ETSI EN 319 411-2 defines seven EU qualified certificate policies for trust service providers issuing EU qualified certificates. This workflow helps certificate-policy owners select the before they draft the CP/CPS, encode policy identifiers, claim support, or prepare assessor evidence.
1
Section 1
Start with the certificate purpose
Start by identifying what the qualified certificate is meant to support: a natural person's electronic signature, a legal person's electronic seal, or website authentication.
EN 319 411-2 builds these qualified profiles on EN 319 411-1 policy families such as NCP, NCP+, EVCP, OVCP, IVCP, and web-authentication requirements, then adds eIDAS-qualified certificate requirements. That means the chosen profile determines both the base controls and the qualified-certificate additions.
Use QCP-n for a qualified certificate issued to a natural person. It is aimed at advanced electronic signatures based on a qualified certificate; select when the policy also claims the qualified-signature route.
Use QCP-l for a qualified certificate issued to a legal person. It is aimed at advanced electronic seals based on a qualified certificate; select QCP-l- when the policy also claims the qualified-seal QSCD route.
Use , QNCP-w, or QNCP-w-gen only for qualified website-authentication certificates, not for ordinary signature or seal certificates.
Document the reason for excluding other profiles so the CP/CPS reviewer can see that the profile was selected deliberately.
For signature and seal certificates, the selection depends on two facts: the subject type and whether the policy requires the private key related to the certified public key to reside in a Qualified Signature Creation Device or Qualified Seal Creation Device. Commission Implementing Regulation (EU) 2025/1943 references EN 319 411-2 V2.6.1 with adaptations for the EU presumption-of-compliance route for qualified signature and seal certificates. Apply those adaptations with the standard, including changes affecting policy applicability, identity validation, certificate issuance, algorithms, status services, personnel, and termination.
The non- profiles still need an explicit policy decision. EN 319 411-2 says QCP-n and QCP-l include NCP requirements and qualified-certificate additions; if the terms and conditions require a secure cryptographic device, NCP+ requirements apply. The QSCD profiles go further and require the QSCD-specific policy path.
Natural person, signature use, no policy claim: select QCP-n and map the applicable NCP or NCP+ base requirements.
Legal person, seal use, no policy claim: select QCP-l and map the applicable NCP or NCP+ base requirements.
Natural person with the private key in a : select and collect QSCD certification, key-generation, and certificate-profile evidence.
Legal person with the private key in a : select QCP-l-qscd and collect the same QSCD evidence for the seal-creation route.
If the issuing TSP manages a remote for the subject, verify that it provides the corresponding qualified remote signature- or seal-device management service required by Regulation (EU) 2025/1943.
Website-authentication certificates follow a separate branch. EN 319 411-2 V2.6.1 defines three qualified website-authentication policy profiles: based on EVCP, QNCP-w based on NCP plus OVCP or IVCP, and QNCP-w-gen based on NCP plus WEB-tagged Part 1 requirements. Older editions used QCP-w for the route now named QEVCP-w; do not copy that historical abbreviation into a new V2.6.1 selection record. From 6 January 2027, Commission Implementing Regulation (EU) 2025/2527 uses EN 319 411-2 V2.6.1 or ETSI TS 119 495 for transport-layer-security authentication outside a web-browser, but points other QWACs, including browser-context certificates, to ETSI TS 119 411-5. Record the relying-party context and applicable date before selecting the legal reference-standard route.
This branch should be decided before certificate templates and public disclosures are finalized because and QNCP-w also depend on external CA/Browser Forum requirement families. EN 319 411-2 states that, for QEVCP-w and QNCP-w, the latest EVCG or BRG requirements take precedence if they conflict with EN 319 411-2 requirements.
Use for an EU qualified website-authentication certificate based on EVCP for a legal person.
Use QNCP-w for an EU qualified website-authentication certificate based on NCP plus OVCP or IVCP.
Use QNCP-w-gen for a general-purpose qualified website-authentication certificate based on NCP and EN 319 411-1 WEB-tagged requirements.
Record whether BRG or EVCG requirements add or override implementation details for QNCP-w or ; the stated conflict-precedence rule does not name QNCP-w-gen.
Translate the selected profile into certificate evidence
After the profile is selected, the evidence pack should prove that the certificate and the CP/CPS follow the selected EN 319 411-2 route. The profile decision should appear in the certificate policy name and identification, the certificate's policy identifier strategy, the CP/CPS control mapping, and the disclosure statement.
EN 319 411-2 requires qualified certificates to include at least one applicable policy identifier choice, and it restricts the qcStatement to the QSCD profiles. If the certificate uses only a TSP-allocated OID, the referenced certificate policy must clearly identify which EN 319 411-2 policy it adopts as the basis.
Store the selected profile, rejected alternatives, subject type, intended certificate use, and decision in the CP/CPS working papers.
Check that certificate policy identifiers match the selected profile and that any TSP-allocated OID clearly maps back to that EN 319 411-2 basis.
For and QCP-l-, verify QSCD certification evidence, key-pair generation route, QSCD status monitoring, the required QSCD qcStatement, and qualified remote-QSCD management status where the issuing TSP manages the device for the subject.
For non- certificates, verify that the QSCD qcStatement is not included.
Use the selected qualified certificate profile to drive CP/CPS updates, certificate template checks, OID mapping, QSCD evidence, and disclosure review.
This worksheet is a pre-audit handoff. It is written as operational rows so it can be copied into a CP/CPS review ticket without losing the selection logic.
Step 1: Identify the certificate use. Choose signature, seal, or website authentication; name the subject type as natural person, legal person, or website-authentication subject. For website authentication, also record whether use is transport-layer-security authentication outside a web-browser or another context, because Regulation (EU) 2025/2527 applies different reference-standard branches from 6 January 2027.
Step 2: Decide the device claim. For signature or seal certificates, record whether the policy requires a and whether the TSP or another qualified TSP manages relevant key material.
Step 3: Select the profile. Map the facts to QCP-n, QCP-l, , QCP-l-, , QNCP-w, or QNCP-w-gen.
Step 4: Bind identifiers and disclosures. Confirm policy identifiers, TSP-allocated OIDs, CP/CPS statements, terms and conditions, and the PKI disclosure statement are consistent with the selected profile.
Step 5: Run a negative check. Confirm no website-authentication profile is being used for a signature or seal certificate, no qcStatement appears outside a QSCD profile, and no qualified claim relies only on EN 319 411-1.
Evidence owner: certificate-policy owner or QTSP compliance owner.
Engineering input: certificate template, configuration, qcStatements, CRL or OCSP profile assumptions, and key-management route.
Legal or compliance input: eIDAS qualified-service claim, terms and conditions, supervisory or trusted-list evidence, and customer-facing limitations.
Assessor input: mapping from selected profile to clauses 5 and 6 of EN 319 411-2 and incorporated EN 319 411-1 requirements.
Common profile-selector failures are traceability failures. The certificate may be technically parseable while the CP/CPS, , qcStatement, or website-authentication route points to a different EN 319 411-2 policy than the one the team intended.
Treat the profile decision as a release gate for qualified certificate services. A profile mismatch can affect assessor evidence, relying-party interpretation, trusted-list validation, and the legal framing of a qualified-certificate claim.
Do not claim or QCP-l- unless the QSCD certification, key-generation route, and QSCD qcStatement evidence are present.
Do not include the qcStatement in certificates that are not issued under or QCP-l-qscd.
Do not use , QNCP-w, or QNCP-w-gen unless the service is actually issuing qualified website-authentication certificates.
Do not treat EN 319 411-2 conformance by itself as proof that the TSP or certificate is qualified under eIDAS; qualification also depends on the legal and supervisory context.
Do not let a TSP-allocated hide the EN 319 411-2 basis; the referenced certificate policy must identify the profile it adopts.
Binding source that references EN 319 411-2 V2.6.1 with adaptations for the presumption-of-compliance route for qualified signature and seal certificates.
Binding future source that separates the reference-standard routes for transport-layer-security authentication outside a web-browser from other QWACs, including browser-context certificates; it applies from 6 January 2027.
Supports policy-identifier checks, TSP-allocated OID handling, QSCD qcStatement inclusion or exclusion, and the CP statement about whether the policy requires QSCD use.
Supports the QCP-n, QCP-l, QCP-n-qscd, and QCP-l-qscd selection rules and the QSCD evidence requirements in key-pair generation and certificate profiles.
"the private key related to the certified public key resides in the QSCD"
Supports the selector's profile set and the distinction between natural-person, legal-person, QSCD, and website-authentication qualified certificate policies.
Supports the worksheet sequence by tying profile selection to certificate purpose, QSCD status, policy identifiers, CP/CPS statements, and incorporated requirements.