Requirements MapGLOBALETSI EN 319 411-2

ETSI EN 319 411-2 requirements map

Trace EU qualified certificate service requirements from EN 319 411-2 into policy profiles, CP/CPS evidence, certificate contents, revocation, status services, and eIDAS mapping.

Map the standard together with its inherited Part 1 controls, current eIDAS text, and binding EU adaptations.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use this map to identify the policy, , inherited controls, binding adaptations, and evidence for an EU qualified certificate service. Start with the current eIDAS and implementing-regulation layer, then trace the applicable EN 319 411-2 V2.6.1 profile, imported EN 319 411-1 requirements, branch, certificate profile, lifecycle controls, and status service. of the standard is informative and does not establish legal compliance.

Section 1

Start with the qualified certificate policy profile

EN 319 411-2 does not define one generic certificate service. It defines EU qualified certificate policies and uses those policy indicators to decide which additional requirements apply. The first mapping step is therefore to identify the service as QCP-n, QCP-l, QCP-n-, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.

The profile changes the baseline. QCP-n and QCP-l use NCP unless the trust service provider's (TSP's) terms require a secure cryptographic device, in which case NCP+ applies. QCP-n- and QCP-l-qscd include the relevant QCP requirements, NCP+, and QSCD provisions. QEVCP-w, QNCP-w, and QNCP-w-gen use different EVCP, OVCP/IVCP, or web-tagged dependencies. For QEVCP-w and QNCP-w, the current BRG or EVCG takes precedence if it conflicts with EN 319 411-2.

  • Map natural-person qualified certificates to QCP-n, or to QCP-n- when the private key related to the certified public key resides in a QSCD.
  • Map legal-person qualified certificates to QCP-l, or to QCP-l- when the private key related to the certified public key resides in a QSCD.
  • Map qualified website authentication certificates to QEVCP-w, QNCP-w, or QNCP-w-gen depending on the EV, OV/IV, or general-purpose website-authentication basis.
  • Record whether the profile imports NCP, NCP+, EVCP, IVCP, OVCP, or EN 319 411-1 web-tagged requirements, including any BRG or EVCG precedence rule.
Section 2

Tie each requirement to CP, CPS, and certificate identifiers

Separate three layers: the states the claimed quality and applicability, the explains how the TSP operates the service, and the certificate carries policy identifiers that relying parties can evaluate.

Clause 6.6.1 requires at least one allowed for the selected profile. That may be the ETSI identifier, an OID allocated to the actually applied, or both, subject to the profile-specific choice. The CP must incorporate or further constrain all applicable clauses 5 and 6 requirements; an internal OID does not remove that traceability.

  • Keep a profile table that lists the adopted EN 319 411-2 policy, any TSP-specific OID, and the corresponding document.
  • Trace CP statements to CPS practices for registration, generation, dissemination, revocation, status service, subject device provisioning, and general operational controls.
  • Check certificate output for the required choice and, where applicable, the correct qualified-certificate statements.
  • For QEVCP-w and QNCP-w, record how BRG or EVCG precedence is applied if those requirements conflict with EN 319 411-2.
Section 3

Map operational controls by service component

Preserve the standard's service-component structure instead of flattening the requirements into a generic checklist. EN 319 411-2 uses OVR for general requirements, GEN for certificate generation, REG for registration, REV for revocation, DIS for dissemination, SDP for subject device provisioning, and CSS for certificate status service.

Many clauses say that the corresponding EN 319 411-1 requirement applies, then add qualified-certificate-specific requirements. Treat those imports as live obligations in the map: the qualified service is not covered just because the EN 319 411-2 add-on text was reviewed.

Commission Implementing Regulation (EU) 2025/2530 adds cross-service duties beside the standards map. A must notify the supervisory body before significant changes covered by Article 1, keep a risk-management framework, maintain a termination plan for each qualified service, and review that plan at least every two years and when provider or service changes are implemented.

  • For registration, include identity and attribute validation paths for natural persons, legal persons, and qualified website authentication subjects.
  • For dissemination, include terms and conditions, subscriber information, PKI disclosure statement support, and any service-use limitations.
  • For revocation and certificate status, map the certificate database, revocation request handling, status publication, CRL or OCSP profile requirements, and availability beyond certificate validity where applicable.
  • For general operations, include audit logging, records archival, termination planning, security incident handling, personnel controls, and technical security controls imported from EN 319 411-1 and EN 319 401. Add current requirements from Regulation (EU) 2025/2530 for change notification, risk management, and service-specific termination planning.
  • Assign an owner to each service termination plan, retain its policies, procedures, third-party arrangements, review records, and audit reports, and trigger a review at least every two years and whenever a relevant provider or service change is implemented.
Section 4

Handle QSCD requirements as a separate branch

For QCP-n- or QCP-l-qscd, map device certification, proof that the public key comes from a key pair generated by a QSCD, any key import or device-to-device movement, third-party device management, and the CPS response to a QSCD status change. Where the TSP manages a remote QSCD for the subject, Regulation (EU) 2025/1943 requires it to provide the corresponding qualified remote-QSCD management service.

Certificate content must also reflect the branch correctly. EN 319 411-2 requires the QSCD qcStatement for QCP-n-qscd and QCP-l-qscd certificates, and it says that the QSCD qcStatement must not be included in certificates that are not issued under those QSCD policies.

  • Create a evidence row only when the policy profile actually requires QSCD use.
  • Record how the TSP verifies device certification and whether any third-party TSP manages the device on behalf of the subject.
  • Map certificate-generation checks that prove the public key to be certified came from the route claimed by the profile.
  • Check certificate profile output for the qcStatement inclusion or exclusion rule before publishing a qualified-certificate claim.
Section 5

Apply current EU adaptations before using Annex A

Regulation (EU) 2025/1943 references EN 319 411-2 V2.6.1 for qualified signature and seal certificates with adaptations. The adaptations replace or add requirements for identity validation, certificate issuance, remote management, cryptographic mechanisms, CRL preservation, personnel controls, key generation, and other areas. Build the map from the adapted text rather than marking the unmodified standard complete.

remains useful for orientation, but it maps the regulation text available when the standard was prepared. The annex itself says it is not a definitive statement of eIDAS conformance, some legal requirements are outside the standard, and the standard was not legally reviewed. Use the current consolidated Regulation and implementing acts for the legal layer.

  • Maintain an adaptation register showing which EN 319 411-2 and EN 319 411-1 clauses are replaced, amended, or supplemented by Regulation (EU) 2025/1943.
  • For identity validation, map current Article 24 routes and note that Regulation (EU) 2025/1566 applies its adapted ETSI TS 119 461 reference standard from 19 August 2027.
  • Keep non-technical regulatory questions separate from the EN 319 411-2 control map.
  • Do not claim complete eIDAS conformance from EN 319 411-2 mapping alone.
  • For QWACs, note that Regulation (EU) 2025/2527 applies its EN 319 411-2 reference routes from 6 January 2027.
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • The regulation referenced by Annex A for qualified trust service provider, qualified certificate, revocation, and status-information requirements.
"qualified trust service providers"
Related guides

Explore more topics

eIDAS QTSP supervision workflow for ETSI EN 319 411-2
Operational workflow for qualified trust service providers using ETSI EN 319 411-2 to manage supervisory-body changes, incidents, termination evidence, trusted-list checks, and assessment records.
ETSI EN 319 411-2 certificate operations
Operational guide for ETSI EN 319 411-2 qualified certificate services: policy identifiers, identity validation, issuance, QSCD handling, revocation status, and relying-party notices.
ETSI EN 319 411-2 compliance checklist
Compliance checklist for ETSI EN 319 411-2 qualified certificate services, covering policy selection, CP/CPS evidence, identity validation, QSCD status, trusted-list reliance, and certificate status services.
ETSI EN 319 411-2 FAQ for EU Qualified Certificates
Answers to common ETSI EN 319 411-2 questions about EU qualified certificate policies, QSCD use, identity validation, trusted lists, and revocation status services.
ETSI EN 319 411-2 Identity Proofing
How EN 319 411-2 applies identity validation for EU qualified certificates, including QCP natural-person, legal-person, website, and evidence-record checks.
ETSI EN 319 411-2 profile selector
Select the right ETSI EN 319 411-2 qualified certificate policy profile for signatures, seals, QSCD use, and website authentication.
ETSI EN 319 411-2 QSCD Route
When QCP-n-qscd or QCP-l-qscd is the right EN 319 411-2 route, what QSCD evidence is needed, and which certificate-profile claims must stay aligned.
ETSI EN 319 411-2 QTSP supervision evidence workflow
Build an assessment-ready QTSP supervision evidence pack for ETSI EN 319 411-2 qualified certificate services, covering policy identifiers, trusted-list checks, incident records, QSCD evidence, and termination controls.
ETSI EN 319 411-2 Qualified Certificate Scope
Use ETSI EN 319 411-2 to scope EU qualified certificate services by certificate policy, subject type, QSCD use, website authentication profile, and eIDAS context.
ETSI EN 319 411-2 trusted-list evidence
Build EN 319 411-2 trusted-list evidence for EU qualified certificate reliance: relying-party notice text, QTSP service identifiers, validation records, and change triggers.
ETSI EN 319 411-2 trusted-list validation workflow
Validate an EN 319 411-2 EU qualified-certificate claim by mapping the certificate service to the QTSP trusted-list entry, policy profile, relying-party notice, and status evidence.
ETSI EN 319 411-2 vs eIDAS Qualified Trust Services
Compare ETSI EN 319 411-2 certificate policy requirements with the eIDAS qualified-status, supervision, audit, and trusted-list framework.
ETSI EN 319 411-2 vs EN 319 411-1
Compare ETSI EN 319 411-2 EU qualified certificate requirements with EN 319 411-1 general certificate-service requirements, including policy inheritance, QSCD controls, and CP/CPS evidence reuse.
ETSI EN 319 411-2: Certificate Revocation FAQ
Answer the ETSI EN 319 411-2 revocation question for qualified certificate services: CPS procedures, 24-hour publication, CRL or OCSP status, and evidence to retain.
ETSI EN 319 411-2: end-to-end qualified certificate lifecycle management workflow
Lifecycle workflow for ETSI EN 319 411-2 qualified certificate services, from policy selection and identity validation through issuance, renewal, re-key, modification, revocation, status services, and records.
ETSI EN 319 411-2: Legal vs Natural Person Certs
ETSI EN 319 411-2 separates qualified certificate policies for natural persons, legal persons, QSCD use, and website authentication subscribers.
ETSI EN 319 411-2: QCP, QNCP, and QEVCP Profile Selection
Choose the right ETSI EN 319 411-2 qualified certificate policy profile: QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen.
How should QTSPs select an ETSI EN 319 411-2 qualified certificate profile?
A focused FAQ on choosing QCP-n, QCP-l, QCP-n-qscd, QCP-l-qscd, QEVCP-w, QNCP-w, or QNCP-w-gen under ETSI EN 319 411-2.
How should relying parties use trusted lists under ETSI EN 319 411-2?
FAQ on EN 319 411-2 trusted-list reliance for EU qualified certificates: relying-party notices, QTSP service identifiers, validation evidence, and source references.
QSCD Requirements in ETSI EN 319 411-2
How ETSI EN 319 411-2 treats QSCD-backed qualified certificates, including QCP-n-qscd and QCP-l-qscd policies, key-use controls, QSCD verification, and certificate profile evidence.
QTSP Supervision and ETSI EN 319 411-2
How ETSI EN 319 411-2 supports QTSP supervision evidence for qualified certificate services, trusted-list reliance, liability responsibility, incident records, and audit preparation.
Qualified certificates under ETSI EN 319 411-2
FAQ answer for QTSPs on how ETSI EN 319 411-2 treats EU qualified certificates, policy identifiers, QSCD variants, website certificates, and lifecycle evidence.
What are the qualified certificate policies in ETSI EN 319 411-2?
FAQ on ETSI EN 319 411-2 qualified certificate policies, including QCP-n, QCP-l, QSCD variants, QEVCP-w, QNCP-w, and policy identifiers.
Which QWAC Profile Fits ETSI EN 319 411-2?
Choose between QEVCP-w, QNCP-w, and QNCP-w-gen for qualified website authentication certificates under ETSI EN 319 411-2.