primesign Blog: Qualifizierte Signaturen, eIDAS & Fernsignieren

Was ein QTSP garantiert: eIDAS-Vertrauen erklärt

Geschrieben von primesign Editorial | Sep 7, 2026, 12:02:18 PM

In short: A qualified trust service provider (QTSP) is an organisation formally supervised under eIDAS and listed on an EU Trusted List. Its qualified status is what turns an electronic signature into a QES with the highest legal recognition across the EU, and what makes reliable QES validation possible.

When you rely on a qualified electronic signature, you are trusting more than a piece of software. You are trusting the qualified trust service provider (QTSP) that issued the certificate and vouched for the signer's identity. Under Regulation (EU) No 910/2014 (eIDAS), the qualified status is not a marketing label. It is a legal designation earned through audits and ongoing supervision, and it is the reason a QES carries the same legal effect as a handwritten signature throughout the EU. Understanding what that status actually guarantees helps you judge a provider, and helps a relying party decide whether to accept a signature at face value.

What a qualified trust service provider is, exactly

In eIDAS terms, a trust service provider offers services such as creating, verifying and validating electronic signatures, seals, timestamps and certificates. A qualified trust service provider is one that has been granted qualified status by its national supervisory body after a conformity assessment by an accredited body.

The distinction matters. Only a qualified provider may issue the qualified certificates that underpin a QES, and only qualified services benefit from the strongest legal presumptions under the regulation.

Supervision and the EU Trusted List

Two mechanisms give a qualified trust service provider its credibility. The first is supervision: each EU member state designates a supervisory body that monitors qualified providers on its territory. The second is the EU Trusted List, a machine-readable, member-state-published register of qualified providers and the services they are approved to offer.

Before you accept a signature as qualified, its certificate should trace back to a provider on a national EU Trusted List. This is how relying parties confirm status objectively rather than taking a claim on faith.

A qualified trust service provider is expected to:

  • Undergo an initial conformity assessment and regular reassessments by an accredited body.
  • Operate under continuous supervision by a national supervisory body.
  • Appear on the relevant member state's EU Trusted List for each qualified service it provides.
  • Issue qualified certificates and maintain revocation information so signatures can be validated over time.
  • Report significant security breaches to the supervisory body within the required timeframes.

Why QES validation depends on the QTSP

QES validation is the process of confirming that a signature was created with a qualified certificate, using a qualified signature creation device, and that the certificate was valid at the time of signing. Every link in that chain leads back to a qualified trust service provider.

Validators check the signing certificate against the issuing provider's status on the EU Trusted List and against revocation data the provider publishes. Where a qualified timestamp is present, it anchors the moment of signing. Without a genuine QTSP behind the certificate, none of these checks can return a qualified result.

What this means when you choose a provider

For organisations, the practical takeaway is simple: verify status before you rely on it. A credible provider will make its qualified status, supervisory body and EU Trusted List entry easy to confirm, and will support qualified certificates, seals and timestamps that validate cleanly in standard tools such as PAdES-based PDF signatures.

Choosing a qualified trust service provider that is transparent about supervision, EU hosting and validation gives your signed documents durable, cross-border legal standing rather than a signature that merely looks official.

Qualified certificates and long-term trust

A qualified certificate is the credential a qualified trust service provider issues to a verified signer or organisation. It binds an identity to a key pair and is the anchor that lets others confirm who signed. Because the provider maintains revocation information and status responders, relying parties can check whether a certificate was valid at the moment of signing rather than only today.

This is also why durable trust depends on the provider. When qualified timestamps and validation data are captured, a signature backed by a genuine QTSP can remain verifiable for years, long after the original certificate expires.

How primesign helps

primesign operates as a qualified trust service provider under eIDAS, so the signatures, seals and timestamps you create are backed by supervised, EU Trusted List status and validate as qualified across the EU.

Want to be sure your signatures validate as qualified everywhere they are used?