Artifact GuideGLOBALETSI EN 319 411-2

ETSI EN 319 411-2 Qualified Profile Selector

Choose the EN 319 411-2 policy profile that matches the certificate subject, intended use, QSCD claim, and website-authentication route.

This serves as standards implementation guidance for certificate-policy scoping and evidence planning, not for legal interpretation.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
6

Structured answer sets in this page tree.

Primary sources
11

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

ETSI EN 319 411-2 defines seven EU qualified certificate policies for trust service providers issuing EU qualified certificates. This workflow helps certificate-policy owners select the before they draft the CP/CPS, encode policy identifiers, claim support, or prepare assessor evidence.

Section 1

Start with the certificate purpose

Start by identifying what the qualified certificate is meant to support: a natural person's electronic signature, a legal person's electronic seal, or website authentication.

EN 319 411-2 builds these qualified profiles on EN 319 411-1 policy families such as NCP, NCP+, EVCP, OVCP, IVCP, and web-authentication requirements, then adds eIDAS-qualified certificate requirements. That means the chosen profile determines both the base controls and the qualified-certificate additions.

  • Use QCP-n for a qualified certificate issued to a natural person. It is aimed at advanced electronic signatures based on a qualified certificate; select when the policy also claims the qualified-signature route.
  • Use QCP-l for a qualified certificate issued to a legal person. It is aimed at advanced electronic seals based on a qualified certificate; select QCP-l- when the policy also claims the qualified-seal QSCD route.
  • Use , QNCP-w, or QNCP-w-gen only for qualified website-authentication certificates, not for ordinary signature or seal certificates.
  • Document the reason for excluding other profiles so the CP/CPS reviewer can see that the profile was selected deliberately.
Section 2

Select QCP-n, QCP-l, or a QSCD variant

For signature and seal certificates, the selection depends on two facts: the subject type and whether the policy requires the private key related to the certified public key to reside in a Qualified Signature Creation Device or Qualified Seal Creation Device. Commission Implementing Regulation (EU) 2025/1943 references EN 319 411-2 V2.6.1 with adaptations for the EU presumption-of-compliance route for qualified signature and seal certificates. Apply those adaptations with the standard, including changes affecting policy applicability, identity validation, certificate issuance, algorithms, status services, personnel, and termination.

The non- profiles still need an explicit policy decision. EN 319 411-2 says QCP-n and QCP-l include NCP requirements and qualified-certificate additions; if the terms and conditions require a secure cryptographic device, NCP+ requirements apply. The QSCD profiles go further and require the QSCD-specific policy path.

  • Natural person, signature use, no policy claim: select QCP-n and map the applicable NCP or NCP+ base requirements.
  • Legal person, seal use, no policy claim: select QCP-l and map the applicable NCP or NCP+ base requirements.
  • Natural person with the private key in a : select and collect QSCD certification, key-generation, and certificate-profile evidence.
  • Legal person with the private key in a : select QCP-l-qscd and collect the same QSCD evidence for the seal-creation route.
  • If the issuing TSP manages a remote for the subject, verify that it provides the corresponding qualified remote signature- or seal-device management service required by Regulation (EU) 2025/1943.
Section 3

Select the website-authentication profile

Website-authentication certificates follow a separate branch. EN 319 411-2 V2.6.1 defines three qualified website-authentication policy profiles: based on EVCP, QNCP-w based on NCP plus OVCP or IVCP, and QNCP-w-gen based on NCP plus WEB-tagged Part 1 requirements. Older editions used QCP-w for the route now named QEVCP-w; do not copy that historical abbreviation into a new V2.6.1 selection record. From 6 January 2027, Commission Implementing Regulation (EU) 2025/2527 uses EN 319 411-2 V2.6.1 or ETSI TS 119 495 for transport-layer-security authentication outside a web-browser, but points other QWACs, including browser-context certificates, to ETSI TS 119 411-5. Record the relying-party context and applicable date before selecting the legal reference-standard route.

This branch should be decided before certificate templates and public disclosures are finalized because and QNCP-w also depend on external CA/Browser Forum requirement families. EN 319 411-2 states that, for QEVCP-w and QNCP-w, the latest EVCG or BRG requirements take precedence if they conflict with EN 319 411-2 requirements.

  • Use for an EU qualified website-authentication certificate based on EVCP for a legal person.
  • Use QNCP-w for an EU qualified website-authentication certificate based on NCP plus OVCP or IVCP.
  • Use QNCP-w-gen for a general-purpose qualified website-authentication certificate based on NCP and EN 319 411-1 WEB-tagged requirements.
  • Record whether BRG or EVCG requirements add or override implementation details for QNCP-w or ; the stated conflict-precedence rule does not name QNCP-w-gen.
Section 4

Translate the selected profile into certificate evidence

After the profile is selected, the evidence pack should prove that the certificate and the CP/CPS follow the selected EN 319 411-2 route. The profile decision should appear in the certificate policy name and identification, the certificate's policy identifier strategy, the CP/CPS control mapping, and the disclosure statement.

EN 319 411-2 requires qualified certificates to include at least one applicable policy identifier choice, and it restricts the qcStatement to the QSCD profiles. If the certificate uses only a TSP-allocated OID, the referenced certificate policy must clearly identify which EN 319 411-2 policy it adopts as the basis.

  • Store the selected profile, rejected alternatives, subject type, intended certificate use, and decision in the CP/CPS working papers.
  • Check that certificate policy identifiers match the selected profile and that any TSP-allocated OID clearly maps back to that EN 319 411-2 basis.
  • For and QCP-l-, verify QSCD certification evidence, key-pair generation route, QSCD status monitoring, the required QSCD qcStatement, and qualified remote-QSCD management status where the issuing TSP manages the device for the subject.
  • For non- certificates, verify that the QSCD qcStatement is not included.
Section 5

Profile selector worksheet

This worksheet is a pre-audit handoff. It is written as operational rows so it can be copied into a CP/CPS review ticket without losing the selection logic.

Step 1: Identify the certificate use. Choose signature, seal, or website authentication; name the subject type as natural person, legal person, or website-authentication subject. For website authentication, also record whether use is transport-layer-security authentication outside a web-browser or another context, because Regulation (EU) 2025/2527 applies different reference-standard branches from 6 January 2027.

Step 2: Decide the device claim. For signature or seal certificates, record whether the policy requires a and whether the TSP or another qualified TSP manages relevant key material.

Step 3: Select the profile. Map the facts to QCP-n, QCP-l, , QCP-l-, , QNCP-w, or QNCP-w-gen.

Step 4: Bind identifiers and disclosures. Confirm policy identifiers, TSP-allocated OIDs, CP/CPS statements, terms and conditions, and the PKI disclosure statement are consistent with the selected profile.

Step 5: Run a negative check. Confirm no website-authentication profile is being used for a signature or seal certificate, no qcStatement appears outside a QSCD profile, and no qualified claim relies only on EN 319 411-1.

  • Evidence owner: certificate-policy owner or QTSP compliance owner.
  • Engineering input: certificate template, configuration, qcStatements, CRL or OCSP profile assumptions, and key-management route.
  • Legal or compliance input: eIDAS qualified-service claim, terms and conditions, supervisory or trusted-list evidence, and customer-facing limitations.
  • Assessor input: mapping from selected profile to clauses 5 and 6 of EN 319 411-2 and incorporated EN 319 411-1 requirements.
Section 6

Mistakes that break the profile decision

Common profile-selector failures are traceability failures. The certificate may be technically parseable while the CP/CPS, , qcStatement, or website-authentication route points to a different EN 319 411-2 policy than the one the team intended.

Treat the profile decision as a release gate for qualified certificate services. A profile mismatch can affect assessor evidence, relying-party interpretation, trusted-list validation, and the legal framing of a qualified-certificate claim.

  • Do not claim or QCP-l- unless the QSCD certification, key-generation route, and QSCD qcStatement evidence are present.
  • Do not include the qcStatement in certificates that are not issued under or QCP-l-qscd.
  • Do not use , QNCP-w, or QNCP-w-gen unless the service is actually issuing qualified website-authentication certificates.
  • Do not treat EN 319 411-2 conformance by itself as proof that the TSP or certificate is qualified under eIDAS; qualification also depends on the legal and supervisory context.
  • Do not let a TSP-allocated hide the EN 319 411-2 basis; the referenced certificate policy must identify the profile it adopts.
Primary sources

References and citations

etsi.org
Referenced sections
  • Supports the QCP-n, QCP-l, QCP-n-qscd, and QCP-l-qscd selection rules and the QSCD evidence requirements in key-pair generation and certificate profiles.
"the private key related to the certified public key resides in the QSCD"
etsi.org
Referenced sections
  • Supports the worksheet sequence by tying profile selection to certificate purpose, QSCD status, policy identifiers, CP/CPS statements, and incorporated requirements.
"Certificate Policy name and identification"
eur-lex.europa.eu
Referenced sections
  • Supports the warning that qualified status is part of the wider eIDAS trust-service framework, not only a standards-document label.
"qualified trust services"
Related guides

Explore more topics

eIDAS QTSP supervision workflow for ETSI EN 319 411-2
Operational workflow for qualified trust service providers using ETSI EN 319 411-2 to manage supervisory-body changes, incidents, termination evidence, trusted-list checks, and assessment records.
ETSI EN 319 411-2 certificate operations
Operational guide for ETSI EN 319 411-2 qualified certificate services: policy identifiers, identity validation, issuance, QSCD handling, revocation status, and relying-party notices.
ETSI EN 319 411-2 compliance checklist
Compliance checklist for ETSI EN 319 411-2 qualified certificate services, covering policy selection, CP/CPS evidence, identity validation, QSCD status, trusted-list reliance, and certificate status services.
ETSI EN 319 411-2 FAQ for EU Qualified Certificates
Answers to common ETSI EN 319 411-2 questions about EU qualified certificate policies, QSCD use, identity validation, trusted lists, and revocation status services.
ETSI EN 319 411-2 Identity Proofing
How EN 319 411-2 applies identity validation for EU qualified certificates, including QCP natural-person, legal-person, website, and evidence-record checks.
ETSI EN 319 411-2 QSCD Route
When QCP-n-qscd or QCP-l-qscd is the right EN 319 411-2 route, what QSCD evidence is needed, and which certificate-profile claims must stay aligned.
ETSI EN 319 411-2 QTSP supervision evidence workflow
Build an assessment-ready QTSP supervision evidence pack for ETSI EN 319 411-2 qualified certificate services, covering policy identifiers, trusted-list checks, incident records, QSCD evidence, and termination controls.
ETSI EN 319 411-2 Qualified Certificate Scope
Use ETSI EN 319 411-2 to scope EU qualified certificate services by certificate policy, subject type, QSCD use, website authentication profile, and eIDAS context.
ETSI EN 319 411-2 requirements map
Map ETSI EN 319 411-2 requirements for EU qualified certificate services across QCP profiles, CP/CPS documentation, QSCD use, certificate profiles, revocation, and eIDAS Annex A references.
ETSI EN 319 411-2 trusted-list evidence
Build EN 319 411-2 trusted-list evidence for EU qualified certificate reliance: relying-party notice text, QTSP service identifiers, validation records, and change triggers.
ETSI EN 319 411-2 trusted-list validation workflow
Validate an EN 319 411-2 EU qualified-certificate claim by mapping the certificate service to the QTSP trusted-list entry, policy profile, relying-party notice, and status evidence.
ETSI EN 319 411-2 vs eIDAS Qualified Trust Services
Compare ETSI EN 319 411-2 certificate policy requirements with the eIDAS qualified-status, supervision, audit, and trusted-list framework.
ETSI EN 319 411-2 vs EN 319 411-1
Compare ETSI EN 319 411-2 EU qualified certificate requirements with EN 319 411-1 general certificate-service requirements, including policy inheritance, QSCD controls, and CP/CPS evidence reuse.
ETSI EN 319 411-2: Certificate Revocation FAQ
Answer the ETSI EN 319 411-2 revocation question for qualified certificate services: CPS procedures, 24-hour publication, CRL or OCSP status, and evidence to retain.
ETSI EN 319 411-2: end-to-end qualified certificate lifecycle management workflow
Lifecycle workflow for ETSI EN 319 411-2 qualified certificate services, from policy selection and identity validation through issuance, renewal, re-key, modification, revocation, status services, and records.
ETSI EN 319 411-2: Legal vs Natural Person Certs
ETSI EN 319 411-2 separates qualified certificate policies for natural persons, legal persons, QSCD use, and website authentication subscribers.
ETSI EN 319 411-2: QCP, QNCP, and QEVCP Profile Selection
Choose the right ETSI EN 319 411-2 qualified certificate policy profile: QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.
How should QTSPs select an ETSI EN 319 411-2 qualified certificate profile?
A focused FAQ on choosing QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen under ETSI EN 319 411-2.
How should relying parties use trusted lists under ETSI EN 319 411-2?
FAQ on EN 319 411-2 trusted-list reliance for EU qualified certificates: relying-party notices, QTSP service identifiers, validation evidence, and source references.
QSCD Requirements in ETSI EN 319 411-2
How ETSI EN 319 411-2 treats QSCD-backed qualified certificates, including QCP-n-qscd and QCP-l-qscd policies, key-use controls, QSCD verification, and certificate profile evidence.
QTSP Supervision and ETSI EN 319 411-2
How ETSI EN 319 411-2 supports QTSP supervision evidence for qualified certificate services, trusted-list reliance, liability responsibility, incident records, and audit preparation.
Qualified certificates under ETSI EN 319 411-2
FAQ answer for QTSPs on how ETSI EN 319 411-2 treats EU qualified certificates, policy identifiers, QSCD variants, website certificates, and lifecycle evidence.
What are the qualified certificate policies in ETSI EN 319 411-2?
FAQ on ETSI EN 319 411-2 qualified certificate policies, including QCP-n, QCP-l, QSCD variants, QEVCP-w, QNCP-w, and policy identifiers.
Which QWAC Profile Fits ETSI EN 319 411-2?
Choose between QEVCP-w, QNCP-w, and QNCP-w-gen for qualified website authentication certificates under ETSI EN 319 411-2.