QSCD Certificate eIDAS: Everything You Need to Know to Obtain It in France in 2026
The QSCD certificate is the cornerstone of qualified electronic signature in Europe. Discover its definition, legal framework and concrete steps to obtain it in France.
Writer — Certyneo · About Certyneo

The growing adoption of digital transformation is compelling businesses and government agencies to master precise technical concepts. Among these, the QSCD certificate (Qualified Signature Creation Device) occupies a central place within the eIDAS framework. Without it, no qualified electronic signature — the only type carrying a legal presumption of value equivalent to a handwritten signature — can be issued. Yet the vast majority of French organisations still do not understand what a QSCD is, how it differs from a simple digital certificate, and what steps allow them to obtain it. This article provides you with a complete answer: technical definition, regulatory foundations, a list of accredited actors in France and the step-by-step obtaining process.
What is a QSCD certificate? Definition and regulatory scope
The term QSCD is the English acronym for Qualified Signature Creation Device. It designates a hardware or software tool that generates and stores the cryptographic keys used for electronic signing, whilst guaranteeing a maximum level of security defined by the eIDAS Regulation No. 910/2014.
Distinction between qualified certificate and QSCD
It is important to distinguish between two concepts that are often confused:
- The qualified certificate (Qualified Certificate for Electronic Signature, QCert) is a digital certificate issued by a qualified trust service provider (QTSP). It attests to the identity of the signatory and contains their public key.
- The QSCD is the secure medium on which the private key associated with the certificate is generated and stored. This may be a cryptographic USB token, a smart card, an HSM (Hardware Security Module) or a remote QSCD (remote QSCD) hosted by the service provider.
For a signature to be qualified under eIDAS, both elements must be present: a qualified certificate AND a QSCD. Annex II of the regulation sets out the requirements that the device must meet (uniqueness of signature creation data, impossibility of deducing the private key, protection against falsification, etc.).
Levels of electronic signature and the place of QSCD
The eIDAS regulation defines three levels of signature:
- Simple electronic signature (SES): no specific technical requirement.
- Advanced electronic signature (AdES): linked uniquely to the signatory, created from data under their exclusive control, but without the obligation to use a QSCD.
- Qualified electronic signature (QES): imperatively requires a qualified certificate stored on a QSCD. It is the only level benefiting from a legal presumption of equivalence to a handwritten signature in all member states.
To deepen the differences between these three levels, the comparison of electronic signature solutions from Certyneo offers a detailed analysis.
Qualified service providers (QTSP) in France: who can issue a QSCD?
In France, the issuance of qualified certificates and the provision of QSCDs are exclusively the responsibility of qualified trust service providers (QTSP) registered on the national trust list (Trust Service List, TSL), published and maintained by the ANSSI (Agence nationale de la sécurité des systèmes d'information — National Cyber Security Agency).
ANSSI, the French supervisory authority
ANSSI plays the role in France of supervisory body (supervisory body) provided for in Article 17 of eIDAS. It audits QTSP candidates according to strict criteria aligned with the standards ETSI EN 319 401 (general requirements for trust service providers) and ETSI EN 319 411 (qualified certificates). A provider cannot claim to be "qualified" without being listed on the French trust list published in signed XML format.
Among the accredited French QTSPs are notably actors such as Certigna, CertEurope, Docaposte, Keynectis and Thales (formerly Gemalto). Each offers qualified certificate solutions stored on hardware QSCDs (smart cards, USB tokens) or remote QSCDs, the latter showing strong growth since 2022.
Remote QSCD (remote QSCD): the new standard in enterprise
The remote QSCD represents a major evolution: the signatory's private key is no longer stored on a physical medium provided to the user, but in a certified HSM, hosted in the secure infrastructure of the QTSP. The signatory accesses their device via strong authentication (OTP, biometrics, mobile application). This approach, governed by the ETSI EN 319 432 standard and validated by ANSSI, is now integrated into most SaaS qualified signature platforms, including Certyneo.
The legal value of electronic signature does not depend on the physical or remote nature of the QSCD, as long as eIDAS compliance is attested by an ANSSI qualification.
How to obtain a QSCD certificate in France: the step-by-step process
Obtaining a qualified certificate on QSCD follows a formalised process, more demanding than that for a simple or advanced certificate. Here are the essential steps.
Step 1: Choose your QTSP and type of QSCD
The first decision concerns the type of QSCD desired:
- Physical QSCD (smart card or USB token): suitable for occasional use, freelance professionals or executives. Involves physical delivery of the medium.
- Remote QSCD: ideal for organisations signing at high volume or in a completely digital mode. No physical medium to manage.
The choice of provider also depends on the available integrations (REST API, webhooks, HRIS connectors) and the level of support. It is advisable to consult the official list of QTSPs on the ANSSI portal before making any decision.
Step 2: The identity verification process (KYC)
The eIDAS regulation imposes rigorous identity verification before issuing a qualified certificate. Two modalities are accepted:
- In-person, face-to-face (in-person): the applicant presents themselves at a registration point of the QTSP or to a mandated verification operator, with their official identity documents.
- Remote via video (remote identity proofing): since 2021, some QTSPs offer verification by videoconference in real time with an agent, governed by the requirements of ETSI EN 319 461. Automated verification by AI (eKYC) is not yet permitted for qualified certificates in France as of mid-2026, with ANSSI still requiring human intervention.
The required documents generally include: a valid identity document (national ID card, passport), proof of connection to the professional entity (Kbis, RCS extract), and sometimes a letter of mandate for signatories acting on behalf of a legal entity.
Step 3: Key generation and delivery of the QSCD
Once the identity is verified, the QTSP proceeds to generate the cryptographic key pair in the secure environment of the QSCD. For a physical QSCD, the medium is initialised and then delivered or sent to the holder with a secure PIN code. For a remote QSCD, the holder activates their device via the service provider's mobile application and configures their strong authentication mechanism.
The qualified certificate is then associated with the public key and published in the QTSP's directory. Its validity period is generally 1 to 3 years, depending on the subscription offer. Renewal must be anticipated before expiration to maintain continuity of signing capability.
Cost, timelines and renewal: what you need to anticipate
Indicative pricing schedule for 2026
The prices of qualified certificates on QSCD vary significantly depending on the service provider and the type of device:
- Physical QSCD (USB token or card): between €80 and €250 excl. VAT for the first issuance (including the hardware medium), then €50 to €150 excl. VAT for annual renewal.
- Remote QSCD: often integrated into SaaS subscription offers starting from €15 to €40 excl. VAT per user per month, or in per-transaction packs for low volumes.
These costs must be weighed against the time savings and reduction in legal risks. The ROI calculator from Certyneo allows you to precisely estimate the return on investment based on the volume of signed documents.
Obtaining timelines
The time between application and the effective availability of the qualified certificate is generally 3 to 10 working days for physical solutions (including postal delivery) and a few hours to 48 hours for remote QSCDs, subject to the completeness of the KYC file. Organisations anticipating peaks in activity (contract renewals at the end of the financial year, calls for tender, account closures) must plan accordingly.
Revocation and certificate lifecycle
A qualified certificate may be revoked before its term in the event of compromise of the private key, departure of the holder or change of certified information. Revocation is published in the Certificate Revocation List (CRL) or via the QTSP's OCSP protocol (Online Certificate Status Protocol). Any signature affixed after revocation is deemed invalid; those affixed before revocation retain their value, provided they are time-stamped. The qualified electronic time-stamping plays a crucial role here in proving the anteriority of a signature.
Legal framework applicable to the QSCD certificate
The regulation governing qualified signature creation devices is extensive and articulated between several European and national texts.
eIDAS Regulation No. 910/2014 (EU) — This founding text is the cornerstone of the system. Article 3(12) defines the qualified signature creation device. Article 26 sets out the requirements for advanced signature, whilst Article 29 and Annex II detail the technical requirements applicable to QSCDs (uniqueness of signature creation data, confidentiality of the private key, non-falsifiability). Article 25(2) confers on qualified signature a presumption of equivalence with a handwritten signature. The eIDAS 2.0 regulation (Regulation 2024/1183, which came into force progressively from 2024) strengthens these requirements and expands the scope to European digital identity wallets (EUDIW).
French Civil Code, Articles 1366 and 1367 — Article 1366 provides that electronic writing has the same probative force as paper writing subject to reliable identification of the author and integrity of the document. Article 1367 specifies that electronic signature consists in the use of a reliable identification process guaranteeing the link with the signed document. Decree No. 2017-1416 of 28 September 2017 establishes the presumption of reliability for qualified signatures compliant with eIDAS.
ETSI standards — The standards ETSI EN 319 132 (XAdES format for XML signature), ETSI EN 319 122 (CAdES), ETSI EN 319 162 (ASiC) and ETSI EN 319 401/411 (requirements for trust service providers and qualified certificates) constitute the technical reference applicable to service providers. Non-compliance with these standards may result in suspension of QTSP qualification by ANSSI.
GDPR No. 2016/679 — The identity verification process (KYC) involves the processing of biometric data and personal data. The data controller (QTSP and, where applicable, the client company) must comply with the principles of minimisation, limited purpose and provide for a retention period proportionate to the purpose. A DPIA (Data Protection Impact Assessment) is recommended for large-scale deployments.
Liability for non-compliance — The use of a non-qualified certificate to sign documents requiring a qualified signature (certain public procurement, electronic notarial documents, dematerialised tax declarations) exposes the organisation to a challenge to the probative value of the document, or even to its nullity. Article 13 of eIDAS provides for a liability regime for QTSPs in the event of breach of their obligations, but this regime does not relieve user companies of their duty of care in the choice and maintenance of their system.
Use cases for QSCD certificates in business
Scenario 1: a law firm dematerialising its procedural documents
A law firm with around fifteen staff members handles several hundred procedural documents, mandates and fee agreements each year. Before deploying a remote QSCD-based solution, each document required printing, handwritten signature and postal delivery or scanning. The firm opted for qualified certificates on remote QSCDs integrated into a SaaS platform, allowing each partner to sign from their desk or mobile device at the qualified level. Result observed: approximately 70% reduction in the time taken to sign amicable severance agreements (from 4 days to less than 24 hours on average), elimination of postage costs and automatic archiving of signed documents in the firm's document management system.
Scenario 2: a manufacturing SME managing its supplier contracts
A manufacturing SME processing around 300 supplier contracts per year faced recurring legal risks associated with simple or scanned signatures, easily contestable. After an audit, it emerged that several contracts worth over €100,000 had been signed without a reliable identification process. The migration to qualified signatures on remote QSCD for high-stakes contracts (strategic suppliers, confidentiality agreements, framework orders) made it possible to secure the contractual assets. The time taken to validate contracts fell by around 60%, with foreign counterparts appreciating the immediate cross-border recognition offered by eIDAS.
Scenario 3: a hospital group deploying qualified signature for its public procurement
A hospital group of around 900 beds had to comply with the obligation, arising from Decree No. 2016-360 on public procurement, to sign electronically the documents of engagement above certain thresholds. The IT department deployed certified USB tokens with QSCD for directors authorised to commit the establishment. Training for users, integration into the public procurement dematerialisation platform and the annual renewal procedure were documented in an internal signature policy (Signature Policy). The estimated operational gain is in the order of 3 to 4 days per procurement procedure, thanks to the elimination of registered mail deliveries and the shuttling of physical approval documents.
Frequently asked questions
What distinguishes a QSCD from a standard HSM?
An HSM (Hardware Security Module) is a generic hardware security module used to store and manage cryptographic keys. A QSCD is an HSM — or any other secure device — that has been evaluated and certified as compliant with the requirements of Annex II of eIDAS Regulation by an accredited laboratory recognised by a national supervisory authority. QSCD qualification attests that the device meets strict criteria for key uniqueness, non-exportability and resistance to physical and logical attacks.
Is a QSCD certificate obtained in France valid throughout the European Union?
Yes. Article 25(2) of eIDAS establishes a mandatory mutual recognition of qualified signatures between all member states. A qualified certificate issued by a French QTSP registered on the national trust list produces the same legal effects in Germany, Spain or Italy as in its country of issuance. This automatic recognition is one of the major advantages of the system for businesses with cross-border contractual activities.
What is the validity period of a QSCD certificate and can it be renewed remotely?
The validity period of a qualified certificate is generally set at 1, 2 or 3 years depending on the QTSP's offer. Renewal can be carried out remotely for remote QSCDs, provided that the identity of the holder has already been verified face-to-face or by video during the initial issuance. Most QTSPs send expiration alerts 60 and 30 days before the deadline. Ignoring these alerts exposes you to an interruption in your qualified signing capability.
Is a QSCD certificate mandatory for all electronically signed documents?
No. The level of signature required depends on the nature of the document and the applicable regulatory framework. Qualified signature on QSCD is mandatory for certain specific documents (electronic notarial documents, certain public procurement, dematerialised tax declarations). For the majority of ordinary commercial contracts, an advanced signature is sufficient. It is recommended to consult the electronic signature glossary or seek legal advice to determine the required level document by document.
How do I verify that a signature is indeed based on a valid QSCD certificate?
Verification is carried out by consulting the metadata of the signed document using a validation tool compliant with ETSI specifications, such as the DSS (Digital Signature Service) service of the European Commission, available free of charge. This tool verifies the certificate's chain of trust, its status (not revoked), its compliance with the qualified profile and the presence of a qualified time-stamp. Some SaaS platforms like Certyneo integrate this validation report directly into the document management interface.
Conclusion
The QSCD certificate is far more than a technical formality: it is the legal and cryptographic foundation of qualified electronic signature, the only level offering a legal presumption of equivalence to a handwritten signature throughout the European Union. In France, obtaining it involves going through a QTSP accredited by ANSSI, a rigorous identity verification process and an informed choice between physical QSCD and remote QSCD — the latter becoming the standard for organisations seeking agility and scalability.
Certyneo natively integrates certified remote QSCDs into its SaaS platform, allowing your teams to sign at the qualified level without any physical medium to manage. Whether you are starting from scratch or migrating from another solution, our experts support you at every step. Discover Certyneo pricing or contact our team for an audit of your qualified signature needs.
Try Certyneo for free
Send your first signature envelope in less than 5 minutes. 5 envelopes/mo for 14 days, then 2/mo, no credit card required.
Dive deeper
Reference articles on this topic.
Dive deeper
Our comprehensive guides to master electronic signatures.
Recommended articles
Deepen your knowledge with these articles related to the topic.

QES, AES, and SES: Understanding the Three Levels of eIDAS Electronic Signature in 2026
The eIDAS regulation distinguishes three levels of electronic signature with vastly different legal values. Mastering these distinctions is essential to secure your contracts in 2026.

Healthcare Data Protection and GDPR Compliance for Professionals
Healthcare data is the most sensitive personal data under GDPR. Discover all the obligations that apply to healthcare sector professionals in 2026.

VAT 2026: Calculation, Declaration and New Obligations for Businesses
The VAT reform 2026 transforms the calculation and declaration rules for millions of French businesses. Master the new obligations before they apply to you.