eIDAS-Aligned PKI & Trust Service Consulting for Europe
DictaLabs is a PKI, digital signature and certificate management company with offices in Lahore, Pakistan and Middletown, Delaware, USA. For Europe, we offer eIDAS-aligned PKI and trust service consulting and products designed around ETSI standards; clients can contact either office or email info@dictalabs.com.
EU law
How eIDAS regulates trust services
eIDAS sets EU-wide rules for electronic identification and trust services. Regulation (EU) No 910/2014 applies from 1 July 2016. Regulation (EU) 2024/1183, often called eIDAS 2.0, amended it and entered into force on 20 May 2024.
Qualified status
Article 3(20) defines a qualified trust service provider as one that provides qualified trust services “and is granted the qualified status by the supervisory body”. Under Article 25, a qualified electronic signature has “the equivalent legal effect of a handwritten signature”.
What eIDAS 2.0 added
Trust services now include managing remote signature and seal creation devices, electronic attestations of attributes, electronic archiving and electronic ledgers. Article 5a requires each Member State to provide at least one European Digital Identity Wallet.
Audits and supervision
Under Article 20, qualified providers are audited “at least every 24 months by a conformity assessment body”. Since eIDAS 2.0, the audit also covers Article 21 of the NIS 2 Directive (EU) 2022/2555. Providers must inform the supervisory body at least one month before a planned audit.
Trusted lists
Each Member State must “establish, maintain and publish trusted lists” of qualified providers and their services (Article 22). Search them in the EU trusted list browser or read the Commission’s trusted lists page.
ETSI standards
Relevant ETSI standards include:
- EN 319 401: general TSP requirements
- EN 319 411-1 and -2: certificate issuers and EU qualified certificates
- EN 319 421 and 319 422: timestamping
- EN 319 122, 319 132 and 319 142: CAdES, XAdES and PAdES signatures
- EN 319 403-1: conformity assessment bodies
Qualified timestamps
Implementing Regulation (EU) 2025/1929 of 29 September 2025 sets the reference standards for qualified electronic time stamps. Its Annex applies ETSI EN 319 421 V1.3.1 and EN 319 422 V1.1.1, with adaptations.
This page is general information, not legal advice.
TSP readiness
How DictaLabs helps you prepare to become a trust service provider
DictaLabs helps organisations prepare to become trust service providers, including qualified ones. Only the supervisory body can grant qualified status. Under Article 21, you notify your supervisory body with a conformity assessment report. If you comply, it grants qualified status and the national trusted list is updated. It must explain any delay beyond three months.
A review of your current setup against eIDAS and the relevant ETSI requirements, with a prioritised list of gaps.
Architecture for CA hierarchies, HSM-backed keys and the trust services built on them.
Certificate policies and practice statements structured on RFC 3647, written to match how you actually operate.
Preparation for the conformity assessment against eIDAS and ETSI requirements, before the conformity assessment body arrives.
Readiness support for Common Criteria (ISO/IEC 15408) evaluations, where your products need them.
Our guide explains the steps: how to become a qualified trust service provider under eIDAS.
Products
DictaLabs products for trust service projects
These products support trust service projects. DictaLabs TSA is designed around ETSI EN 319 421/422. Using any product does not by itself make a service qualified.
Timestamping designed around RFC 3161, RFC 5816 and ETSI EN 319 421/422, the ETSI standards that Regulation (EU) 2025/1929 references.
An HSM-backed certificate authority platform with RFC 5280 certificate and CRL profiles and OCSP.
A central HSM-backed cryptographic service with REST APIs, for Thales Luna, Entrust nShield, Utimaco CryptoServer, AWS CloudHSM and Azure Key Vault/Managed HSM.
Certificate lifecycle management across multiple CA platforms, with ACME, SCEP and EST.
See how RFC 3161 timestamping works.
Use cases
Typical use cases in Europe
These are typical scenarios, not customer case studies.
A company that plans to issue qualified certificates prepares CP/CPS documents. It runs a gap analysis against ETSI EN 319 401 and 319 411 and plans its conformity assessment.
An organisation sets up a timestamping service and aligns it with ETSI EN 319 421/422 from the start.
eIDAS 2.0 lists managing remote signature and seal creation devices as a trust service. Providers planning remote signing need a design for HSM-backed key management.
Issuing certificates for staff, systems or devices under a documented CP/CPS, with lifecycle automation.
Inventory algorithms and keys now. Then plan how CAs, signatures and timestamps will move to post-quantum cryptography.
Read our post-quantum PKI migration plan.
Contact
How to work with DictaLabs from Europe
DictaLabs has no office in the EU. Clients in Europe can contact either of our offices or email info@dictalabs.com.
Write to info@dictalabs.com with a short description of your project.
26 Block G4 Rd, Phase 2, Johar Town, Lahore, Punjab, Pakistan.
A no-cost starting point before a PKI or trust service project.
Tell us your Member State, the trust services you plan and your timeline.
FAQ
Frequently asked questions
Yes, with preparation. We help with PKI architecture, CP/CPS documents based on RFC 3647, gap analysis and audit readiness against eIDAS and ETSI requirements. Only your national supervisory body can grant qualified status, after a conformity assessment.
It notifies its supervisory body and submits a conformity assessment report (Article 21). If the requirements are met, the body grants qualified status and the provider appears on the national trusted list. Qualified providers are then audited at least every 24 months (Article 20).
Regulation (EU) 2024/1183 entered into force on 20 May 2024. It introduced European Digital Identity Wallets and added trust services such as electronic attestations of attributes, electronic archiving, electronic ledgers and managing remote signature and seal creation devices.
ETSI EN 319 421 and EN 319 422. EN 319 421 sets policy and security requirements for providers issuing time-stamps. EN 319 422 profiles the RFC 3161 protocol. Regulation (EU) 2025/1929 applies both, with adaptations, to qualified electronic time stamps.
No. DictaLabs has offices in Lahore, Pakistan and Middletown, Delaware, USA. Clients in Europe can contact either office or email info@dictalabs.com.
Sources
Official sources
- Regulation (EU) No 910/2014 (eIDAS), EUR-Lex
- Regulation (EU) 2024/1183 (eIDAS 2.0), EUR-Lex
- Commission Implementing Regulation (EU) 2025/1929, Publications Office of the EU
- EU trusted list browser, European Commission
- EU trusted lists, European Commission (Shaping Europe’s digital future)
- ETSI EN 319 401, General Policy Requirements for Trust Service Providers
- ETSI EN 319 411-1, TSPs issuing certificates, Part 1: General requirements
- ETSI EN 319 411-2, TSPs issuing EU qualified certificates
- ETSI EN 319 421, TSPs issuing Time-Stamps
- ETSI EN 319 422, Time-stamping protocol and time-stamp token profiles
- ETSI EN 319 403-1, Requirements for conformity assessment bodies assessing TSPs
- ETSI EN 319 122-1, CAdES digital signatures
- ETSI EN 319 132-1, XAdES digital signatures
- ETSI EN 319 142-1, PAdES digital signatures
Preparing a trust service in Europe?
Talk to us about CP/CPS, audit readiness, timestamping or post-quantum planning. Email info@dictalabs.com or contact either office.
