Qualified TSP Provider eIDAS: Understanding the Role of Trust Services
Trust Service Providers (TSPs) are at the heart of the eIDAS Regulation. Discover their obligations, qualification process and impact on the legal value of your signatures.
Writer — Certyneo · About Certyneo

Introduction
Since the entry into force of eIDAS Regulation No. 910/2014, Trust Service Providers (TSPs) have formed the backbone of digital trust in Europe. These actors, subject to strict regulation, issue certificates, time stamps and qualified signatures that give legal force to electronic exchanges. With the adoption of eIDAS 2.0 Regulation (EU Regulation 2024/1183), their obligations have evolved further. This article explains what a TSP is, how it is accredited, what services it can offer, and why choosing a qualified provider is decisive for your business.
---
What is a Trust Service Provider (TSP)?
Definition and regulatory scope
According to Article 3 of the eIDAS Regulation, a Trust Service Provider is a natural or legal person that provides one or more trust services, either on a qualified basis or on a non-qualified basis. The Regulation clearly distinguishes between these two categories: only qualified providers benefit from the presumption of conformity and the enhanced legal value attached to their services.
Trust services covered by eIDAS include:
- Creation, verification and validation of electronic signatures (simple, advanced or qualified)
- Creation, verification and validation of electronic seals (for legal entities)
- Creation, verification and validation of qualified electronic time stamps
- Qualified electronic registered mail services
- Issuance and management of certificates for website authentication (QWAC)
- Long-term preservation of qualified signatures and seals
Since eIDAS 2.0, the scope has expanded to include European digital identity wallets (EUDIW) and qualified electronic attribute attestations, further strengthening the TSP's scope of intervention.
The distinction between qualified and non-qualified TSP
Not all trust service providers carry the same legal weight. A non-qualified TSP may operate freely, but its services carry no legal presumption of conformity. A qualified TSP (QTSP, Qualified Trust Service Provider) is listed on the national trust list supervised (Trusted List) by its Member State, published and maintained in accordance with Article 22 eIDAS and Implementing Decision 2015/1505.
In France, it is ANSSI (Agence nationale de la sécurité des systèmes d'information – National Agency for Information Systems Security) that acts as the supervision body (Article 17 eIDAS). The French trust list is accessible via the centralised European portal. For further information on the hierarchy of signature levels and their recognition, see our complete guide to eIDAS 2.0 Regulation.
---
The TSP qualification process
Compliance audit by a conformity assessment body
To obtain qualified status, a provider must submit to an audit conducted by an accredited conformity assessment body (CAB) accredited by COFRAC in France (or the equivalent body in each Member State). This audit verifies compliance with the requirements of Annex II of eIDAS (for qualified certificates) and applicable ETSI standards.
The main applicable technical standards are:
- ETSI EN 319 401: General requirements for TSPs
- ETSI EN 319 411-1 and -2: Certification policy and certification practice statement for qualified certificates
- ETSI EN 319 421: Policy and practices for time-stamp service providers
- ETSI EN 319 132: XAdES profile for advanced and qualified signatures
- ETSI EN 319 122: CAdES profile
The audit results in an evaluation report submitted to the national supervision body, which may grant, refuse or withdraw the qualification. The validity period of a qualification certificate is generally 24 months, renewable.
The European Trusted List: the reference register
The European Trust List (EU Trusted List, or TL) is the central mechanism by which eIDAS guarantees cross-border interoperability. Each Member State publishes its national list, and the European Commission aggregates them in the List of Trusted Lists (LOTL). This pyramidal structure allows any verification system to trace back to the European root of trust.
As at 1 January 2026, the LOTL lists over 200 qualified TSPs across all Member States, collectively issuing millions of qualified certificates per year. For a SaaS solution buyer, verifying that a provider is listed is the first due diligence step to take.
Ongoing monitoring obligations
Qualification is not acquired permanently. Qualified TSPs are subject to:
- Periodic audits (at least every 24 months)
- Notification without delay of any security incidents affecting services (Article 19 eIDAS)
- Maintaining an up-to-date certification policy (CP) and certification practice statement (CPS) that are public
- Maintaining a business continuity plan and a service cessation plan guaranteeing data preservation in case of closure
---
Qualified services and their legal scope
Qualified electronic signature (QES)
The qualified electronic signature is the highest level provided for by eIDAS. It is based on a qualified certificate issued by a QTSP and is created using a qualified electronic signature creation device (QSCD), such as a Common Criteria EAL4+-certified smart card or an HSM (Hardware Security Module) compliant with protection profile EN 419 221-5.
Article 25§2 of eIDAS establishes the principle of equivalence with handwritten signatures: a QES produced in one Member State is recognised in all Member States without any additional formality. This is the only level to which this automatic legal presumption applies. For further information on the legal value of electronic signatures in different contractual contexts, we have produced a dedicated guide.
Qualified electronic time stamp
The qualified electronic time stamp (QTS, Qualified Time Stamp) certifies infallibly that a document or data existed at a specific moment in time. Under Article 41 eIDAS, it benefits from a presumption of accuracy of date and time, as well as data integrity.
Typical uses include: proof of patent filing, evidential archiving, logging of contractual events. The qualified electronic time stamp also plays a central role in long-term preservation of signatures.
Qualified electronic registered mail service
The qualified REMS (Qualified Electronic Registered Mail Service) is the digital equivalent of recorded mail with acknowledgement of receipt. It guarantees identification of the parties, integrity of transmitted data, time-stamping of sending and receipt. Article 44 eIDAS grants it a presumption of data integrity and accuracy of the date and time of sending and receipt. This service is particularly useful for formal notices, contract terminations or legal notifications.
---
Choosing your TSP provider: key criteria
Qualification, interoperability and geographic coverage
The first criterion is obviously the presence on the Trusted List of the Member State or States in which you operate. But beyond formal qualification, several practical dimensions come into play:
- Interoperability: does the TSP support standard ETSI formats (XAdES, PAdES, CAdES, JAdES)? Will signatures produced be verifiable by third-party tools such as the European DSS validator?
- Service availability: what is the guaranteed SLA? Are QSCD infrastructures geographically redundant?
- Geographic coverage: if you operate in multiple European countries, does the TSP offer qualified certificates recognised in those countries?
- APIs and integration: are REST/SOAP APIs well documented? Is there an SDK or native integration with your application stack?
Pricing transparency and business model
Qualified TSPs typically charge per certificate issued, per transaction volume or through annual subscriptions. Prices vary considerably: an individual qualified certificate costs between €50 and €200 per year, while mass signature solutions (server) can exceed several thousand euros per year. Compare market offerings with our comparison of electronic signature solutions.
Support, GDPR compliance and data location
A TSP processing personal data (which is systematically the case for the issuance of qualified certificates) is subject to GDPR Regulation No. 2016/679. Check:
- The location of data (EU hosting or outside EU?)
- Data retention and deletion policies
- The existence of a designated Data Protection Officer (DPO)
- Any subcontracting and applicable Standard Contractual Clauses (SCCs)
For businesses wishing to migrate from an existing solution to a more compliant provider, our guide on migration from DocuSign or YouSign to Certyneo details the steps and precautions to take.
Legal framework applicable to eIDAS TSP providers
Founding texts
The legal framework for trust service providers is built on several regulatory layers articulated together.
eIDAS Regulation No. 910/2014/EU (amended by EU Regulation 2024/1183 known as "eIDAS 2.0"): the reference text defining trust services, qualification levels, TSP obligations (Articles 13 to 22 for general obligations, Articles 23 to 45 for specific qualified services) and the liability regime (Article 13: liability for any damage caused intentionally or through negligence, with reversal of the burden of proof in favour of the victim).
French Civil Code, Articles 1366 and 1367: Article 1366 establishes the principle of equivalence of electronic writing to writing on paper, subject to identification of the author and integrity. Article 1367 defines electronic signature and its presumption of reliability when qualified within the meaning of eIDAS.
Decree No. 2017-1416 of 28 September 2017 on electronic signatures: clarifies the technical conditions for reliable electronic signatures under French law, explicitly referring to eIDAS requirements.
Security and notification obligations
Article 19 of eIDAS requires TSPs to implement appropriate technical and organisational measures to manage risks to their services. In the event of a security incident or loss of integrity having a significant impact on the service or personal data, the TSP must notify the supervision body without undue delay and at the latest within 24 hours of becoming aware of it. This obligation is cumulative with that provided for in Article 33 of GDPR Regulation No. 2016/679 (notification to the supervisory authority – CNIL in France – within 72 hours).
The NIS2 Directive (2022/2555/EU), transposed into French law by Law No. 2023-703 of 1 August 2023, subjects qualified TSPs to strengthened requirements for cyber risk management and incident notification, as essential or important entities depending on their size.
Liability and sanctions
The eIDAS liability regime (Article 13) is stringent: the TSP is presumed liable for any damage caused to any natural or legal person by a breach of its obligations. It is for the TSP to prove the absence of fault. National penalties for non-compliance may include withdrawal of qualification, administrative fines (up to €10 million or 2% of worldwide turnover under GDPR), and civil liability actions. In France, ANSSI may also impose corrective measures.
Use cases: eIDAS TSP in practice
A law firm managing dematerialised court documents
A large law firm with around fifty lawyers handles daily legal documents requiring a qualified signature: submissions, powers of attorney, business transfer documents. By relying on a QTSP listed on the French Trusted List, the firm generates PAdES-LTV signatures (Long-Term Validation) incorporating a qualified time stamp. Result: the turnaround time for a signable document falls from 3 to 4 days (paper exchange) to less than 2 hours. The evidentiary value of each signature is automatically verifiable by the opposing party and by courts, without further expert review, reducing procedural disputes by around 70% according to field feedback from comparable firms.
An SME securing cross-border supplier contracts
A French industrial SME with around 180 employees, sourced from suppliers in Germany, Poland and Spain, previously had to have certain contracts legalised or apostille-stamped to guarantee cross-border recognition. By integrating via API a qualified TSP delivering certificates recognised throughout the EU (Article 25§2 eIDAS), the SME eliminates these formalities. The 300 supplier contracts signed annually are now electronically signed with automatic legal recognition in the three partner countries. The estimated saving in administrative costs and processing time reaches 35 to 45% over the entire contract cycle, consistent with ranges published in sector studies by the Federation of Mechanical Industries.
A hospital group preserving the integrity of its digital medical records
A hospital group with around 1,200 beds must guarantee the integrity and authenticity of its operating reports, prescriptions and informed consents over retention periods of up to 20 years (Article R. 1112-7 of the French Public Health Code). By using a qualified electronic time-stamping service provided by a QTSP, the group creates infallible proof of integrity from the moment the document is produced. Internal audits and HAS (French Health Authority) inspections can now automatically verify the integrity of each archived document, reducing the workload of quality assurance teams by around 25% according to healthcare sector benchmarks.
Frequently asked questions
What is a qualified trust service provider under eIDAS?
A qualified trust service provider (QTSP) is an organisation that has obtained qualified status from the supervision body of its Member State (ANSSI in France), following a compliance audit by an accredited body. It is listed on the national trust list published in accordance with Article 22 of eIDAS. This status allows it to provide services with a legal presumption of conformity: qualified signatures, qualified time stamps, qualified seals, qualified electronic registered mail services.
How do I verify that a TSP provider is genuinely qualified under eIDAS?
Verification is carried out via the official European Commission portal "eIDAS Trusted List Browser" (tlbrowser.tsl.website) or via the ANSSI portal for French providers. Simply search for the provider's name or service URL. The list is updated in real time. Any provider claiming to be qualified without appearing on this list does not benefit from any legal presumption attached to qualified eIDAS services.
Is a qualified TSP in one European country recognised throughout the EU?
Yes. This is one of the fundamental contributions of eIDAS: the principle of mutual cross-border recognition (Article 25§2 for signatures, Article 35§2 for seals, Article 41§2 for time stamps). An electronic signature qualified using a certificate issued by a French QTSP is legally recognised in Germany, Spain, Poland or any other Member State, without any additional step. This interoperability is the main purpose of the eIDAS Regulation at the European level.
What is the difference between a qualified certificate and an advanced certificate?
An advanced certificate can be issued by any provider, qualified or not, according to minimum technical requirements. A qualified certificate can only be issued by a QTSP listed on the Trusted List, on the basis of Annex I of eIDAS (certificate content) and after rigorous identity verification of the applicant in person or via a qualified remote identification process (QES). The qualified certificate is the necessary condition for issuing a qualified electronic signature, the only one to benefit from the presumption of equivalence with a handwritten signature.
Can a TSP lose its eIDAS qualification? What are the consequences?
Yes. The supervision body may withdraw or suspend a TSP's qualification in case of serious breach of its obligations (negative audit, major unresolved security incident, false declaration). Withdrawal is published on the Trusted List with a "revoked" status. Certificates issued before revocation remain valid if their trust chain is preserved in compliant evidential archiving. However, no new qualified certificate can be issued after revocation, and services provided cease to benefit from eIDAS legal presumptions.
Conclusion
Trust Service Providers (TSPs) are far more than mere technical suppliers: they constitute the regulatory and legal foundation on which all the evidentiary value of electronic signatures in Europe rests. Understanding their role, qualification process and obligations is essential for any organisation wishing to secure its digital exchanges with undisputed legal value. The choice of a QTSP listed on the European Trusted List is not optional as soon as you aim for qualified signatures or qualified time stamps.
Certyneo relies exclusively on qualified TSPs recognised under eIDAS to guarantee you electronic signatures with full legal value, interoperable throughout the European Union. Ready to secure your contractual workflows? Create your Certyneo account free of charge or contact our team for a personalised demonstration.
Try Certyneo for free
Send your first signature envelope in less than 5 minutes. 5 envelopes/mo for 14 days, then 2/mo, no credit card required.
Go deeper into this topic
Reference articles on this topic.
Go deeper into this topic
Our comprehensive guides to master electronic signatures.
Certyneo Community
A question about electronic signatures?
Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.
Recommended articles
Deepen your knowledge with these related articles.

QSCD Certificate eIDAS: Everything You Need to Know to Obtain One in France in 2026
The QSCD certificate is the cornerstone of qualified electronic signatures in Europe. Discover its definition, legal framework and concrete steps to obtain one in France.

QES, AES and SES: Understanding the Three Levels of eIDAS Electronic Signature in 2026
The eIDAS regulation distinguishes three levels of electronic signature with very different legal values. Mastering these distinctions is essential to secure your contracts in 2026.

Health Data Protection and GDPR Compliance for Healthcare Professionals
Health data represents the most sensitive personal information under the GDPR. Discover all the obligations that apply to healthcare sector professionals in 2026.