eIDAS Trust Service Provider: Understanding the Role of Trust Services
Trust Service Providers (TSPs) are at the heart of the eIDAS Regulation. Discover their obligations, qualification process, and impact on the legal value of your signatures.
Writer — Certyneo · About Certyneo

Introduction
Since the entry into force of eIDAS Regulation No. 910/2014, Trust Service Providers (TSPs) have been the backbone of digital trust in Europe. These actors, subject to strict regulation, issue the certificates, time stamps, and qualified signatures that give legal force to electronic exchanges. With the adoption of eIDAS 2.0 Regulation (EU Regulation 2024/1183), their obligations have evolved further. This article explains what a TSP is, how it is accredited, what services it can offer, and why choosing a qualified provider is crucial for your business.
---
What is a Trust Service Provider (TSP)?
Definition and Regulatory Scope
According to Article 3 of eIDAS Regulation, a Trust Service Provider is a natural or legal person who provides one or more trust services, either in a qualified capacity or as a non-qualified provider. The regulation clearly distinguishes between these two categories: only qualified providers benefit from the presumption of compliance and the enhanced legal value attached to their services.
Trust services covered by eIDAS include:
- Creation, verification, and validation of electronic signatures (simple, advanced, or qualified)
- Creation, verification, and validation of electronic seals (for legal entities)
- Creation, verification, and validation of qualified electronic time stamps
- Qualified electronic registered mail services
- Issuance and management of certificates for website authentication (QWAC)
- Long-term preservation of qualified signatures and seals
Since eIDAS 2.0, the scope has been extended to European digital identity wallets (EUDIW) and qualified electronic attribute attestations, further strengthening TSP intervention areas.
The Distinction Between Qualified and Non-Qualified TSPs
Not all trust service providers are equal in legal terms. A non-qualified TSP can operate freely, but its services carry no legal presumption of compliance. A qualified TSP (QTSP, Qualified Trust Service Provider) is listed on the supervised national trust list (Trusted List) of its Member State, published and maintained in accordance with Article 22 of eIDAS and Implementing Decision 2015/1505.
In France, the ANSSI (Agence nationale de la sécurité des systèmes d'information) plays the role of supervision body (Article 17 eIDAS). The French trust list is accessible via the centralized European portal. For more information on the hierarchy of signature levels and their recognition, consult our comprehensive guide to eIDAS 2.0 Regulation.
---
The TSP Qualification Process
Compliance Audit by a Conformity Assessment Body
To obtain qualified status, a provider must undergo an audit conducted by a Conformity Assessment Body (CAB) accredited by COFRAC in France (or the equivalent national body in each Member State). This audit verifies compliance with the requirements of Annex II of eIDAS (for qualified certificates) and applicable ETSI standards.
The main reference technical standards are:
- ETSI EN 319 401: General requirements for TSPs
- ETSI EN 319 411-1 and -2: Policy and practice for issuance of qualified certificates
- ETSI EN 319 421: Policy and practice for TSPs issuing time stamps
- ETSI EN 319 132: XAdES profile for advanced and qualified signatures
- ETSI EN 319 122: CAdES profile
The audit results in an evaluation report transmitted to the national supervision body, which may grant, refuse, or withdraw the qualification. The validity period of a qualification certificate is generally 24 months, renewable.
The European Trusted List: The Reference Registry
The European Trusted List (EU Trusted List, or TL) is the central mechanism through which eIDAS ensures cross-border interoperability. Each Member State publishes its national list, and the European Commission aggregates all of them in the List of Trusted Lists (LOTL). This pyramidal architecture allows any verification system to trace back to the European root of trust.
As of January 1, 2026, the LOTL lists more than 200 qualified TSPs across all Member States, collectively issuing millions of qualified certificates annually. For a buyer of a SaaS solution, verifying that a provider is listed on this list is the first due diligence step to perform.
Continuous Monitoring Obligations
Qualification is not definitively acquired. Qualified TSPs are subject to:
- Periodic audits (at least every 24 months)
- Notification without delay of any security incident affecting the services (Article 19 eIDAS)
- Maintaining updated certification policy (CP) and certification practice statement (CPS) that are publicly available
- Maintaining a business continuity plan and a service cessation plan ensuring data preservation in case of shutdown
---
Qualified Services and Their Legal Scope
Qualified Electronic Signature (QES)
The qualified electronic signature is the highest level provided for by eIDAS. It is based on a qualified certificate issued by a QTSP and is created using a qualified electronic signature creation device (QSCD), such as a Common Criteria EAL4+ certified smart card or an HSM (Hardware Security Module) compliant with the protection profile EN 419 221-5.
Article 25(2) of eIDAS establishes the principle of equivalence with a handwritten signature: a QES produced in one Member State is recognized in all Member States without additional formality. This is the only level for which this legal presumption applies automatically. To learn more about the legal value of electronic signatures according to contractual contexts, we have devoted a dedicated guide.
Qualified Electronic Time Stamp
The qualified electronic time stamp (QTS) provides irrefutable evidence that a document or data existed at a specific moment in time. According to Article 41 of eIDAS, it benefits from a presumption of accuracy of date and time, as well as data integrity.
Typical uses include: patent filing proof, evidentiary archiving, logging of contractual events. The qualified electronic time stamp also plays a central role in the long-term preservation of signatures.
The Qualified Electronic Registered Mail Service
The qualified REMS (Qualified Electronic Registered Mail Service) is the digital equivalent of registered mail with proof of receipt. It guarantees identification of the parties, integrity of transmitted data, time stamping of sending and receipt. Article 44 of eIDAS grants it a presumption of data integrity and accuracy of sending and receipt dates. This service is particularly useful for formal notices, contract terminations, or legal notifications.
---
Choosing Your TSP Provider: Determining Criteria
Qualification, Interoperability, and Geographic Coverage
The first criterion is obviously the presence on the Trusted List of the Member State(s) in which you operate. But beyond formal qualification, several practical dimensions come into play:
- Interoperability: Does the TSP support ETSI standard formats (XAdES, PAdES, CAdES, JAdES)? Will signatures produced be verifiable by third-party tools like the European DSS validator?
- Service availability: What SLA is guaranteed? Are QSCD infrastructures geographically redundant?
- Geographic coverage: If you operate in multiple European countries, does the TSP offer qualified certificates recognized in those countries?
- APIs and integration: Are REST/SOAP APIs well documented? Is there an SDK or native integration with your application stack?
Pricing Transparency and Business Model
Qualified TSPs typically charge per issued certificate, per transaction volume, or via annual subscriptions. Prices vary considerably: an individual qualified certificate costs between €50 and €200 per year ex-tax, while mass signature solutions (server) can exceed several thousand euros annually. Compare market offerings with our comparison of electronic signature solutions.
Support, GDPR Compliance, and Data Location
A TSP processing personal data (which is systematically the case for qualified certificate issuance) is subject to GDPR Regulation No. 2016/679. Verify:
- Data location (EU or non-EU hosting?)
- Data retention and deletion policy
- Existence of a designated DPO (Data Protection Officer)
- Any subcontracting and applicable standard contractual clauses (SCCs)
For companies wishing to migrate from an existing solution to a more compliant provider, our guide on migration from DocuSign or YouSign to Certyneo details the steps and precautions to take.
Legal Framework Applicable to eIDAS TSP Providers
Founding Texts
The legal framework for trust service providers rests on several regulatory layers articulated with each other.
eIDAS Regulation No. 910/2014/EU (as amended by EU Regulation 2024/1183, known as "eIDAS 2.0"): the reference text defining trust services, qualification levels, TSP obligations (Articles 13 to 22 for general obligations, Articles 23 to 45 for specific qualified services), and the liability regime (Article 13: liability for any damage caused intentionally or through negligence, with reversal of burden of proof in favor of the victim).
French Civil Code, Articles 1366 and 1367: Article 1366 establishes the principle of equivalence between electronic writing and writing on paper provided the author is identified and integrity is maintained. Article 1367 defines electronic signature and its presumption of reliability when qualified under eIDAS.
Decree No. 2017-1416 of September 28, 2017 on electronic signature: specifies in French law the technical conditions for reliable electronic signature, explicitly referring to eIDAS requirements.
Security and Notification Obligations
Article 19 of eIDAS requires TSPs to take appropriate technical and organizational measures to manage risks to their services. In case of a security incident or loss of integrity having a significant impact on the service or personal data, the TSP must notify the supervision body without undue delay and at the latest within 24 hours of becoming aware of it. This obligation accumulates with that provided for in Article 33 of GDPR No. 2016/679 (notification to the supervisory authority — CNIL in France — within 72 hours).
The NIS2 Directive (2022/2555/EU), transposed into French law by Law No. 2023-703 of August 1, 2023, subjects qualified TSPs to enhanced cybersecurity risk management and incident notification requirements as essential or important entities depending on their size.
Liability and Sanctions
The eIDAS liability regime (Article 13) is stringent: the TSP is presumed responsible for any damage caused to any natural or legal person by a breach of its obligations. It is incumbent on the TSP to prove the absence of fault. National sanctions for non-compliance may include withdrawal of qualification, administrative fines (up to €10 million or 2% of worldwide turnover under GDPR), and civil liability actions. In France, ANSSI may also impose corrective measures.
Usage Scenarios: The eIDAS TSP in Practice
A Law Firm Managing Dematerialized Court Documents
A law firm of about fifty attorneys handling business matters daily processes documents requiring qualified signatures: pleadings, representation mandates, business fund transfer deeds. By relying on a QTSP listed on the French Trusted List, the firm generates PAdES-LTV signatures (Long-Term Validation) incorporating a qualified time stamp. Result: the processing time for a signable document drops from 3 to 4 days (paper circulation) to less than 2 hours. The evidentiary value of each signature is automatically verifiable by the opposing party and courts without additional expertise, reducing procedural disputes by around 70% according to field feedback from comparable firms.
An Industrial SME Securing Cross-Border Supplier Contracts
An industrial SME of about 180 employees sourced from suppliers in Germany, Poland, and Spain previously had to have certain contractual documents legalized or apostilled to guarantee cross-border recognition. By integrating via API a qualified TSP issuing certificates recognized throughout the EU (Article 25(2) eIDAS), the SME eliminates these formalities. The 300 annual supplier contracts are now electronically signed with automatic legal recognition in the three partner countries. Estimated savings in administrative costs and lead times reach 35 to 45% across the entire contract cycle, consistent with ranges published by mechanical industry sectoral studies.
A Hospital Group Preserving the Integrity of Its Digital Medical Records
A hospital group of approximately 1,200 beds must guarantee the integrity and authenticity of its operative reports, prescriptions, and informed consents over retention periods of up to 20 years (Article R. 1112-7 of the Public Health Code). By using a qualified electronic time stamp service provided by a QTSP, the group creates irrefutable integrity proofs as soon as the document is produced. Internal audits and HAS (High Health Authority) controls can now automatically verify the integrity of each archived document, reducing the workload of quality teams by approximately 25% according to healthcare sector benchmarks.
Frequently Asked Questions
What is a Trust Service Provider qualified under eIDAS?
A qualified Trust Service Provider (QTSP) is an organization that has obtained qualified status from the supervision body of its Member State (ANSSI in France) after a compliance audit by an accredited organization. It is listed on the national trust list published in accordance with Article 22 of eIDAS. This status allows it to provide services with a legal presumption of compliance: qualified signatures, qualified time stamps, qualified seals, qualified electronic registered mail services.
How can I verify that a TSP provider is genuinely qualified under eIDAS?
Verification is performed via the official European Commission portal "eIDAS Trusted List Browser" (tlbrowser.tsl.website) or via the ANSSI portal for French providers. Simply search for the provider's name or service URL. The list is updated in real time. Any provider claiming to be qualified without being listed on this list benefits from no legal presumption attached to qualified eIDAS services.
Is a qualified TSP in one European country recognized throughout the EU?
Yes. This is one of the fundamental contributions of eIDAS: the principle of mutual cross-border recognition (Article 25(2) for signatures, Article 35(2) for seals, Article 41(2) for time stamps). An electronic signature qualified by means of a certificate issued by a French QTSP is legally recognized in Germany, Spain, Poland, or any other Member State without additional steps. This interoperability is the main reason for eIDAS Regulation at the European level.
What is the difference between a qualified certificate and an advanced certificate?
An advanced certificate can be issued by any provider, qualified or not, according to minimum technical requirements. A qualified certificate can only be issued by a QTSP listed on the Trusted List based on Annex I of eIDAS (certificate content) and after rigorous verification of the applicant's identity face-to-face or via a qualified remote identification process (QES). The qualified certificate is a necessary condition for issuing a qualified electronic signature, the only one benefiting from the presumption of equivalence with a handwritten signature.
Can a TSP lose its eIDAS qualification? What are the consequences?
Yes. The supervision body may withdraw or suspend a TSP's qualification in case of serious breach of its obligations (negative audit, unresolved major security incident, false declaration). The withdrawal is published on the Trusted List with a "revoked" status. Certificates issued before revocation remain valid if their trust chain is preserved in compliant evidentiary archiving. However, no new qualified certificate can be issued after revocation, and services provided cease to benefit from eIDAS legal presumptions.
Conclusion
Trust Service Providers (TSPs) are far more than mere technical suppliers: they constitute the regulatory and legal foundation on which all the evidentiary value of electronic signature in Europe rests. Understanding their role, qualification process, and obligations is essential for any organization seeking to secure its digital exchanges with unquestionable legal value. The choice of a QTSP listed on the European Trusted List is not optional as soon as you aim for qualified signature or qualified time stamp.
Certyneo relies exclusively on qualified TSPs recognized under eIDAS to guarantee you electronic signatures with full legal value, interoperable throughout the European Union. Ready to secure your contract workflows? Create your Certyneo account free of charge or contact our team for a personalized demonstration.
Try Certyneo for Free
Send your first signature envelope in less than 5 minutes. 5 envelopes/mo for 14 days, then 2/mo, no credit card required.
Dive Deeper
Reference articles on this topic.
Dive Deeper
Our comprehensive guides to master electronic signatures.
Certyneo Community
A question about electronic signatures?
Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.
Recommended Articles
Deepen your knowledge with these related articles.

QSCD eIDAS Certificate: Everything You Need to Know to Obtain One in France in 2026
The QSCD certificate is the cornerstone of qualified electronic signature in Europe. Discover its definition, legal framework, and concrete steps to obtain one in France.

QES, AES, and SES: Understanding the Three Levels of eIDAS Electronic Signature in 2026
The eIDAS regulation distinguishes three levels of electronic signature with very different legal values. Mastering these distinctions is essential to secure your contracts in 2026.

Healthcare Data Protection and GDPR Compliance for Professionals
Healthcare data is the most sensitive personal data under GDPR. Discover all the obligations that apply to healthcare sector professionals in 2026.