Trust service providers (TSPs) that issue certificates for electronic signatures are subject to extensive legal and technical requirements.These are anchored, among other things, in the eIDAS Regulation, which aims to ensure that electronic signatures and associated transactions are legally binding and recognised throughout the EU.
If, as a trust service provider, you wish to be officially included in the European eIDAS Trusted Service List (TSL), you must therefore prove that your service fulfils the security requirements set out in the eIDAS Regulation.
We support you in keeping track of the jungle of requirements and accompany you on your way to qualification status. From checking the necessary requirements through to conformity assessment or re-certification, we offer you both the complete eIDAS package and individual services.
Our offer is aimed at a wide range of organisations involved in the secure, legally binding distribution and use of digital signatures:
This is how we support you holistically:
Training & Qualification
Concept & preparation
Testing & conformity assessment
Audit of your implementation based on the eIDAS Regulation, including
Application of the following ETSI standards:
Certification & re-certification
An electronic signature serves as proof that an electronic document has been signed by a natural person. The European eIDAS Regulation also defines the advanced electronic signature and the qualified electronic signature (QES), which are relevant forms of signature for business transactions. They enable the signatory to be identified and are clearly assigned to the signatory. A qualified electronic signature is also used when the written form is required by law. It has the same legal effect as a handwritten signature, for example when contracts are concluded between companies or for legally binding transactions.
A simple electronic signature (EES) is any form of electronic data with which a person signs a document. The advanced electronic signature (AES) already offers more security, as it is clearly assigned to a person and makes changes to the document recognisable. The qualified electronic signature (QES) is the highest level - it is based on a qualified certificate and is generated with a secure signature creation device. It is legally equivalent to a handwritten signature.
A QES makes it possible to process legally binding contracts, applications or notifications completely digitally - efficiently, securely and without media discontinuity. Your company can use it to speed up processes and fulfil regulatory requirements, particularly in European business transactions.
The eIDAS Regulation (electronic IDentification, Authentication and trust Services; EU No. 910/2014) is the European legal framework for electronic identification and trust services. It regulates the recognition of e.g. electronic signatures, seals, time stamps and other trust services in all EU member states. Only those who meet the eIDAS requirements can be recognised as qualified trust service providers and offer legally binding electronic transactions.
Overall, the duration of the conformity assessment process depends on, for example, the number of trust services targeted, the complexity of your infrastructure and your current implementation status. As a rule, a complete conformity assessment process - including project kick-off, stage 1 audit, stage 2 audit, report preparation and certification - takes 6 months, although possible non-conformities during the audit can extend the duration.
As part of the conformity assessment, independent evaluators from conformity assessment bodies (CAB) (such as TÜV NORD CERT) check your documents (e.g. CP/CPS/TSPS, Policy Disclosure Statement, GTC and Termination Plan) for compliance with criteria and requirements, technical and organisational measures based on the relevant eIDAS articles and standards such as ETSI EN 319 401. The aim is to objectively determine the conformity of your trust service with the requirements of the eIDAS Regulation.
Yes, authorisation as a qualified trust service provider is subject to regular recertification, as the certificate is valid for a total of 2 years. The recertification audit takes place within the last 6 months of the certificate validity of the currently valid certificate (months 18 - 24).
We support you throughout the entire life cycle of your trust service - from training as an eIDAS.PROFESSIONAL, workshops, preliminary audits, successful conformity assessments and certifications through to successful inclusion in the EU Trusted List (EUTL). Our team of experts offers comprehensive advice, audits and technical assessments from a single source.
We support you with the technical depth of over 500 PKI projects, years of regulatory experience as one of the first conformity assessment bodies and a clear understanding of the requirements of modern companies - from the first eIDAS.PROFESSIONAL training to the successful QES certification of your electronic signature solution.