profile Fits ETSI EN 319 411-2?
Choose between QEVCP-w, QNCP-w, and QNCP-w-gen for qualified website authentication certificates under ETSI EN 319 411-2.