eIDAS-Aligned PKI & Trust Service Consulting for Europe

DictaLabs is a PKI, digital signature and certificate management company with offices in Lahore, Pakistan and Middletown, Delaware, USA. For Europe, we offer eIDAS-aligned PKI and trust service consulting and products designed around ETSI standards; clients can contact either office or email info@dictalabs.com.

EU law

How eIDAS regulates trust services

eIDAS sets EU-wide rules for electronic identification and trust services. Regulation (EU) No 910/2014 applies from 1 July 2016. Regulation (EU) 2024/1183, often called eIDAS 2.0, amended it and entered into force on 20 May 2024.

Qualified status

Article 3(20) defines a qualified trust service provider as one that provides qualified trust services “and is granted the qualified status by the supervisory body”. Under Article 25, a qualified electronic signature has “the equivalent legal effect of a handwritten signature”.

What eIDAS 2.0 added

Trust services now include managing remote signature and seal creation devices, electronic attestations of attributes, electronic archiving and electronic ledgers. Article 5a requires each Member State to provide at least one European Digital Identity Wallet.

Audits and supervision

Under Article 20, qualified providers are audited “at least every 24 months by a conformity assessment body”. Since eIDAS 2.0, the audit also covers Article 21 of the NIS 2 Directive (EU) 2022/2555. Providers must inform the supervisory body at least one month before a planned audit.

Trusted lists

Each Member State must “establish, maintain and publish trusted lists” of qualified providers and their services (Article 22). Search them in the EU trusted list browser or read the Commission’s trusted lists page.

ETSI standards

Relevant ETSI standards include:

  • EN 319 401: general TSP requirements
  • EN 319 411-1 and -2: certificate issuers and EU qualified certificates
  • EN 319 421 and 319 422: timestamping
  • EN 319 122, 319 132 and 319 142: CAdES, XAdES and PAdES signatures
  • EN 319 403-1: conformity assessment bodies

Qualified timestamps

Implementing Regulation (EU) 2025/1929 of 29 September 2025 sets the reference standards for qualified electronic time stamps. Its Annex applies ETSI EN 319 421 V1.3.1 and EN 319 422 V1.1.1, with adaptations.

This page is general information, not legal advice.

TSP readiness

How DictaLabs helps you prepare to become a trust service provider

DictaLabs helps organisations prepare to become trust service providers, including qualified ones. Only the supervisory body can grant qualified status. Under Article 21, you notify your supervisory body with a conformity assessment report. If you comply, it grants qualified status and the national trusted list is updated. It must explain any delay beyond three months.

A review of your current setup against eIDAS and the relevant ETSI requirements, with a prioritised list of gaps.

Architecture for CA hierarchies, HSM-backed keys and the trust services built on them.

Certificate policies and practice statements structured on RFC 3647, written to match how you actually operate.

Preparation for the conformity assessment against eIDAS and ETSI requirements, before the conformity assessment body arrives.

Readiness support for Common Criteria (ISO/IEC 15408) evaluations, where your products need them.

Products

DictaLabs products for trust service projects

These products support trust service projects. DictaLabs TSA is designed around ETSI EN 319 421/422. Using any product does not by itself make a service qualified.

Timestamping designed around RFC 3161, RFC 5816 and ETSI EN 319 421/422, the ETSI standards that Regulation (EU) 2025/1929 references.

An HSM-backed certificate authority platform with RFC 5280 certificate and CRL profiles and OCSP.

Digital signatures and signing workflows for documents and approvals.

A central HSM-backed cryptographic service with REST APIs, for Thales Luna, Entrust nShield, Utimaco CryptoServer, AWS CloudHSM and Azure Key Vault/Managed HSM.

Certificate lifecycle management across multiple CA platforms, with ACME, SCEP and EST.

See how RFC 3161 timestamping works.

Use cases

Typical use cases in Europe

These are typical scenarios, not customer case studies.

A company that plans to issue qualified certificates prepares CP/CPS documents. It runs a gap analysis against ETSI EN 319 401 and 319 411 and plans its conformity assessment.

An organisation sets up a timestamping service and aligns it with ETSI EN 319 421/422 from the start.

eIDAS 2.0 lists managing remote signature and seal creation devices as a trust service. Providers planning remote signing need a design for HSM-backed key management.

Issuing certificates for staff, systems or devices under a documented CP/CPS, with lifecycle automation.

Inventory algorithms and keys now. Then plan how CAs, signatures and timestamps will move to post-quantum cryptography.

Contact

How to work with DictaLabs from Europe

DictaLabs has no office in the EU. Clients in Europe can contact either of our offices or email info@dictalabs.com.

Write to info@dictalabs.com with a short description of your project.

26 Block G4 Rd, Phase 2, Johar Town, Lahore, Punjab, Pakistan.

651 N Broad St, Suite 201, Middletown, DE 19709, USA. Phone +1 352-451-6005.

A no-cost starting point before a PKI or trust service project.

Tell us your Member State, the trust services you plan and your timeline.

FAQ

Frequently asked questions

Can DictaLabs help us become a QTSP?

Yes, with preparation. We help with PKI architecture, CP/CPS documents based on RFC 3647, gap analysis and audit readiness against eIDAS and ETSI requirements. Only your national supervisory body can grant qualified status, after a conformity assessment.

How does a provider get qualified status?

It notifies its supervisory body and submits a conformity assessment report (Article 21). If the requirements are met, the body grants qualified status and the provider appears on the national trusted list. Qualified providers are then audited at least every 24 months (Article 20).

What changed with eIDAS 2.0?

Regulation (EU) 2024/1183 entered into force on 20 May 2024. It introduced European Digital Identity Wallets and added trust services such as electronic attestations of attributes, electronic archiving, electronic ledgers and managing remote signature and seal creation devices.

Which ETSI standards apply to timestamping?

ETSI EN 319 421 and EN 319 422. EN 319 421 sets policy and security requirements for providers issuing time-stamps. EN 319 422 profiles the RFC 3161 protocol. Regulation (EU) 2025/1929 applies both, with adaptations, to qualified electronic time stamps.

Does DictaLabs have an office in Europe?

No. DictaLabs has offices in Lahore, Pakistan and Middletown, Delaware, USA. Clients in Europe can contact either office or email info@dictalabs.com.

Preparing a trust service in Europe?

Talk to us about CP/CPS, audit readiness, timestamping or post-quantum planning. Email info@dictalabs.com or contact either office.