Becoming a Qualified Trust Service Provider under eIDAS 2.0: A Step-by-Step Checklist

Illustration of a person reviewing a compliance checklist beside a shield

To become a Qualified Trust Service Provider (QTSP) under eIDAS 2.0, you must build a trust service that meets the regulation and the matching ETSI standards, pass an audit by an accredited conformity assessment body, and notify your national supervisory body. Only after the supervisory body grants qualified status and adds you to the national trusted list can you sell the service as qualified.

What is a QTSP?

A trust service provider (TSP) offers electronic trust services such as certificates, electronic seals or timestamps. A QTSP is a TSP that a national supervisory body has granted qualified status for one or more of its services.

eIDAS 2.0 rewrote the definition of a trust service. The list now covers:

  • issuing and validating certificates for electronic signatures, electronic seals and website authentication;
  • creating, validating and preserving electronic signatures and seals;
  • managing remote signature and seal creation devices;
  • issuing and validating electronic attestations of attributes;
  • creating and validating electronic timestamps;
  • electronic registered delivery;
  • electronic archiving and electronic ledgers.

Several of these, such as attestations of attributes, archiving and ledgers, now have qualified versions with their own requirements.

What changed with eIDAS 2.0

  • The legal base. eIDAS 2.0 is Regulation (EU) 2024/1183, which amends the original eIDAS Regulation (EU) No 910/2014. It was published on 30 April 2024 and entered into force on 20 May 2024.
  • The wallet. It creates the European Digital Identity Wallet. QTSPs can issue qualified electronic attestations of attributes, and the wallet is one of the accepted ways to verify a person’s identity before issuing a qualified certificate.
  • The link to NIS2. QTSP audits now confirm the requirements of eIDAS and of Article 21 of the NIS2 Directive (EU) 2022/2555, which covers cybersecurity risk-management measures.
  • Reference standards. The Commission adopts implementing acts that list reference standards for many qualified services. Meeting them gives a presumption of compliance, so check which ones apply to your service when you start.

The step-by-step checklist

Step 1: Pick your service and your country

Decide which qualified service or services you will offer first. Qualified status is granted for specific services, so each one must be in the scope of your audit.

Your supervisory body is the one designated by the EU member state where you are established.

Step 2: Run a gap analysis

Compare your current setup with Article 24 of eIDAS (requirements for QTSPs) and the ETSI standards for your service. The core ETSI standards include:

  • EN 319 401: general policy requirements for trust service providers.
  • EN 319 411-1 and EN 319 411-2: requirements for providers issuing certificates, with 411-2 covering EU qualified certificates.
  • EN 319 412: certificate profiles.
  • EN 319 421: providers issuing timestamps.

For an outside view, our PKI consulting services include compliance advisory, audit preparation and remediation.

Step 3: Design the technical architecture

Plan the CA hierarchy, key ceremonies, HSMs that meet the certification requirements for your service, a secure time source, network zones and backups. Build in redundancy and disaster recovery from day one.

A platform such as DictaLabs CA, our certificate authority platform, supports root, intermediate and issuing CA hierarchies, offline roots and HSM integration over PKCS#11. As its product page notes, formal compliance wording depends on the approved scope of the selected release and deployment.

Step 4: Write the documents

  • A Certificate Policy and Certification Practice Statement (CP/CPS) structured according to RFC 3647. Our guide to common CP/CPS audit gaps explains what auditors check.
  • Terms and conditions, a PKI disclosure statement, and subscriber and relying party agreements.
  • A risk assessment, an information security policy, business continuity and disaster recovery plans, and an up-to-date termination plan, which Article 24 requires.

Step 5: Build the identity verification process

Before issuing a qualified certificate, a QTSP must verify the person’s identity. Article 24(1a) lists the accepted methods, alone or combined:

  • the European Digital Identity Wallet, or a notified electronic identification means at assurance level high;
  • a certificate for a qualified electronic signature or seal that was itself issued after one of the other methods;
  • other methods that identify the person with a high level of confidence, confirmed by a conformity assessment body;
  • the physical presence of the person, or of an authorized representative of a legal person.

Document every step, because auditors will test it end to end.

Step 6: People and roles

Define trusted roles, separation of duties, training records and background checks. Name the people responsible for key ceremonies and incident response.

Step 7: Financial and legal readiness

Article 24 requires sufficient financial resources and/or appropriate liability insurance, in line with national law. You also need GDPR records for the identity data you collect.

Step 8: Pre-audit

A dry run against the ETSI requirements finds gaps while they are still cheap to fix. Collect the evidence auditors will ask for: logs, ceremony records, policies and test results.

Step 9: Formal conformity assessment

Choose a conformity assessment body (CAB) accredited under Regulation (EC) No 765/2008 as competent to assess QTSPs. ETSI EN 319 403-1 sets the requirements for bodies that assess trust service providers. The CAB audits you and issues a conformity assessment report.

Step 10: Notify the supervisory body

Under Article 21, you notify the supervisory body of your intention to provide the qualified service, together with the conformity assessment report.

If the supervisory body concludes that you comply, it grants qualified status and informs the body that updates the national trusted list, no later than three months after notification. If it needs longer, it must tell you why and when it expects to finish. Once your status appears in the trusted list, you may use the EU trust mark for qualified trust services.

Step 11: Stay qualified

  • Be audited by a CAB at least every 24 months (Article 20), and send the report to the supervisory body within three working days of receiving it.
  • Tell the supervisory body at least one month before a planned audit, and at least one month before changing a qualified service.
  • Notify the supervisory body of security breaches or disruptions that have a significant impact on the service without undue delay, and in any event within 24 hours.

How long does it take and what does it cost?

It depends on the service, your starting point and your country. A team that already runs a well-documented CA is in a very different place from one starting from scratch. Ask your supervisory body and your CAB about their timelines early.

Common reasons QTSP projects slip

  • Documents written from templates that do not match real operations.
  • HSMs or software chosen before checking certification requirements.
  • An identity verification process that was never tested end to end.
  • A conformity assessment body booked too late.

How DictaLabs helps

Our eIDAS trust service provider consulting supports organizations pursuing TSP status and QTSP readiness. It covers:

  • Design and setup of trust services: public and private CAs, qualified and non-qualified services, signing and sealing, timestamping and validation.
  • CP/CPS development aligned with RFC 3647, eIDAS requirements and the CA/Browser Forum Baseline Requirements.
  • Key management, incident response, subscriber and relying party agreements, and business continuity and disaster recovery plans.
  • Alignment of architecture, cryptographic controls, identity verification and operational procedures with eIDAS and ETSI standards.
  • Common Criteria (ISO/IEC 15408) support, pre-audit gap analysis, evidence preparation and remediation support.

Related products include DictaLabs CA and DictaLabs TSA, our RFC 3161 timestamping authority.

Next step

This checklist is general guidance, not legal advice. Always check the current consolidated eIDAS text and your supervisory body’s own rules. When you are ready to plan your route to qualified status, talk to our trust services team.