Artifact GuideGLOBALETSI EN 319 411-2

ETSI EN 319 411-2 Qualified Profile Selector

Choose the EN 319 411-2 policy profile that matches the certificate subject, intended use, QSCD claim, and website-authentication route.

Use this as standards implementation guidance for certificate-policy scoping and evidence planning, not for legal interpretation.

Author
Sorena AI
Published
May 9, 2026
Updated
May 9, 2026
Sections
6

Structured answer sets in this page tree.

Primary sources
10

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated May 9, 2026
Overview

ETSI EN 319 411-2 defines EU qualified certificate policy profiles for trust service providers issuing qualified certificates. This workflow helps certificate-policy owners decide which profile to use before they draft the CP/CPS, encode policy identifiers, claim QSCD support, or prepare assessor evidence.

Section 1

Start with the certificate purpose

The first selection question is not whether the service is generally secure. It is what the qualified certificate is meant to support: a natural person's electronic signature, a legal person's electronic seal, or website authentication.

EN 319 411-2 builds these qualified profiles on EN 319 411-1 policy families such as NCP, NCP+, EVCP, OVCP, IVCP, and web-authentication requirements, then adds eIDAS-qualified certificate requirements. That means the chosen profile determines both the base controls and the qualified-certificate additions.

  • Use QCP-n when the qualified certificate is issued to a natural person for electronic-signature use without a QSCD-specific policy claim.
  • Use QCP-l when the qualified certificate is issued to a legal person for electronic-seal use without a QSCD-specific policy claim.
  • Use QEVCP-w, QNCP-w, or QNCP-w-gen only for qualified website-authentication certificates, not for ordinary signature or seal certificates.
  • Document the reason for excluding other profiles so the CP/CPS reviewer can see that the profile was selected deliberately.
Section 2

Select QCP-n, QCP-l, or a QSCD variant

For signature and seal certificates, the selector turns on two facts: the subject type and whether the policy requires the private key related to the certified public key to reside in a Qualified Signature Creation Device or Qualified Seal Creation Device.

The non-QSCD profiles still need an explicit policy decision. EN 319 411-2 says QCP-n and QCP-l include NCP requirements and qualified-certificate additions; if the terms and conditions require a secure cryptographic device, NCP+ requirements apply. The QSCD profiles go further and require the QSCD-specific policy path.

  • Natural person, signature use, no QSCD policy claim: select QCP-n and map the applicable NCP or NCP+ base requirements.
  • Legal person, seal use, no QSCD policy claim: select QCP-l and map the applicable NCP or NCP+ base requirements.
  • Natural person with the private key in a QSCD: select QCP-n-qscd and collect QSCD certification, key-generation, and certificate-profile evidence.
  • Legal person with the private key in a QSCD: select QCP-l-qscd and collect the same QSCD evidence for the seal-creation route.
Section 3

Select the website-authentication profile

Website-authentication certificates follow a separate branch. EN 319 411-2 defines three qualified website-authentication policy profiles, and the correct route depends on whether the certificate is based on EVCP, on NCP plus OVCP or IVCP, or on the general-purpose QNCP-w-gen route.

This branch should be decided before certificate templates and public disclosures are finalized because QEVCP-w and QNCP-w also depend on external CA/Browser Forum requirement families. EN 319 411-2 states that, for QEVCP-w and QNCP-w, the latest EVCG or BRG requirements take precedence if they conflict with EN 319 411-2 requirements.

  • Use QEVCP-w for an EU qualified website-authentication certificate based on EVCP for a legal person.
  • Use QNCP-w for an EU qualified website-authentication certificate based on NCP plus OVCP or IVCP.
  • Use QNCP-w-gen for a general-purpose qualified website-authentication certificate based on NCP and EN 319 411-1 WEB-tagged requirements.
  • Record whether BRG or EVCG requirements add or override implementation details for the selected website-authentication profile.
Section 4

Translate the selected profile into certificate evidence

After the profile is selected, the evidence pack should prove that the certificate and the CP/CPS follow the selected EN 319 411-2 route. The profile decision should appear in the certificate policy name and identification, the certificate's policy identifier strategy, the CP/CPS control mapping, and the disclosure statement.

EN 319 411-2 requires qualified certificates to include at least one applicable policy identifier choice, and it restricts the QSCD qcStatement to the QSCD profiles. If the certificate uses only a TSP-allocated OID, the referenced certificate policy must clearly identify which EN 319 411-2 policy it adopts as the basis.

  • Store the selected profile, rejected alternatives, subject type, intended certificate use, and QSCD decision in the CP/CPS working papers.
  • Check that certificate policy identifiers match the selected profile and that any TSP-allocated OID clearly maps back to that EN 319 411-2 basis.
  • For QCP-n-qscd and QCP-l-qscd, verify QSCD certification evidence, key-pair generation route, QSCD status monitoring, and the required QSCD qcStatement.
  • For non-QSCD certificates, verify that the QSCD qcStatement is not included.
Section 5

Profile selector worksheet

Use this worksheet as a pre-audit handoff. It is written as operational rows so it can be copied into a CP/CPS review ticket without losing the selection logic.

Step 1: Identify the certificate use. Choose signature, seal, or website authentication; name the subject type as natural person, legal person, or website-authentication subject.

Step 2: Decide the device claim. For signature or seal certificates, record whether the policy requires a QSCD and whether the TSP or another qualified TSP manages relevant key material.

Step 3: Select the profile. Map the facts to QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.

Step 4: Bind identifiers and disclosures. Confirm policy identifiers, TSP-allocated OIDs, CP/CPS statements, terms and conditions, and the PKI disclosure statement are consistent with the selected profile.

Step 5: Run a negative check. Confirm no website-authentication profile is being used for a signature or seal certificate, no QSCD qcStatement appears outside a QSCD profile, and no qualified claim relies only on EN 319 411-1.

  • Evidence owner: certificate-policy owner or QTSP compliance owner.
  • Engineering input: certificate template, policy OID configuration, qcStatements, CRL or OCSP profile assumptions, and key-management route.
  • Legal or compliance input: eIDAS qualified-service claim, terms and conditions, supervisory or trusted-list evidence, and customer-facing limitations.
  • Assessor input: mapping from selected profile to clauses 5 and 6 of EN 319 411-2 and incorporated EN 319 411-1 requirements.
Section 6

Mistakes that break the profile decision

Most profile-selector failures are traceability failures. The certificate may look technically valid while the CP/CPS, policy OID, qcStatement, or website-authentication route points to a different EN 319 411-2 policy than the one the team intended.

Treat the profile decision as a release gate for qualified certificate services. A profile mismatch can affect assessor evidence, relying-party interpretation, trusted-list validation, and the legal framing of a qualified-certificate claim.

  • Do not claim QCP-n-qscd or QCP-l-qscd unless the QSCD certification, key-generation route, and QSCD qcStatement evidence are present.
  • Do not include the QSCD qcStatement in certificates that are not issued under QCP-n-qscd or QCP-l-qscd.
  • Do not use QEVCP-w, QNCP-w, or QNCP-w-gen unless the service is actually issuing qualified website-authentication certificates.
  • Do not treat EN 319 411-2 conformance by itself as proof that the TSP or certificate is qualified under eIDAS; qualification also depends on the legal and supervisory context.
  • Do not let a TSP-allocated policy OID hide the EN 319 411-2 basis; the referenced certificate policy must identify the profile it adopts.
Primary sources

References and citations

etsi.org
Referenced sections
  • Supports the QCP-n, QCP-l, QCP-n-qscd, and QCP-l-qscd selection rules and the QSCD evidence requirements in key-pair generation and certificate profiles.
"the private key related to the certified public key resides in the QSCD"
etsi.org
Referenced sections
  • Supports the worksheet sequence by tying profile selection to certificate purpose, QSCD status, policy identifiers, CP/CPS statements, and incorporated requirements.
"Certificate Policy name and identification"
eur-lex.europa.eu
Referenced sections
  • Supports the warning that qualified status is part of the wider eIDAS trust-service framework, not only a standards-document label.
"qualified trust services"
Related guides

Explore more topics

eIDAS QTSP supervision workflow for ETSI EN 319 411-2
Operational workflow for qualified trust service providers using ETSI EN 319 411-2 to manage supervisory-body changes, incidents, termination evidence, trusted-list checks, and assessment records.
EN 319 411-2 vs EN 319 411-1 Qualified Certs
Compare ETSI EN 319 411-2 qualified certificate requirements with EN 319 411-1 general certificate-service requirements, including QCP profiles, QSCD evidence, CP/CPS reuse, and audit boundaries.
ETSI EN 319 411-2 compliance checklist
Compliance checklist for ETSI EN 319 411-2 qualified certificate services, covering policy selection, CP/CPS evidence, identity validation, QSCD status, trusted-list reliance, and certificate status services.
ETSI EN 319 411-2 FAQ for EU Qualified Certificates
Answers to common ETSI EN 319 411-2 questions about EU qualified certificate policies, QSCD use, identity validation, trusted lists, and revocation status services.
ETSI EN 319 411-2 Identity Proofing
How EN 319 411-2 applies identity validation for EU qualified certificates, including QCP natural-person, legal-person, website, and evidence-record checks.
ETSI EN 319 411-2 QSCD Route
When QCP-n-qscd or QCP-l-qscd is the right EN 319 411-2 route, what QSCD evidence is needed, and which certificate-profile claims must stay aligned.
ETSI EN 319 411-2 QTSP supervision evidence workflow
Build an assessment-ready QTSP supervision evidence pack for ETSI EN 319 411-2 qualified certificate services, covering policy identifiers, trusted-list checks, incident records, QSCD evidence, and termination controls.
ETSI EN 319 411-2 qualified certificate operations: issuance, suspension, and revocation
Operational guide for ETSI EN 319 411-2 qualified certificate services: policy identifiers, identity validation, issuance, QSCD handling, revocation status, and relying-party notices.
ETSI EN 319 411-2 Qualified Certificate Scope
Use ETSI EN 319 411-2 to scope EU qualified certificate services by certificate policy, subject type, QSCD use, website authentication profile, and eIDAS context.
ETSI EN 319 411-2 requirements map
Map ETSI EN 319 411-2 requirements for EU qualified certificate services across QCP profiles, CP/CPS documentation, QSCD use, certificate profiles, revocation, and eIDAS Annex A references.
ETSI EN 319 411-2 trusted-list evidence
Build EN 319 411-2 trusted-list evidence for EU qualified certificate reliance: relying-party notice text, QTSP service identifiers, validation records, and change triggers.
ETSI EN 319 411-2 trusted-list validation workflow
Validate an EN 319 411-2 EU qualified-certificate claim by mapping the certificate service to the QTSP trusted-list entry, policy profile, relying-party notice, and status evidence.
ETSI EN 319 411-2 vs eIDAS Qualified Trust Services
Compare ETSI EN 319 411-2 certificate policy requirements with the eIDAS qualified-status, supervision, audit, and trusted-list framework.
ETSI EN 319 411-2: Certificate Revocation FAQ
Answer the ETSI EN 319 411-2 revocation question for qualified certificate services: CPS procedures, 24-hour publication, CRL or OCSP status, and evidence to retain.
ETSI EN 319 411-2: end-to-end qualified certificate lifecycle management workflow
Lifecycle workflow for ETSI EN 319 411-2 qualified certificate services, from policy selection and identity validation through issuance, renewal, re-key, modification, revocation, status services, and records.
ETSI EN 319 411-2: Legal vs Natural Person Certs
ETSI EN 319 411-2 separates qualified certificate policies for natural persons, legal persons, QSCD use, and website authentication subscribers.
ETSI EN 319 411-2: QCP, QNCP, and QEVCP Profile Selection
Choose the right ETSI EN 319 411-2 qualified certificate policy profile: QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.
How should QTSPs select an ETSI EN 319 411-2 qualified certificate profile?
A focused FAQ on choosing QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen under ETSI EN 319 411-2.
How should relying parties use trusted lists under ETSI EN 319 411-2?
FAQ on EN 319 411-2 trusted-list reliance for EU qualified certificates: relying-party notices, QTSP service identifiers, validation evidence, and source references.
QSCD Requirements in ETSI EN 319 411-2
How ETSI EN 319 411-2 treats QSCD-backed qualified certificates, including QCP-n-qscd and QCP-l-qscd policies, key-use controls, QSCD verification, and certificate profile evidence.
QTSP Supervision and ETSI EN 319 411-2
How ETSI EN 319 411-2 supports QTSP supervision evidence for qualified certificate services, trusted-list reliance, liability responsibility, incident records, and audit preparation.
Qualified certificates under ETSI EN 319 411-2
FAQ answer for QTSPs on how ETSI EN 319 411-2 treats EU qualified certificates, policy identifiers, QSCD variants, website certificates, and lifecycle evidence.
What are the qualified certificate policies in ETSI EN 319 411-2?
FAQ on ETSI EN 319 411-2 qualified certificate policies, including QCP-n, QCP-l, QSCD variants, QEVCP-w, QNCP-w, and policy identifiers.
Which QWAC Profile Fits ETSI EN 319 411-2?
Choose between QEVCP-w, QNCP-w, and QNCP-w-gen for qualified website authentication certificates under ETSI EN 319 411-2.