Go to main content
Certyneo

eIDAS Trust Service Provider: Understanding the Role of Trust Services

Trust Service Providers (TSPs) are at the heart of the eIDAS regulation. Discover their obligations, qualification process, and impact on the legal value of your signatures.

Certyneo Legal Team13 min read

Certyneo Legal Team

Writer — Certyneo · About Certyneo

a person sitting at a table with a laptop

Introduction

Since the entry into force of eIDAS Regulation No. 910/2014, Trust Service Providers (TSPs) have formed the backbone of digital trust in Europe. These actors, subject to strict regulation, deliver certificates, time stamps, and qualified signatures that give legal force to electronic transactions. With the adoption of eIDAS 2.0 (EU Regulation 2024/1183), their obligations have evolved further. This article explains what a TSP is, how it is accredited, what services it can provide, and why choosing a qualified provider is crucial for your business.

---

What is a Trust Service Provider (TSP)?

Definition and regulatory scope

According to Article 3 of eIDAS Regulation, a Trust Service Provider is a natural or legal person that delivers one or more trust services, either on a qualified or non-qualified basis. The regulation clearly distinguishes between these two categories: only qualified providers benefit from the presumption of conformity and the enhanced legal value attached to their services.

Trust services covered by eIDAS include:

  • Creation, verification, and validation of electronic signatures (simple, advanced, or qualified)
  • Creation, verification, and validation of electronic seals (for legal entities)
  • Creation, verification, and validation of qualified electronic time stamps
  • Qualified electronic registered mail services
  • Issuance and management of certificates for website authentication (QWAC)
  • Long-term preservation of qualified signatures and seals

Since eIDAS 2.0, the list has expanded to include European digital identity wallets (EUDIW) and qualified electronic attribute attestations, further extending the scope of TSP intervention.

The distinction between qualified and non-qualified TSP

Not all trust service providers have equal legal standing. A non-qualified TSP may operate freely, but its services carry no legal presumption of conformity. A qualified TSP (QTSP, Qualified Trust Service Provider) is listed on the Trusted List of its Member State, published and maintained in accordance with Article 22 of eIDAS and Implementing Decision 2015/1505.

In France, the ANSSI (National Agency for Information Systems Security) acts as the supervisory body (Article 17 eIDAS). The French Trusted List is accessible via the centralized European portal. For more details on the hierarchy of signature levels and their recognition, consult our comprehensive guide to eIDAS 2.0.

---

The TSP qualification process

Conformity audit by a Conformity Assessment Body

To obtain qualified status, a provider must undergo an audit conducted by an accredited Conformity Assessment Body (CAB), accredited by COFRAC in France (or the equivalent national body in each Member State). This audit verifies compliance with the requirements of Annex II of eIDAS (for qualified certificates) and applicable ETSI standards.

The main technical reference standards are:

  • ETSI EN 319 401: general requirements for TSPs
  • ETSI EN 319 411-1 and -2: certification policy and practices for qualified certificates
  • ETSI EN 319 421: policy and practices for time stamping TSPs
  • ETSI EN 319 132: XAdES profile for advanced and qualified signatures
  • ETSI EN 319 122: CAdES profile

The audit results in an evaluation report submitted to the national supervisory body, which may grant, deny, or withdraw qualification. The validity period of a qualification certificate is generally 24 months and renewable.

The European Trusted List: the central register

The European Trusted List (EU Trusted List, or TL) is the central mechanism through which eIDAS ensures cross-border interoperability. Each Member State publishes its national list, and the European Commission aggregates all lists in the List of Trusted Lists (LOTL). This pyramidal architecture allows any verification system to trace back to the European root of trust.

As of January 1, 2026, the LOTL lists more than 200 qualified TSPs across all Member States, collectively issuing millions of qualified certificates annually. For a buyer of SaaS solutions, verifying that a provider is listed on this list is the first due diligence step.

Continuous monitoring obligations

Qualification is not permanent. Qualified TSPs are subject to:

  • Periodic audits (at least every 24 months)
  • Notification without delay of any security incident affecting services (Article 19 eIDAS)
  • Maintaining an up-to-date certification policy (CP) and certification practice statement (CPS) that are publicly available
  • Maintaining a business continuity plan and cessation plan ensuring data preservation in case of discontinuation

---

Qualified Electronic Signature (QES)

The qualified electronic signature is the highest level provided for under eIDAS. It is based on a qualified certificate issued by a QTSP and is created using a qualified electronic signature creation device (QSCD), such as a Common Criteria EAL4+ certified smart card or an HSM (Hardware Security Module) complying with EN 419 221-5 protection profile.

Article 25(2) of eIDAS establishes the principle of equivalence with handwritten signatures: a QES produced in one Member State is recognized in all Member States without additional formalities. This is the only level for which this automatic legal presumption applies. To explore the legal value of electronic signatures according to contractual contexts, we have dedicated a specific guide.

Qualified Electronic Time Stamp

The qualified electronic time stamp (QTS, Qualified Time Stamp) provides irrefutable proof that a document or data existed at a specific moment in time. Under Article 41 of eIDAS, it benefits from a presumption of accuracy of date and time, as well as data integrity.

Typical uses include: proof of patent filing, probative archiving, and logging of contractual events. The qualified electronic time stamp also plays a central role in long-term preservation of signatures.

Qualified Electronic Registered Mail Service

The qualified REMS (Qualified Electronic Registered Mail Service) is the digital equivalent of registered mail with proof of receipt. It guarantees identification of the parties, integrity of transmitted data, time-stamping of sending and receipt. Article 44 of eIDAS confers on it a presumption of data integrity and accuracy of sending and receipt dates. This service is particularly useful for formal notices, contract terminations, or legal notifications.

---

Choosing your TSP provider: key criteria

Qualification, interoperability, and geographic coverage

The first criterion is obviously the presence on the Trusted List of the Member State(s) in which you operate. But beyond formal qualification, several practical dimensions come into play:

  • Interoperability: does the TSP support ETSI standard formats (XAdES, PAdES, CAdES, JAdES)? Will the signatures produced be verifiable by third-party tools such as the European DSS validator?
  • Service availability: what SLA is guaranteed? Are QSCD infrastructures geographically redundant?
  • Geographic coverage: if you operate in multiple European countries, does the TSP offer qualified certificates recognized in those countries?
  • APIs and integration: are REST/SOAP APIs well documented? Is there an SDK or native integration with your application stack?

Pricing transparency and commercial model

Qualified TSPs typically charge per certificate issued, per transaction volume, or via annual subscriptions. Prices vary considerably: an individual qualified certificate costs between €50 and €200 per year (excluding VAT), while bulk signature solutions (server-based) can exceed several thousand euros annually. Compare market offers with our comparison of electronic signature solutions.

Support, GDPR compliance, and data localization

A TSP processing personal data (which is systematically the case for qualified certificate issuance) is subject to GDPR Regulation 2016/679. Verify:

  • Data localization (EU hosting or outside EU?)
  • Data retention and deletion policies
  • The existence of a designated Data Protection Officer (DPO)
  • Any potential subcontracting and applicable Standard Contractual Clauses (SCCs)

For enterprises wishing to migrate from an existing solution to a more compliant provider, our guide on migration from DocuSign or YouSign to Certyneo details the steps and precautions to take.

Foundational texts

The legal framework for trust service providers rests on several interconnected regulatory layers.

eIDAS Regulation No. 910/2014/EU (amended by EU Regulation 2024/1183, known as "eIDAS 2.0"): the reference text defining trust services, qualification levels, TSP obligations (Articles 13 to 22 for general obligations, Articles 23 to 45 for specific qualified services) and the liability regime (Article 13: liability for any loss or damage caused intentionally or through negligence, with reversal of burden of proof in favor of the victim).

French Civil Code, Articles 1366 and 1367: Article 1366 establishes the principle of equivalence between electronic writing and paper-based writing subject to author identification and integrity. Article 1367 defines electronic signature and its presumption of reliability when qualified under eIDAS.

Decree No. 2017-1416 of September 28, 2017 relating to electronic signature: specifies in French law the technical conditions for reliable electronic signature, explicitly referring to eIDAS requirements.

Security and notification obligations

Article 19 of eIDAS requires TSPs to implement appropriate technical and organizational measures to manage risks to their services. In the event of a security incident or integrity loss having a significant impact on the service or personal data, the TSP must notify the supervisory body without undue delay and, at the latest, within 24 hours of becoming aware of it. This obligation is cumulative with that provided for in Article 33 of GDPR No. 2016/679 (notification to the supervisory authority—CNIL in France—within 72 hours).

The NIS2 Directive (2022/2555/EU), transposed into French law by Law No. 2023-703 of August 1, 2023, subjects qualified TSPs to strengthened cyber risk management and incident notification requirements as essential or important entities depending on their size.

Liability and sanctions

The eIDAS liability regime (Article 13) is stringent: the TSP is presumed liable for any loss or damage caused to any natural or legal person by a failure to fulfill its obligations. It must prove the absence of fault. National sanctions for non-compliance may include withdrawal of qualification, administrative fines (up to €10 million or 2% of worldwide turnover under GDPR), and civil liability actions. In France, ANSSI may also impose corrective measures.

Use cases: eIDAS TSP in practice

A law firm managing digitalized procedural documents

A 50-lawyer law firm regularly handles documents requiring qualified signatures: briefs, representation mandates, business transfer deeds. By relying on a QTSP listed on the French Trusted List, the firm generates PAdES-LTV signatures (Long-Term Validation) incorporating a qualified time stamp. Result: the processing time for a signable document drops from 3-4 days (paper circulation) to less than 2 hours. The probative value of each signature is automatically verifiable by the opposing party and courts without expert assessment, reducing procedural disputes by approximately 70% according to on-the-ground feedback from comparable firms.

An industrial SME securing cross-border supplier contracts

A 180-employee French industrial SME sourced from suppliers in Germany, Poland, and Spain previously had to have certain contractual documents legalized or apostilled to guarantee cross-border recognition. By integrating via API a qualified TSP issuing certificates recognized throughout the EU (Article 25(2) eIDAS), the SME eliminates these formalities. The 300 annual supplier contracts are now electronically signed with automatic legal recognition in all three partner countries. The estimated savings in administrative costs and processing time reaches 35-45% across the entire contract cycle, consistent with ranges published by sector studies from the Mechanical Industries Federation.

A hospital group preserving the integrity of its digital medical records

A hospital group of approximately 1,200 beds must guarantee the integrity and authenticity of its surgical reports, prescriptions, and informed consents over storage periods of up to 20 years (Article R. 1112-7 of the French Public Health Code). By using a qualified electronic time stamp service provided by a QTSP, the group creates irrefutable integrity proof immediately upon document creation. Internal audits and HAS (High Authority for Health) controls can now automatically verify the integrity of each archived document, reducing the workload of quality teams by approximately 25% according to sector benchmarks in healthcare.

Frequently asked questions

What is a qualified trust service provider under eIDAS?

A qualified trust service provider (QTSP) is an organization that has obtained qualified status from the supervisory body of its Member State (ANSSI in France) after conformity audit by an accredited body. It is listed on the national Trusted List published in accordance with Article 22 of eIDAS. This status enables it to deliver services with legal presumption of conformity: qualified signatures, qualified time stamps, qualified seals, and qualified electronic registered mail.

How do I verify that a TSP provider is truly qualified under eIDAS?

Verification is performed via the official European Commission portal "eIDAS Trusted List Browser" (tlbrowser.tsl.website) or via the ANSSI portal for French providers. Simply search for the provider's name or service URL. The list is updated in real time. Any provider claiming to be qualified without appearing on this list enjoys no presumption of law attached to qualified eIDAS services.

Is a TSP qualified in one European country recognized throughout the EU?

Yes. This is one of the fundamental contributions of eIDAS: the principle of mutual cross-border recognition (Article 25(2) for signatures, Article 35(2) for seals, Article 41(2) for time stamps). A qualified electronic signature created using a certificate issued by a French QTSP is legally recognized in Germany, Spain, Poland, or any other Member State without additional steps. This interoperability is the main raison d'être of eIDAS at European level.

What is the difference between a qualified certificate and an advanced certificate?

An advanced certificate can be issued by any provider, qualified or not, according to minimum technical requirements. A qualified certificate may only be issued by a QTSP listed on the Trusted List, based on Annex I of eIDAS (certificate content) and following rigorous verification of the applicant's identity in person or via a qualified remote identification process (QES). The qualified certificate is the necessary condition for issuing a qualified electronic signature, the only one to benefit from the presumption of equivalence with a handwritten signature.

Can a TSP lose its eIDAS qualification? What are the consequences?

Yes. The supervisory body may withdraw or suspend a TSP's qualification in case of serious breach of its obligations (negative audit, unresolved major security incident, false statement). Withdrawal is published on the Trusted List with a "revoked" status. Certificates issued before revocation remain valid if their trust chain is preserved in compliant probative archiving. However, no new qualified certificates may be issued after revocation, and services cease to benefit from eIDAS legal presumptions.

Conclusion

Trust Service Providers (TSPs) are far more than mere technical vendors: they form the regulatory and legal foundation on which all the probative value of electronic signatures in Europe rests. Understanding their role, qualification process, and obligations is essential for any enterprise seeking to secure its digital transactions with indisputable legal value. The choice of a QTSP listed on the European Trusted List is not optional when aiming for qualified signatures or qualified time stamps.

Certyneo relies exclusively on qualified TSP providers recognized under eIDAS to guarantee you electronic signatures with full legal value, interoperable throughout the European Union. Ready to secure your contract workflows? Create your Certyneo account for free or contact our team for a personalized demonstration.

Try Certyneo for free

Send your first signature envelope in under 5 minutes. 5 envelopes/mo for 14 days, then 2/mo, no credit card required.

Go deeper on the topic

Our comprehensive guides to master electronic signatures.

Certyneo Community

A question about electronic signatures?

Join the Certyneo community: ask your questions, share your answers and connect with thousands of users and our team.