
eIDAS Trust Service Provider: Understanding the Role of Trust Services
Trust Service Providers (TSPs) are at the heart of the eIDAS Regulation. Discover their obligations, qualification process, and impact on the legal value of your signatures.
Updated on
The eIDAS regulation is the foundational text for electronic signatures in Europe. It defines three levels of signatures (simple, advanced, qualified), establishes the legal value of electronic documents, and regulates trust service providers. This guide explains everything you need to know to be compliant by 2026.

Before eIDAS, each Member State of the European Union had its own regulations on electronic signatures, creating legal fragmentation that hindered cross-border exchanges. An electronic signature valid in France was not necessarily recognized in Germany or Spain.
The Regulation (EU) No 910/2014, known as eIDAS (Electronic IDentification, Authentication and trust Services), was adopted on July 23, 2014 and entered into force on July 1, 2016. As a regulation (not a directive), it applies directly and uniformly in all 27 Member States, with no national transposition required.
eIDAS pursues three main objectives: to create a single digital market in Europe through mutual recognition of electronic identities, to guarantee legal certainty for cross-border electronic transactions, and to establish a framework of trust for digital services through qualified trust service providers (QTSP — Qualified Trust Service Provider).
eIDAS establishes a pyramid of three levels of electronic signatures, each with its own technical requirements and probative value.
eIDAS Requirements
Usage Examples
Legal Value
Basic contractual value, no legal presumption
eIDAS Requirements
Usage Examples
Legal Value
Strong evidentiary value — recommended for important contracts
eIDAS Requirements
Usage Examples
Legal Value
Legal presumption equivalent to handwritten signature (art. 25 eIDAS)
The eIDAS regulation was revised by Regulation (EU) 2024/1183, published in the EU Official Journal on April 30, 2024, and entered into force on May 20, 2024. This revision modernizes the initial framework to address contemporary digital challenges: digital identity of citizens, sovereign cloud, and resilience of trust service providers.
The flagship measure of eIDAS 2.0 is the European digital identity wallet (EUDIW). By the end of 2026, each Member State must offer its citizens and residents an application allowing them to store and present certified identity credentials — the digital equivalent of an ID card, driving license, diplomas. This evolution will have a direct impact on qualified signature processes.
eIDAS 2.0 introduces the European Digital Identity Wallet: every European citizen will be able to store their certified identity credentials (identity card, driver's license, diplomas) in a mobile application that is interoperable across the EU.
Requirements for qualified trust service providers (QTSP) are strengthened, particularly regarding cybersecurity, audits, and service continuity.
eIDAS 2.0 adds new qualified services: qualified electronic archiving, qualified data attribution management, and qualified electronic register (certified blockchain).
Better mutual recognition of digital identities between Member States. Qualified signatures issued in any EU country are recognized everywhere.
eIDAS compliance is not limited to choosing a signature level. It requires reflection on the entire process: risk identification, tool selection, proof retention and document governance.
Here is a practical checklist for companies wishing to secure their electronic signature processes in compliance with eIDAS:
Certyneo natively implements the three levels of the eIDAS regulation: SES (Simple Electronic Signature), AES (Advanced Electronic Signature) and QES (Qualified Electronic Signature). Advanced signature is based on dual-factor authentication: a single-use link sent by email and an OTP code sent by SMS via our OTP SMS provider, in accordance with the four criteria of article 26 of eIDAS. Qualified signature (QES) is delivered per act at €14.90/signature on all plans, including Free, via a qualified provider (QTSP) listed on the European trust list — legal equivalent of a handwritten signature throughout the EU under article 25(2) of eIDAS.
Each envelope generates a comprehensive audit trail: timestamp of each action (sending, link opening, OTP validation, signature affixation, possible refusal), signer's IP address, and browser user-agent. This audit trail is embedded at the bottom of each page of the final PDF (audit footer) and preserved for 10 years.
Data is hosted (EU) (IONOS infrastructure), within the European Union, in compliance with digital sovereignty requirements and the GDPR. Please see our security and compliance page for all technical details.
eIDAS (Electronic Identification, Authentication and Trust Services) is the European regulation (EU) No 910/2014 that establishes a common legal framework for electronic signatures, electronic seals, time stamps, electronic registered delivery services, and website authentication services in the European Union. It entered into force on July 1, 2016, and applies directly in all 27 Member States.
eIDAS 2.0 (regulation (EU) 2024/1183, which entered into force on May 20, 2024) modernizes eIDAS 1.0 by introducing notably the European digital identity wallet (EUDIW — European Digital Identity Wallet), which will allow European citizens to store certified digital identity credentials. For businesses, eIDAS 2.0 strengthens requirements for qualified trust service providers (QTSP) and improves cross-border interoperability.
Yes. Article 25 of eIDAS explicitly prohibits refusing legal effects to an electronic signature on the sole ground that it is in electronic form. A simple signature (SES) therefore has legal value, but it does not benefit from the legal presumption reserved for qualified signatures (QES). In case of dispute, it is for the person relying on the signature to prove its authenticity.
The general rule is to calibrate the level to the legal and commercial risk of the document. For standard documents with low stakes (quotes, internal orders), simple signature is sufficient. For important business contracts, employment contracts, NDAs or mandates, advanced signature (AES) is recommended. Qualified signature (QES) is reserved for situations where the law explicitly requires it (certain administrative deeds, large-scale public contracts) or when the risk of contestation is maximal.
Certyneo natively implements all three eIDAS levels: simple signature (SES), advanced signature (AES) with SMS OTP, and qualified signature (QES) at €14.90 per signature on every plan, including Free, via a qualified QTSP from the EU trust list. Every envelope generates a timestamped audit trail embedded in the final PDF. Data is hosted in the European Union, in line with digital sovereignty requirements.
eIDAS applies to trust services provided in the EU. A company established outside the EU wishing its signatures to be recognized in the EU must use an eIDAS-compliant solution or a recognized qualified trust service provider (QTSP) in a Member State''s trust list. For international B2B exchanges, mutual recognition agreements exist with certain third countries.
Certyneo Community
Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.
We use cookies to improve your experience on our site. Cookies strictly necessary for the service to function are always active. Learn more about our cookie policy

Trust Service Providers (TSPs) are at the heart of the eIDAS Regulation. Discover their obligations, qualification process, and impact on the legal value of your signatures.

The eIDAS regulation distinguishes three levels of electronic signature with very different legal values. Mastering these distinctions is essential to secure your contracts in 2026.

A poorly drafted non-compete clause is void ab initio. Discover the inescapable legal conditions to protect your business in full compliance.

Cross-border electronic signature eIDAS raises major legal and technical questions for businesses operating between Europe and the Maghreb. Discover how to secure your international contractual exchanges.

The eIDAS 2 regulation fundamentally reshapes electronic signature rules in Europe. Discover the key changes, implementation timeline, and actions to take now.

The eIDAS regulation mandates mutual recognition of qualified electronic signatures between all EU Member States. Discover how this principle works in practice in 2026.