What Is a Qualified Trust Service Provider (QTSP) under eIDAS?

A qualified trust service provider (QTSP) is an organization that offers one or more qualified trust services, such as qualified electronic signatures, seals or time stamps, under the EU eIDAS Regulation. It has passed an independent audit, has been granted qualified status by its national supervisory body, and is listed on its country’s EU trusted list.

What eIDAS is

eIDAS is Regulation (EU) No 910/2014 on electronic identification and trust services. Its trust service rules have applied since July 1, 2016.

It was updated by Regulation (EU) 2024/1183, often called eIDAS 2.0, which entered into force on May 20, 2024. eIDAS 2.0 also creates the European Digital Identity Wallet.

eIDAS gives one set of rules for all EU member states. A qualified trust service from one member state is recognized in all the others.

Trust services under eIDAS

A trust service is an electronic service such as:

  • electronic signatures (for people)
  • electronic seals (for organizations)
  • electronic time stamps
  • electronic registered delivery
  • certificates for website authentication
  • validation and preservation of signatures and seals

eIDAS 2.0 adds new trust services, including electronic attestations of attributes, electronic archiving, electronic ledgers and the management of remote signature and seal creation devices.

Qualified and non-qualified providers

Any company can be a trust service provider (TSP) if it meets the general security and reporting rules. A non-qualified TSP does not need an audit or qualified status before it starts.

A QTSP must meet stricter rules and pass an audit before it may offer a qualified service. The difference matters in law:

  • A qualified electronic signature has the same legal effect as a handwritten signature in every member state.
  • A qualified electronic seal is presumed to be intact and to come from the named organization.
  • A qualified electronic time stamp is presumed to have an accurate date and time and intact data. See how RFC 3161 timestamps work.
  • If damage occurs, a QTSP is presumed to be at fault unless it proves it was not (Article 13).

How an organization becomes a QTSP

  1. Build the service: systems, HSMs, identity checks, trained staff and processes.
  2. Write the documents: Certificate Policy and Certification Practice Statement (CP/CPS), terms and conditions, security policy, business continuity plan and termination plan.
  3. Pass a conformity assessment: an independent conformity assessment body (CAB), accredited in an EU member state, audits the service. The audit usually uses ETSI standards.
  4. Notify the supervisory body: the provider sends the CAB’s report to its national supervisory body.
  5. Get qualified status: the supervisory body checks the report and grants qualified status. The service is added to the national trusted list. Only then may the provider call it qualified and use the EU trust mark.
  6. Stay qualified: a new conformity assessment at least every 24 months, plus ongoing supervision.

Key ETSI standards

  • ETSI EN 319 401: general policy requirements for all trust service providers
  • ETSI EN 319 411-1 and 319 411-2: requirements for providers that issue certificates (411-2 covers EU qualified certificates)
  • ETSI EN 319 412 series: certificate profiles
  • ETSI EN 319 421: requirements for time-stamping services
  • ETSI EN 319 403-1: requirements for the conformity assessment bodies that audit providers

Qualified signatures and seals also need a certified qualified signature or seal creation device (QSCD).

How to check a QTSP

Every member state publishes a trusted list of its qualified providers and services. The European Commission publishes a central list that points to every national trusted list.

If a provider or service is not on a trusted list, it is not qualified.

How DictaLabs helps

DictaLabs supports organizations pursuing TSP status and QTSP readiness through its trust service provider (TSP) consulting. The work aligns technical architecture, cryptographic controls, identity verification processes and operational procedures with eIDAS requirements and ETSI standards. It covers:

  • CP/CPS documents aligned with RFC 3647, eIDAS requirements and the CA/Browser Forum Baseline Requirements
  • Operational documents: key management policies, incident response procedures, subscriber and relying party agreements, and business continuity and disaster recovery plans
  • Audit readiness: pre-audit gap analysis, evidence preparation, technical and procedural clarifications, and remediation support
  • Common Criteria (ISO/IEC 15408) readiness, including Security Target preparation

On the platform side, DictaLabs CA is built around ETSI and eIDAS trust service models and supports trust service providers that want to launch a CA-as-a-Service offering. DictaLabs TSA provides RFC 3161 timestamping designed around ETSI EN 319 421/422.

Next step

Planning to launch a trust service? Schedule a consultation with DictaLabs.

Related