DS/EN 319 411-2 V2.1.1:2016

Electronic Signatures and Infrastructures (ESI); Policy and security requirements for Trust Service Providers issuing certificates; Part 2: Requirements for trust service providers issuing EU qualified certificates



The present document specifies policy and security requirements for the issuance, maintenance and life-cycle
management of EU qualified certificates as defined in Regulation (EU) N° 910/2014 [i.1]. These policy and security
requirements support reference certificate policies for the issuance, maintenance and life-cycle management of EU
qualified certificates issued to natural persons (including natural persons associated with a legal person), to legal
persons and to web sites, respectively.
The present document does not specify how the requirements identified can be assessed by an independent party,
including requirements for information to be made available to such independent assessors, or requirements on such
assessors. The present document however provides in annex B a check list of the policy requirements specific to TSP
issuing EU qualified certificates (as expressed in the present document) as well as all the requirements incorporated by
reference to ETSI EN 319 411-1 [2] and ETSI EN 319 401 [1], that can be used by the TSP to prepare an assessment of
its practices against the present document and/or by the assessor when conducting the assessment for confirming that a
TSP meets the requirements for issuing qualified certificates under Regulation (EU) N° 910/2014 [i.1].
NOTE: See ETSI EN 319 403 [i.7] for guidance on assessment of TSP processes and services.

