Skip to main content

ETSI EN 319 401

ETSI EN 319 401 sets general policy and security requirements for trust service providers, as part of the ETSI electronic-signature and trust-infrastructure series. It applies to the operator of a trust service, not the software the operator runs. This page indexes the clauses relevant to a software supplier's development practices.

Requirement groupThemes
Clause 7.1 — internal organization, including the segregation of conflicting dutiesT9 Segregation of duties and least privilege
Clause 7.2 — human resources, including the security responsibilities of direct suppliers and service providersT9 Segregation of duties and least privilege
T11 Third-party components and supply chain
Incident managementT13 Vulnerability handling and disclosure
T14 Security updates and supported versions

Clause 7 directs implementers to apply the guidance of ISO/IEC 27002:2022, so the ISO/IEC 27001 Annex A rows answer clause 7's development-relevant requirements directly, and a trust service provider's auditor can use them as they stand.

EN 319 411-1 and 411-2 for certificates, EN 319 421 and 422 for time-stamping, and EN 419 241-2 for remote signing inherit EN 319 401 and add operator obligations; the themes answer the software-supplier and change-control portions, and the remainder belongs to the trust service provider.