Go to main content
Certyneo

QSCD Certificate eIDAS: Everything You Need to Know to Obtain One in France in 2026

The QSCD certificate is the cornerstone of qualified electronic signature in Europe. Discover its definition, legal framework, and concrete steps to obtain one in France.

Certyneo Legal Team13 min read

Certyneo Legal Team

Writer — Certyneo · About Certyneo

woman in white long sleeve shirt using macbook pro

The growing digitalization wave is compelling businesses and administrations to master precise technical concepts. Among them, the QSCD certificate (Qualified Signature Creation Device) occupies a central place in the eIDAS framework. Without it, no qualified electronic signature—the only one carrying a legal presumption of value equivalent to handwritten signature—can be issued. Yet, the vast majority of French organizations still do not understand what a QSCD is, how it differs from a simple digital certificate, or what steps allow them to obtain one. This article provides you with a complete answer: technical definition, regulatory foundations, a list of accredited actors in France, and a step-by-step acquisition process.

What is a QSCD Certificate? Definition and Regulatory Scope

The term QSCD is the English acronym for Qualified Signature Creation Device, which translates into French as dispositif qualifié de création de signature (qualified signature creation device). It designates a hardware or software tool that generates and stores the cryptographic keys used for electronic signing, while guaranteeing a maximum level of security defined by the eIDAS Regulation No. 910/2014.

Distinction Between Qualified Certificate and QSCD

It is important to distinguish between two notions that are often confused:

  • The qualified certificate (Qualified Certificate for Electronic Signature, QCert) is a digital certificate issued by a qualified trust service provider (QTSP). It attests to the signer's identity and contains their public key.
  • The QSCD is the secure support on which the private key associated with the certificate is generated and stored. This can be a cryptographic USB token, a smart card, an HSM (Hardware Security Module), or a remote QSCD (remote QSCD) hosted by the service provider.

For a signature to be qualified under eIDAS, both elements must be present: a qualified certificate AND a QSCD. Annex II of the regulation sets out the requirements that the device must meet (uniqueness of creation data, impossibility of deducing the private key, protection against falsification, etc.).

Levels of Electronic Signature and the Role of QSCD

The eIDAS regulation defines three levels of signature:

  1. Simple Electronic Signature (SES): no specific technical requirement.
  2. Advanced Electronic Signature (AdES): uniquely linked to the signer, created from data under their exclusive control, but without mandatory use of QSCD.
  3. Qualified Electronic Signature (QES): imperatively requires a qualified certificate stored on a QSCD. It is the only level benefiting from a legal presumption of equivalence to handwritten signature in all member states.

To deepen your understanding of the differences between these three levels, Certyneo's comparison of electronic signature solutions offers detailed analysis.

Qualified Service Providers (QTSP) in France: Who Can Issue a QSCD?

In France, the issuance of qualified certificates and the provision of QSCDs fall exclusively to Qualified Trust Service Providers (QTSP) registered on the national trust list (Trust Service List, TSL), published and maintained by the ANSSI (Agence nationale de la sécurité des systèmes d'information / National Agency for Information Systems Security).

ANSSI: The French Supervisory Authority

ANSSI plays the role in France of supervisory body (supervisory body) provided for in Article 17 of eIDAS. It audits QTSP candidates according to strict criteria aligned with the ETSI EN 319 401 (general requirements for TSP) and ETSI EN 319 411 (qualified certificates) standards. A service provider cannot claim to be "qualified" without appearing on the French trust list published in signed XML format.

Among accredited French QTSPs are notably actors such as Certigna, CertEurope, Docaposte, Keynectis, and Thales (formerly Gemalto). Each offers qualified certificate packages stored on hardware QSCDs (smart cards, USB tokens) or remote QSCDs, the latter experiencing strong growth since 2022.

Remote QSCD: The New Business Standard

The remote QSCD represents a major evolution: the signer's private key is no longer stored on a physical support provided to the user, but in a certified HSM hosted within the QTSP's secure infrastructure. The signer accesses their device via strong authentication (OTP, biometrics, mobile application). This approach, governed by the ETSI EN 319 432 standard and validated by ANSSI, is now integrated into most SaaS qualified signature platforms, including Certyneo.

The legal value of electronic signature does not depend on whether the QSCD is physical or remote, as long as eIDAS compliance is certified by an ANSSI qualification.

How to Obtain a QSCD Certificate in France: The Step-by-Step Process

Obtaining a qualified certificate on QSCD follows a formalized process, more demanding than that for a simple or advanced certificate. Here are the essential steps.

Step 1: Choose Your QTSP and Type of QSCD

The first decision concerns the type of QSCD desired:

  • Physical QSCD (smart card or USB token): suitable for occasional use, sole practitioners, or executives. Requires physical delivery of the support.
  • Remote QSCD: ideal for organizations requiring high-volume signature capability or operating in a fully digital mode. No physical support to manage.

The choice of service provider also depends on available integrations (REST API, webhooks, HRIS connectors) and the level of support. It is advisable to consult the official list of QTSPs on the ANSSI portal before making any decision.

Step 2: The Identity Verification Process (KYC)

The eIDAS regulation imposes rigorous identity verification before issuing a qualified certificate. Two modalities are accepted:

  • In-person physical verification (in-person): the applicant presents themselves at a registration point of the QTSP or with a mandated verification operator, with their official identity documents.
  • Remote verification via video (remote identity proofing): since 2021, some QTSPs offer verification through real-time videoconference with an agent, governed by ETSI EN 319 461 requirements. Automated AI-based verification (eKYC) is not yet admitted for qualified certificates in France as of mid-2026, as ANSSI still requires human intervention.

Required documents typically include: valid identity document (national ID card, passport), proof of attachment to the professional entity (Kbis, business register extract), and sometimes a letter of authorization for signers acting on behalf of a legal entity.

Step 3: Key Generation and QSCD Delivery

Once identity is verified, the QTSP proceeds to generate the cryptographic key pair within the QSCD's secure environment. For a physical QSCD, the support is initialized and then delivered or shipped to the holder with a secure PIN code. For a remote QSCD, the holder activates their device via the service provider's mobile application and configures their strong authentication mechanism.

The qualified certificate is then associated with the public key and published in the QTSP's directory. Its validity period is generally 1 to 3 years, depending on the subscription offer. Renewal should be anticipated before expiration to maintain continuous signing capability.

Cost, Timeline, and Renewal: What You Need to Plan For

Indicative Pricing Grid for 2026

The prices of qualified certificates on QSCD vary significantly depending on the service provider and type of device:

  • Physical QSCD (USB token or card): between €80 and €250 excluding tax for initial issuance (including material support), then €50 to €150 excluding tax for annual renewal.
  • Remote QSCD: often included in SaaS subscription offers starting from €15 to €40 excluding tax per user per month, or in per-transaction packs for low volumes.

These costs must be weighed against time savings and reduced legal risks. Certyneo's ROI calculator allows you to precisely estimate the return on investment based on your volume of documents signed.

Acquisition Timeline

The time between application and effective availability of the qualified certificate is generally 3 to 10 business days for physical solutions (including postal delivery) and a few hours to 48 hours for remote QSCDs, provided the KYC documentation is complete. Organizations anticipating activity peaks (contract renewals at year-end, call for tenders, financial close) should plan accordingly.

Revocation and Certificate Lifecycle

A qualified certificate may be revoked before expiration in case of private key compromise, departure of the holder, or change in certified information. Revocation is published in the Certificate Revocation List (CRL) or via the QTSP's OCSP protocol (Online Certificate Status Protocol). Any signature affixed after revocation is deemed invalid; those affixed before retain their value, provided they are time-stamped. Qualified electronic time-stamping plays a crucial role here in proving the anteriority of a signature.

The regulations governing qualified signature creation devices are comprehensive and articulated across several European and national texts.

eIDAS Regulation No. 910/2014 (EU) — This foundational text constitutes the cornerstone of the system. Article 3(12) defines the qualified signature creation device. Article 26 sets out the requirements for advanced signature, while Article 29 and Annex II detail the technical requirements applicable to QSCDs (uniqueness of creation data, confidentiality of private key, non-falsifiability). Article 25(2) confers on qualified signature a presumption of equivalence with handwritten signature. The eIDAS 2.0 regulation (Regulation 2024/1183, progressively applicable since 2024) strengthens these requirements and expands the scope to European digital identity wallets (EUDIW).

French Civil Code, Articles 1366 and 1367 — Article 1366 establishes that electronic documents have the same probative force as paper documents, subject to reliable identification of the author and document integrity. Article 1367 clarifies that electronic signature consists of the use of a reliable identification process guaranteeing the link with the signed act. Decree No. 2017-1416 of September 28, 2017 establishes the presumption of reliability for signatures qualified under eIDAS.

ETSI Standards — The standards ETSI EN 319 132 (XAdES format for XML signature), ETSI EN 319 122 (CAdES), ETSI EN 319 162 (ASiC), and ETSI EN 319 401/411 (requirements for TSP and qualified certificates) constitute the technical framework enforceable against service providers. Non-compliance with these standards may result in suspension of QTSP qualification by ANSSI.

GDPR No. 2016/679 — The identity verification process (KYC) involves processing biometric data and personal data. The data controller (QTSP and, where applicable, the client company) must comply with principles of minimization, limited purpose, and provide for a retention period proportionate to the purpose. A DPIA (Data Protection Impact Assessment) is recommended for large-scale deployments.

Liability for Non-Compliance — Using a non-qualified certificate to sign acts requiring a qualified signature (certain public procurement, electronic notarial deeds, dematerialized tax filings) exposes the organization to contestation of the probative value of the act or even its nullity. Article 13 of eIDAS provides for a liability regime for QTSPs in case of breach of their obligations, but this regime does not relieve user organizations of their duty of care in selecting and maintaining their device.

QSCD Certificate Use Cases in Business

Scenario 1: A Law Firm Dematerializing Its Court Filings

A law firm with approximately fifteen lawyers handles several hundred court filings, powers of attorney, and fee agreements each year. Before deploying a remote QSCD solution, each document required printing, handwritten signature, and postal delivery or scanning. The firm opted for qualified remote certificates integrated into a SaaS platform, allowing each partner to sign from their desk or mobile device at the qualified level. Result observed: approximately 70% reduction in average signing time for mutual termination agreements (from 4 days to less than 24 hours), elimination of postage costs, and automatic archiving of signed documents in the firm's document management system.

Scenario 2: An Industrial SME Managing Supplier Contracts

An SME in the manufacturing sector handling approximately 300 supplier contracts per year faced recurring legal risks related to simple or scanned signatures, easily contestable. After audit, it became apparent that several contracts exceeding €100,000 had been signed without reliable identification procedures. Migration to qualified signatures on remote QSCD for high-stakes contracts (strategic suppliers, confidentiality agreements, framework orders) secured the contractual assets. Contract validation timelines decreased by approximately 60%, with foreign counterparties appreciating the immediate cross-border recognition offered by eIDAS.

Scenario 3: A Hospital Group Deploying Qualified Signature for Public Procurement

A hospital group with approximately 900 beds had to comply with an obligation, arising from Decree No. 2016-360 on public procurement, to electronically sign commitment documents above certain thresholds. The IT department deployed certified QSCD USB tokens for authorized facility officers. User training, integration into the procurement dematerialization platform, and annual renewal procedures were documented in an internal signing policy (Signature Policy). The estimated operational gain is approximately 3 to 4 days per procurement procedure, thanks to elimination of registered mail and physical routing processes.

Frequently Asked Questions

What distinguishes a QSCD from a standard HSM?

An HSM (Hardware Security Module) is a generic security hardware module used to store and manage cryptographic keys. A QSCD is an HSM—or any other secure device—that has been evaluated and certified as compliant with the requirements of Annex II of the eIDAS regulation by an accredited laboratory recognized by a national supervisory authority. QSCD qualification certifies that the device meets strict criteria for key uniqueness, non-exportability, and resistance to physical and logical attacks.

Is a QSCD certificate obtained in France valid throughout the European Union?

Yes. Article 25(2) of eIDAS establishes mandatory mutual recognition of qualified signatures among all member states. A qualified certificate issued by a French QTSP registered on the national trust list produces the same legal effects in Germany, Spain, or Italy as in its country of issuance. This automatic recognition is one of the major advantages of the system for companies with cross-border contractual activities.

What is the validity period of a QSCD certificate and can it be renewed remotely?

A qualified certificate's validity period is generally set at 1, 2, or 3 years depending on the QTSP's offer. Renewal can be performed remotely for remote QSCDs, provided the holder's identity has already been verified in-person or by video during initial issuance. Most QTSPs send expiration alerts 60 and 30 days before the deadline. Ignoring these alerts risks interruption of qualified signature capability.

Is a QSCD certificate required for all electronically signed acts?

No. The required level of signature depends on the nature of the act and applicable regulatory framework. Qualified signature on QSCD is mandatory for specific acts (electronic notarial deeds, certain public procurement, dematerialized tax filings). For the majority of routine commercial contracts, an advanced signature suffices. It is recommended to consult the electronic signature glossary or seek legal counsel to determine the required level for each act.

How do you verify that a signature is indeed based on a valid QSCD certificate?

Verification is performed by consulting the signed document's metadata through a validation tool compliant with ETSI specifications, such as the European Commission's DSS (Digital Signature Service), freely accessible. This tool verifies the certificate's chain of trust, its status (not revoked), its compliance with the qualified profile, and the presence of qualified time-stamping. Some SaaS platforms like Certyneo integrate this validation report directly into the document management interface.

Conclusion

The QSCD certificate is much more than a technical formality: it is the legal and cryptographic foundation of qualified electronic signature, the only level offering a legal presumption of equivalence to handwritten signature throughout the European Union. In France, obtaining it requires working with a QTSP accredited by ANSSI, undergoing rigorous identity verification, and making an informed choice between physical and remote QSCD—the latter increasingly becoming the standard for organizations seeking agility and scalability.

Certyneo natively integrates certified remote QSCDs into its SaaS platform, enabling your teams to sign at the qualified level without managing any physical support. Whether you are starting from scratch or migrating from another solution, our experts guide you at every step. Discover Certyneo's pricing or contact our team for an assessment of your qualified signature needs.

Try Certyneo for free

Send your first signature envelope in under 5 minutes. 5 envelopes/mo for 14 days, then 2/mo, no credit card required.

Go deeper on the topic

Our comprehensive guides to master electronic signatures.

Certyneo Community

A question about electronic signatures?

Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.