Skip to content
QUALIFIED TRUST SERVICES

Legally compliant digital signatures (eIDAS) to drive forward the digitalization of your business processes.

CORPORATE TRUST SERVICES

Cryptography-based trust services
to protect your digital identities,
data and business secrets.

Qualified electronic signature products based on eIDAS - legally binding and secure.

API GUIDE

Upgrade your application with electronic signatures by primesign.





DOCUMENT SIGNING API

Signing of PDF documents. primesign handles document processing and adds a visual signature stamp.

HASH SIGNING API

Signing of hash values. Your application handles document processing and provides the document viewer.

CASH BOX API

RKSV-compliant JWS- or raw signatures for cash box receipts.





primesign TRUST CENTER

All documents for our qualified trust services, certificate revocation list, root-/CA- certificates, etc.

RESOURCES

Fact sheets, product documentation and more.



BLOG

Insights on digital signatures, eIDAS and trust services.

BG_ICON_ARROW_3-1
Back to all questions

What should businesses look for when choosing a trust service provider?

The first criterion is objectively verifiable: the provider must appear on the EU Trusted List as a qualified trust service provider. Without that status it cannot issue qualified signatures, regardless of product quality.

Beyond that, the decision rests on identification options, integration depth, available deployment models, the provider's legal jurisdiction and contractually guaranteed availability. The point most often overlooked is verifiability after the contract ends.

Here's the evaluation checklist:

  • Qualified status: Listed on the EU Trusted List, publicly and independently verifiable. Everything else is moot without it.
  • Signature levels supported: Does the provider cover SES, AES, QES and qualified seals, or only part of the range?
  • Identification options: In particular eID signing with ID Austria and the German national ID card, plus video identification as a fallback.
  • Integration depth: Available APIs, ready-made connectors for common systems, and support for hash signing.
  • Deployment models and jurisdiction: Hosting location, operating models, and the registered office and group structure of the provider.
  • Availability and support: Contractually guaranteed availability, a public status page and support hours.
  • Long-term validation: PAdES with LTV and qualified timestamps as standard, not as a paid extra.
  • Pricing and scaling: How does pricing behave as volumes and use cases grow?
  • eIDAS 2.0 readiness: Is EUDI Wallet support on the roadmap, and when?
  • Exit scenario: Do signed documents remain verifiable without the provider, or is the evidence stored proprietarily?

The point most often overlooked:

  • Verifiability after contract end: A correctly produced PAdES document with LTV stays verifiable independently of the provider; a proprietary signature record does not.
  • Ask explicitly: Ask which signature format is produced and whether verification works without access to the provider's platform.
  • Put it in the contract: Format, exportability and handover of evidence belong in the contract, not in the product brochure.

primesign is a Graz-based listed qualified trust service provider within the CRYPTAS group, with locations in Vienna, Graz, Düsseldorf, Hengelo and Stockholm, and global reach through its partnership with the eMudhra Group. Through OEM and reseller models, integrators can serve every EU market from a single integration.

Benefits

  • Objectively verifiable criteria instead of product claims
  • Comparable offers through consistent requirements
  • No unpleasant surprises at exit or provider change
  • One provider instead of many national integrations
  • Future-proofing through eIDAS 2.0 readiness

Still have questions?

Compare your requirements in a conversation with our experts.

Talk to an expert