Skip to main content
Certyneo

QSCD eIDAS Certificate: Everything You Need to Know to Obtain One in France in 2026

The QSCD certificate is the cornerstone of qualified electronic signature in Europe. Discover its definition, legal framework, and concrete steps to obtain one in France.

Certyneo Editorial Team13 min read
woman in white long sleeve shirt using macbook pro

What Is a QSCD Certificate? Definition and Regulatory Scope

The term QSCD is the English acronym for Qualified Signature Creation Device, defined in French as dispositif qualifié de création de signature. It designates a hardware or software tool that generates and stores cryptographic keys used for electronic signing, while guaranteeing a maximum security level defined by the eIDAS Regulation No. 910/2014.

Distinction Between Qualified Certificate and QSCD

Two concepts are often confused and must be distinguished:

  • The qualified certificate (Qualified Certificate for Electronic Signature, QCert) is a digital certificate issued by a qualified trust service provider (QTSP). It attests to the signer's identity and contains their public key.
  • The QSCD is the secure medium on which the private key associated with the certificate is generated and stored. This can be a cryptographic USB token, a smart card, an HSM (Hardware Security Module), or a remote QSCD (remote QSCD) hosted by the service provider.

For a signature to be qualified under eIDAS, both elements must be present: a qualified certificate AND a QSCD. Annex II of the regulation sets out the requirements the device must meet (uniqueness of creation data, impossibility of deriving the private key, protection against falsification, etc.).

Electronic Signature Levels and the Role of QSCD

The eIDAS regulation defines three levels of electronic signature:

  1. Simple Electronic Signature (SES): no specific technical requirements.
  2. Advanced Electronic Signature (AdES): uniquely linked to the signer, created from data under their exclusive control, but without a QSCD requirement.
  3. Qualified Electronic Signature (QES): absolutely requires a qualified certificate stored on a QSCD. It is the only level benefiting from a legal presumption of equivalence to a handwritten signature in all member states.

To deepen your understanding of the differences between these three levels, Certyneo's comparison of electronic signature solutions offers detailed analysis.

Qualified Service Providers (QTSP) in France: Who Can Issue a QSCD?

In France, the issuance of qualified certificates and the provision of QSCDs fall exclusively to qualified trust service providers (QTSP) registered on the national trust list (Trust Service List, TSL), published and maintained by the ANSSI (Agence nationale de la sécurité des systèmes d'information).

ANSSI, France's Supervisory Authority

ANSSI plays the role of supervisory body (supervisory body) provided for in Article 17 of eIDAS. It audits QTSP candidates according to strict criteria aligned with the standards ETSI EN 319 401 (general requirements for TSP) and ETSI EN 319 411 (qualified certificates). A service provider cannot claim to be "qualified" without appearing on the French trust list published in signed XML format.

Among accredited French QTSPs are notably actors such as Certigna, CertEurope, Docaposte, Keynectis, and Thales (formerly Gemalto). Each offers qualified certificate solutions stored on hardware QSCDs (smart cards, USB tokens) or remote QSCDs, with the latter seeing strong growth since 2022.

Remote QSCD: the New Standard in Enterprise

The remote QSCD represents a major evolution: the signer's private key is no longer stored on a physical medium given to the user, but rather in a certified HSM hosted within the QTSP's secure infrastructure. The signer accesses their device via strong authentication (OTP, biometrics, mobile application). This approach, governed by the ETSI EN 319 432 standard and validated by ANSSI, is now integrated into most SaaS qualified signature platforms, including Certyneo.

The legal value of electronic signature does not depend on whether the QSCD is physical or remote, provided that eIDAS compliance is attested by ANSSI qualification.

How to Obtain a QSCD Certificate in France: The Step-by-Step Process

Obtaining a qualified certificate on QSCD follows a formalized process, more demanding than that for a simple or advanced certificate. Here are the essential steps.

Step 1: Choose Your QTSP and Type of QSCD

The first decision concerns the type of QSCD desired:

  • Physical QSCD (smart card or USB token): suitable for occasional use, liberal professions, or executives. Involves physical delivery of the medium.
  • Remote QSCD: ideal for organizations with high signing volumes or operating 100% digitally. No physical medium to manage.

The choice of service provider also depends on available integrations (REST API, webhooks, HRIS connectors) and support level. It is advisable to consult the official list of QTSPs on the ANSSI portal before making any decision.

Step 2: The Identity Verification Process (KYC)

The eIDAS regulation imposes rigorous identity verification before issuing a qualified certificate. Two methods are accepted:

  • Physical in-person verification: the applicant presents themselves at a registration point of the QTSP or with a mandated verification operator, with their official identity documents.
  • Remote video verification: since 2021, some QTSPs offer verification via real-time videoconference with an agent, governed by ETSI EN 319 461 requirements. Automated AI-based verification (eKYC) is not yet permitted for qualified certificates in France as of mid-2026, as ANSSI still requires human intervention.

Required documents typically include: valid identity document (national ID card, passport), proof of affiliation with the professional entity (business registration certificate, RCS extract), and sometimes a letter of engagement for signatories acting on behalf of a legal entity.

Step 3: Key Generation and QSCD Delivery

Once identity is verified, the QTSP proceeds to generate the cryptographic key pair within the QSCD's secure environment. For a physical QSCD, the medium is initialized then delivered or sent to the holder with a secure PIN code. For a remote QSCD, the holder activates their device via the service provider's mobile application and configures their strong authentication mechanism.

The qualified certificate is then associated with the public key and published in the QTSP's directory. Its validity period is generally 1 to 3 years, depending on the subscription. Renewal should be anticipated before expiration to maintain continuous signing capability.

Cost, Timeline, and Renewal: What You Need to Plan For

Indicative Pricing Grid in 2026

The prices of qualified certificates on QSCD vary significantly depending on the service provider and type of device:

  • Physical QSCD (USB token or card): between 80 € and 250 € net for initial issuance (including the physical medium), then 50 € to 150 € net for annual renewal.
  • Remote QSCD: often integrated into SaaS subscription offers starting from 15 € to 40 € net per user per month, or volume-based packages for low volumes.

These costs should be weighed against time savings and reduced legal risks. Certyneo's ROI calculator allows you to estimate precise return on investment based on your document signing volume.

Delivery Times

The time between application and availability of the qualified certificate is generally 3 to 10 business days for physical solutions (including postal shipping) and a few hours to 48 hours for remote QSCDs, provided the KYC file is complete. Organizations anticipating activity peaks (contract renewals at fiscal year-end, calls for tender, accounting closures) should plan accordingly.

Revocation and Certificate Lifecycle

A qualified certificate may be revoked before its expiration in case of private key compromise, holder departure, or change in certified information. The revocation is published in the Certificate Revocation List (CRL) or via the QTSP's OCSP protocol (Online Certificate Status Protocol). Any signature affixed after revocation is deemed invalid; those affixed before retain their value, provided they are time-stamped. Qualified electronic time-stamping plays a crucial role here in proving the prior date of a signature.

The regulation governing qualified signature creation devices is comprehensive and articulated across several European and national texts.

eIDAS Regulation No. 910/2014 (EU) — This foundational text constitutes the cornerstone of the framework. Article 3(12) defines the qualified signature creation device. Article 26 establishes requirements for advanced signatures, while Article 29 and Annex II detail the technical requirements applicable to QSCDs (uniqueness of creation data, confidentiality of the private key, non-falsifiability). Article 25(2) grants qualified signatures a presumption of equivalence with handwritten signatures. The eIDAS 2.0 regulation (Regulation 2024/1183, progressively entering into force since 2024) strengthens these requirements and expands the scope to European digital identity wallets (EUDIW).

French Civil Code, Articles 1366 and 1367 — Article 1366 establishes that electronic writing has the same probative force as paper writing subject to reliable identification of the author and document integrity. Article 1367 clarifies that electronic signature consists of the use of a reliable identification process guaranteeing the link with the signed act. Decree No. 2017-1416 of September 28, 2017 establishes the presumption of reliability for qualified signatures conforming to eIDAS.

ETSI Standards — The standards ETSI EN 319 132 (XAdES format for XML signatures), ETSI EN 319 122 (CAdES), ETSI EN 319 162 (ASiC), and ETSI EN 319 401/411 (requirements for TSP and qualified certificates) constitute the technical reference applicable to service providers. Non-compliance with these standards may result in suspension of QTSP qualification by ANSSI.

GDPR No. 2016/679 — The identity verification process (KYC) involves processing biometric data and personal data. The data controller (QTSP and, where applicable, the client company) must comply with principles of minimization, limited purpose, and provide proportionate retention periods. A DPIA (Data Protection Impact Assessment) is recommended for large-scale deployments.

Liability for Non-Compliance — Using a non-qualified certificate to sign acts requiring a qualified signature (certain public procurement contracts, electronic notarial acts, dematerialized tax filings) exposes the organization to contestation of the act's probative value, or even nullity. Article 13 of eIDAS provides a liability regime for QTSPs in case of breach of their obligations, but this regime does not relieve user organizations of their due diligence duty in choosing and maintaining their device.

QSCD Certificate Usage Scenarios in Enterprise

Scenario 1: A Law Firm Dematerializing Its Court Filings

A law firm with about fifteen collaborators processes several hundred procedural filings, powers of attorney, and fee agreements annually. Before deploying a remote QSCD solution, each document required printing, handwritten signature, and postal sending or scanning. The firm opted for remote qualified certificates integrated into a SaaS platform, allowing each partner to sign from their desk or mobile at the qualified level. Observed result: approximately 70% reduction in the time to sign mutual settlement agreements (from 4 days to less than 24 hours on average), elimination of postage costs, and automatic archiving of signed acts in the firm's document management system.

Scenario 2: A Small Industrial Manufacturer Managing Its Supplier Contracts

An SME in the manufacturing sector handling approximately 300 supplier contracts annually faced recurring legal risks related to simple or scanned signatures, easily contestable. After audit, it emerged that several contracts exceeding 100,000 € had been signed without reliable identification process. Migration to qualified signatures on remote QSCD for high-stakes contracts (strategic suppliers, confidentiality agreements, framework orders) secured the contractual assets. Contract validation times decreased by approximately 60%, with foreign counterparties appreciating the immediate cross-border recognition offered by eIDAS.

Scenario 3: A Hospital Group Deploying Qualified Signature for Its Public Procurement

A hospital group with approximately 900 beds had to meet the obligation, arising from Decree No. 2016-360 relating to public procurement, to electronically sign engagement acts above certain thresholds. The IT department deployed certified QSCD USB tokens for directors authorized to commit the institution. User training, integration into the public procurement dematerialization platform, and the annual renewal procedure were documented in an internal signature policy (Signature Policy). The estimated operational gain is approximately 3 to 4 days per procurement procedure, thanks to elimination of registered mail and physical document routing.

Frequently Asked Questions

What differentiates a QSCD from a standard HSM?

An HSM (Hardware Security Module) is a generic security module used to store and manage cryptographic keys. A QSCD is an HSM — or any other secure device — that has been evaluated and certified as conforming to the requirements of Annex II of eIDAS Regulation by an accredited laboratory recognized by a national supervisory authority. QSCD qualification attests that the device meets strict criteria for key uniqueness, non-exportability, and resistance to physical and logical attacks.

Is a QSCD certificate obtained in France valid throughout the European Union?

Yes. Article 25(2) of eIDAS establishes mandatory mutual recognition of qualified signatures among all member states. A qualified certificate issued by a French QTSP registered on the national trust list produces the same legal effects in Germany, Spain, or Italy as in its country of issue. This automatic recognition is one of the major advantages of the framework for companies with cross-border contractual activities.

What is the validity period of a QSCD certificate and can it be renewed remotely?

The validity period of a qualified certificate is generally set at 1, 2, or 3 years depending on the QTSP's offer. Renewal can be conducted remotely for remote QSCDs, provided the holder's identity has already been verified in-person or by video upon initial issuance. Most QTSPs send expiration alerts 60 and 30 days before the deadline. Ignoring these alerts exposes you to an interruption of qualified signature capability.

Is the QSCD certificate mandatory for all electronically signed acts?

No. The required signature level depends on the nature of the act and the applicable regulatory framework. The qualified signature on QSCD is mandatory for certain specific acts (electronic notarial acts, certain public procurement contracts, dematerialized tax filings). For the majority of ordinary commercial contracts, an advanced signature suffices. It is recommended to consult the electronic signature glossary or seek legal counsel to determine the required level act by act.

How do you verify that a signature is truly based on a valid QSCD certificate?

Verification is performed by consulting the signed document's metadata via a validation tool compliant with ETSI specifications, such as the DSS (Digital Signature Service) service from the European Commission, available free of charge. This tool verifies the certificate's chain of trust, its status (not revoked), its compliance with the qualified profile, and the presence of qualified time-stamping. Some SaaS platforms like Certyneo integrate this validation report directly into the document management interface.

Conclusion

The QSCD certificate is far more than a technical formality: it is the legal and cryptographic foundation of qualified electronic signature, the only level offering a legal presumption of equivalence to a handwritten signature throughout the European Union. In France, obtaining it requires working with a QTSP accredited by ANSSI, a rigorous identity verification process, and an informed choice between physical QSCD and remote QSCD — the latter increasingly becoming the standard for organizations seeking agility and scalability.

Certyneo natively integrates certified remote QSCDs into its SaaS platform, enabling your teams to sign at the qualified level without managing any physical medium. Whether you're starting from scratch or migrating from another solution, our experts guide you through every step. Discover Certyneo pricing or contact our team for an audit of your qualified signature needs.

The digital transformation of your signature processes starts here — secure, legally recognized, and seamlessly integrated into your workflows.

Try Certyneo for Free

Send your first signature envelope in less than 5 minutes. 5 envelopes/mo for 14 days, then 2/mo, no credit card required.

Dive Deeper

Our comprehensive guides to master electronic signatures.

Certyneo Community

A question about electronic signatures?

Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.