Skip to main content
Certyneo

eIDAS Qualified Trust Service Provider: Understanding the Role of Trust Services

Qualified Trust Service Providers (TSP) are at the heart of the eIDAS Regulation. Discover their obligations, qualification process and impact on the legal value of your signatures.

Certyneo Editorial Team13 min read
a person sitting at a table with a laptop

Introduction

Since the entry into force of eIDAS Regulation No. 910/2014, qualified trust service providers (TSP, Trust Service Providers) have formed the backbone of digital trust in Europe. These actors, subject to strict regulation, deliver the certificates, time stamps and qualified signatures that give legal force to electronic transactions. With the adoption of eIDAS 2.0 Regulation (EU Regulation 2024/1183), their obligations have evolved further. This article explains what a TSP is, how it is accredited, what services it can offer, and why choosing a qualified provider is crucial for your business.

---

What is a Trust Service Provider (TSP)?

Definition and regulatory scope

According to Article 3 of the eIDAS Regulation, a qualified trust service provider is a natural or legal person that provides one or more trust services, either on a qualified basis or on a non-qualified basis. The Regulation clearly distinguishes between these two categories: only qualified providers benefit from the presumption of conformity and the enhanced legal value attached to their services.

Trust services covered by eIDAS include:

  • Creation, verification and validation of electronic signatures (basic, advanced or qualified)
  • Creation, verification and validation of electronic seals (for legal entities)
  • Creation, verification and validation of qualified electronic time stamps
  • Electronic registered mail services
  • Issuance and management of certificates for website authentication (QWAC)
  • Long-term preservation of qualified signatures and seals

Since eIDAS 2.0, the scope has been extended to European digital identity wallets (EUDIW) and qualified electronic attribute attestations, further expanding the range of TSP services.

The distinction between qualified and non-qualified TSP

Not all trust service providers have equal legal standing. A non-qualified TSP can operate freely, but its services carry no legal presumption of conformity. A qualified TSP (QTSP, Qualified Trust Service Provider) is registered on the national trust list supervised by its Member State (Trusted List), published and maintained in accordance with Article 22 eIDAS and Implementing Decision 2015/1505.

In France, it is the ANSSI (Agence nationale de la sécurité des systèmes d'information – National Cybersecurity Agency) that acts as the supervisory body (Article 17 eIDAS). The French trust list is accessible via the centralised European portal. For more information on the hierarchy of signature levels and their recognition, please consult our complete guide to eIDAS 2.0 Regulation.

---

The TSP qualification process

Conformity audit by a conformity assessment body

To obtain qualified status, a provider must undergo an audit conducted by a conformity assessment body (CAB) accredited by COFRAC in France (or the equivalent national body in each Member State). This audit verifies compliance with the requirements of Annex II of eIDAS (for qualified certificates) and applicable ETSI standards.

The main technical reference standards are:

  • ETSI EN 319 401: general requirements for TSP
  • ETSI EN 319 411-1 and -2: certification policy and practices for qualified certificates
  • ETSI EN 319 421: policy and practices for time stamp TSP
  • ETSI EN 319 132: XAdES profile for advanced and qualified signatures
  • ETSI EN 319 122: CAdES profile

The audit results in an evaluation report submitted to the national supervisory body, which may grant, refuse or withdraw the qualification. The validity period of a qualification certificate is generally 24 months, renewable.

The European Trusted List: the reference registry

The European trust list (EU Trusted List, or TL) is the central mechanism by which eIDAS ensures cross-border interoperability. Each Member State publishes its national list, and the European Commission aggregates all of them in the List of Trusted Lists (LOTL). This pyramid structure allows any verification system to trace back to the European root of trust.

As of 1 January 2026, the LOTL lists more than 200 qualified TSPs across all Member States, collectively issuing millions of qualified certificates per year. For a buyer of a SaaS solution, verifying the presence of a provider on this list is the first due diligence step.

Obligations for ongoing supervision

Qualification is not permanent. Qualified TSPs are subject to:

  • Periodic audits (at least every 24 months)
  • Notification without delay of any security incident affecting the services (Article 19 eIDAS)
  • Maintaining updated certification policy (CP) and certification practice statement (CPS) that are public
  • Maintenance of a business continuity plan and a service cessation plan ensuring data preservation in the event of service discontinuation

---

Qualified Electronic Signature (QES)

The qualified electronic signature is the highest level provided for by eIDAS. It is based on a qualified certificate issued by a QTSP and is created using a qualified electronic signature creation device (QSCD), such as a certified smart card with Common Criteria EAL4+ or a Hardware Security Module (HSM) compliant with EN 419 221-5.

Article 25(2) of eIDAS establishes the principle of equivalence with handwritten signatures: a QES produced in one Member State is recognised in all Member States without further formality. This is the only level for which this legal presumption applies automatically. To learn more about the legal value of electronic signatures in various contractual contexts, we have dedicated a comprehensive guide.

Qualified Electronic Time Stamp

The qualified electronic time stamp (QTS, Qualified Time Stamp) unfalsifiably certifies that a document or data existed at a specific moment in time. Under Article 41 eIDAS, it benefits from a presumption of accuracy of date and time, as well as data integrity.

Typical uses include: proof of patent filing, probative archiving, logging of contractual events. The qualified electronic time stamp also plays a central role in long-term preservation of signatures.

Qualified Electronic Registered Mail Service

The qualified ERMS (Qualified Electronic Registered Mail Service) is the digital equivalent of registered mail with acknowledgement of receipt. It guarantees the identification of parties, the integrity of transmitted data, and the time stamping of sending and receipt. Article 44 eIDAS grants it a presumption of data integrity and accuracy of the date of sending and receipt. This service is particularly useful for formal notices, contract terminations or legal notifications.

---

Choosing your TSP provider: key criteria

Qualification, interoperability and geographic coverage

The first criterion is obviously presence on the Trusted List of the Member State(s) in which you operate. But beyond formal qualification, several practical dimensions come into play:

  • Interoperability: does the TSP support standard ETSI formats (XAdES, PAdES, CAdES, JAdES)? Will the signatures produced be verifiable by third-party tools such as the European DSS validator?
  • Service availability: what SLA is guaranteed? Are QSCD infrastructures geographically redundant?
  • Geographic coverage: if you operate in multiple European countries, does the TSP offer qualified certificates recognised in those countries?
  • APIs and integration: are REST/SOAP APIs well documented? Is there an SDK or native integration with your application stack?

Transparent pricing and business model

Qualified TSPs generally charge per certificate issued, per transaction volume or via annual subscriptions. Prices vary considerably: an individual qualified certificate costs between €50 and €200 excluding VAT per year, while bulk signature solutions (server) can exceed several thousand euros annually. Compare market offerings with our comparison of electronic signature solutions.

Support, GDPR compliance and data location

A TSP processing personal data (which is systematically the case for the issuance of qualified certificates) is subject to GDPR Regulation 2016/679. Verify:

  • Data location (hosting in EU or outside?)
  • Data retention and deletion policy
  • Existence of a designated Data Protection Officer (DPO)
  • Possible subcontracting and applicable standard contractual clauses (SCC)

For businesses wishing to migrate from an existing solution to a more compliant provider, our guide on migration from DocuSign or YouSign to Certyneo details the steps and precautions to take.

Founding texts

The legal framework for trust service providers rests on several regulatory layers articulated with one another.

eIDAS Regulation No. 910/2014/EU (amended by EU Regulation 2024/1183 known as "eIDAS 2.0"): the reference text defining trust services, qualification levels, TSP obligations (Articles 13 to 22 for general obligations, Articles 23 to 45 for specific qualified services) and the liability regime (Article 13: liability for any damage caused intentionally or through negligence, with reversal of the burden of proof in favour of the victim).

French Civil Code, Articles 1366 and 1367: Article 1366 establishes the principle of equivalence of electronic writing to writing on paper provided that the author is identified and the document is intact. Article 1367 defines electronic signature and its presumption of reliability when qualified within the meaning of eIDAS.

Decree No. 2017-1416 of 28 September 2017 relating to electronic signature: specifies in French law the technical conditions for reliable electronic signature, explicitly referring to eIDAS requirements.

Security and notification obligations

Article 19 of eIDAS requires TSPs to take appropriate technical and organisational measures to manage the risks to their services. In the event of a security incident or loss of integrity having a significant impact on the service or personal data, the TSP must notify the supervisory body without undue delay and, at the latest, within 24 hours of becoming aware of it. This obligation is cumulative with that provided for in Article 33 of GDPR Regulation 2016/679 (notification to the supervisory authority – CNIL in France – within 72 hours).

The NIS2 Directive (2022/2555/EU), transposed into French law by Law No. 2023-703 of 1 August 2023, subjects qualified TSPs to enhanced requirements for cyber risk management and incident notification, as essential or important entities according to their size.

Liability and sanctions

The eIDAS liability regime (Article 13) is strict: the TSP is presumed liable for any damage caused to any natural or legal person by a breach of its obligations. It is up to the TSP to prove the absence of fault. National sanctions for non-compliance may include withdrawal of qualification, administrative fines (up to €10 million or 2% of global turnover under GDPR), and civil liability actions. In France, ANSSI may also impose corrective measures.

Use cases: the eIDAS TSP in practice

A law firm managing dematerialised procedural documents

A corporate law firm with approximately fifty staff members daily handles documents requiring a qualified signature: briefs, powers of attorney, transfer deeds of business. By relying on a QTSP listed on the French Trusted List, the firm generates PAdES-LTV signatures (Long-Term Validation) integrating a qualified time stamp. Result: the time to process a signable document drops from 3 to 4 days (paper exchange) to less than 2 hours. The probative value of each signature is automatically verifiable by the opposing party and by courts, without additional expert review, reducing procedural disputes by around 70% according to feedback from comparable firms.

A SME securing its cross-border supplier contracts

A French industrial SME with approximately 180 employees, supplied by vendors in Germany, Poland and Spain, previously had to have certain contractual documents legalised or apostilled to guarantee their cross-border recognition. By integrating via API a qualified TSP delivering certificates recognised throughout the EU (Article 25(2) eIDAS), the SME eliminates these formalities. The 300 supplier contracts processed annually are now signed electronically with automatic legal recognition in the three partner countries. The estimated gain in administrative costs and timelines reaches 35 to 45% over the entire contract cycle, consistent with the ranges published by sectoral studies of the Fédération des industries mécaniques.

A hospital group preserving the integrity of its digital medical records

A hospital group with approximately 1,200 beds must guarantee the integrity and authenticity of its operation reports, prescriptions and informed consents over retention periods of up to 20 years (Article R. 1112-7 of the French Public Health Code). By using a qualified electronic time stamping service provided by a QTSP, the group creates unfalsifiable evidence of integrity from the time of document creation. Internal audits and controls by the HAS (Haute Autorité de Santé – High Health Authority) can now automatically verify the integrity of each archived document, reducing the workload of quality teams by approximately 25% according to healthcare sector benchmarks.

Frequently asked questions

What is a qualified trust service provider under eIDAS?

A qualified trust service provider (QTSP) is an organisation that has obtained qualified status from the supervisory body of its Member State (ANSSI in France), following a conformity audit by an accredited body. It is listed on the national trust list published in accordance with Article 22 of eIDAS. This status allows it to provide services with a legal presumption of conformity: qualified signatures, qualified time stamps, qualified seals, qualified electronic registered mail services.

How do I verify that a TSP provider is genuinely qualified under eIDAS?

Verification is carried out via the official European Commission portal "eIDAS Trusted List Browser" (tlbrowser.tsl.website) or via the ANSSI portal for French providers. Simply search for the provider's name or service URL. The list is updated in real time. Any provider claiming to be qualified without appearing on this list benefits from no legal presumption attached to qualified eIDAS services.

Is a TSP qualified in one European country recognised throughout the EU?

Yes. This is one of the fundamental contributions of eIDAS: the principle of cross-border mutual recognition (Article 25(2) for signatures, Article 35(2) for seals, Article 41(2) for time stamps). A qualified electronic signature created using a certificate issued by a French QTSP is legally recognised in Germany, Spain, Poland or any other Member State, without any further action. This interoperability is the main reason for the eIDAS Regulation at European level.

What is the difference between a qualified certificate and an advanced certificate?

An advanced certificate can be issued by any provider, qualified or not, according to minimum technical requirements. A qualified certificate can only be issued by a QTSP listed on the Trusted List, on the basis of Annex I to eIDAS (certificate content) and after rigorous verification of the applicant's identity in person or through a qualified remote identification process (QES). The qualified certificate is a necessary condition for issuing a qualified electronic signature, the only one to benefit from the presumption of equivalence with a handwritten signature.

Can a TSP lose its eIDAS qualification? What are the consequences?

Yes. The supervisory body may withdraw or suspend a TSP's qualification in case of serious breach of its obligations (negative audit, major unresolved security incident, misrepresentation). Withdrawal is published on the Trusted List with a "revoked" status. Certificates issued before revocation remain valid if their chain of trust is preserved in compliant probative archiving. However, no new qualified certificate can be issued after revocation, and the services provided cease to benefit from eIDAS legal presumptions.

Conclusion

Trust service providers (TSP) are far more than mere technical suppliers: they form the regulatory and legal foundation upon which all probative value of electronic signatures in Europe rests. Understanding their role, qualification process and obligations is essential for any business wishing to secure its digital exchanges with undeniable legal value. Choosing a QTSP listed on the European Trusted List is not optional when you are aiming for qualified signatures or qualified time stamps.

Certyneo relies exclusively on qualified TSPs recognised under eIDAS to guarantee you electronic signatures with full legal value, interoperable throughout the European Union. Ready to secure your contract workflows? Create your Certyneo account for free or contact our team for a personalised demonstration.

Try Certyneo for free

Send your first signature envelope in less than 5 minutes. 5 envelopes/mo for 14 days, then 2/mo, no credit card required.

Dive deeper

Our comprehensive guides to master electronic signatures.

Certyneo Community

A question about electronic signatures?

Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.