If the organization provides a qualified trust service, the compliance file should be built around supervisory status, conformity assessment, security controls, identity verification, service terms, incident handling, certificate databases where relevant, and termination planning. eIDAS ties qualified status to a supervisory body and to each qualified service granted that status.
A QTSP must be audited at its own expense at least every 24 months by a conformity assessment body and submit the resulting report to its supervisory body within three working days after receipt. The supervisory body may also audit or require an assessment at any time. Treat the two-year interval as a maximum cycle, not a reason to defer reviews after a material service, control, ownership, or threat change.
If the organization relies on a QTSP, procurement evidence should identify the exact qualified service being bought, not only the vendor name. Keep the trusted-list entry, certificate policy or practice statement, qualified service status, conformity or audit evidence supplied by the provider, service terms, limitations, revocation/status service information, and termination or continuity commitments needed to validate historic evidence.