Skip to content
QUALIFIED TRUST SERVICES

Legally compliant digital signatures (eIDAS) to drive forward the digitalization of your business processes.

CORPORATE TRUST SERVICES

Cryptography-based trust services
to protect your digital identities,
data and business secrets.

Qualified electronic signature products based on eIDAS - legally binding and secure.

API GUIDE

Upgrade your application with electronic signatures by primesign.





DOCUMENT SIGNING API

Signing of PDF documents. primesign handles document processing and adds a visual signature stamp.

HASH SIGNING API

Signing of hash values. Your application handles document processing and provides the document viewer.

CASH BOX API

RKSV-compliant JWS- or raw signatures for cash box receipts.





primesign TRUST CENTER

All documents for our qualified trust services, certificate revocation list, root-/CA- certificates, etc.

RESOURCES

Fact sheets, product documentation and more.



BLOG

Insights on digital signatures, eIDAS and trust services.

BG_ICON_ARROW_3-1
Back to all questions

What does a QES rest on — the qualified certificate and the QSCD?

A qualified electronic signature depends on two mandatory components: a qualified certificate binding the signatory's verified identity to a public key, and a qualified signature creation device (QSCD) protecting the corresponding private key and performing the signing operation.

Both may only be supplied by a qualified trust service provider listed on a national EU Trusted List. If any of the three prerequisites is missing — verified identity, qualified certificate, QSCD — the result is not a QES but at most an advanced electronic signature.

Here's how the components fit together:

  • Identity verification under Article 24 eIDAS: Before issuance, the trust service provider verifies the identity by appropriate means and in accordance with the applicable national law.
  • Key generation: The key pair is generated inside the QSCD. The private key never leaves that device.
  • Certificate issuance: The qualified certificate attests the binding between public key and identified person and names the issuing provider.
  • Requirements on the provider: Chapter III of the eIDAS Regulation sets out the requirements from Article 13 onwards. Only providers meeting them and admitted to the Trusted List count as qualified.
  • Local or server-side QSCD: A local QSCD is a smart card or token; a server-side QSCD is a certified hardware security module at the provider, used for remote signing.
  • Revocation: Compromised certificates are revoked centrally via revocation lists and OCSP and become immediately unusable.

How to recognise a genuinely qualified provider:

  • Entry on the Trusted List: The EU Trusted List is the public register of all qualified providers and their services. A provider absent from it cannot issue a QES.
  • Conformity assessment: Qualified providers are audited regularly by a conformity assessment body; those reports form part of your own evidence chain.
  • Public trust centre: Root and CA certificates, revocation lists and service descriptions should be publicly retrievable.

primesign is listed as a qualified trust service provider and operates its own signature creation devices, hosted in the EU. Current root and CA certificates, revocation lists and the corresponding conformity evidence are published in the primesign Trust Center and are therefore independently verifiable.

Benefits

  • Qualified status is public and objectively verifiable
  • Certified signature creation devices secure sole control
  • Central revocation protects against loss or compromise
  • Regular audits by a conformity assessment body
  • Evidence transfers directly into your own audit chain

Still have questions?

Questions about certificates and trust services? Our team can help.

Talk to an expert