FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
19of19items
Across 6 modules • Updated Jul 25, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
What is a qualified trust service provider under eIDAS?

What supervision and operating evidence matters?

QTSP status is supervised, not self-declared. eIDAS requires qualified trust service providers to be audited at their own expense at least every 24 months by a conformity assessment body, with the conformity assessment report submitted to the supervisory body within three working days of receipt. Supervisory bodies may also audit or require additional conformity assessment at any time.

The operating evidence should prove that the service still meets the qualified-service requirements after onboarding, certificate issuance, identity or attribute verification, revocation, incident handling, subcontracting, cloud hosting, termination planning, and service changes. Where qualified certificates are issued, eIDAS requires revocation status publication in a timely manner and in any event within 24 hours after receipt of the request.

  • Conformity assessment report scope, date, assessment body, and the qualified services covered.
  • Supervisory body grant or withdrawal evidence and any conditions, remediation requests, or change approvals.
  • Policies for identity verification, attribute verification, certificate issuance, revocation, status services, cryptographic controls, logging, staff competence, subcontractors, and termination.
  • Incident and disruption records, including notifications required by applicable eIDAS, NIS2, and data-protection rules.
  • Contract and architecture evidence showing the deployed product uses the listed qualified service, not a non-qualified variant or separate reseller service.

What is the minimum evidence pack for using a QTSP in a regulated workflow?

Keep the trusted-list proof, the service description, the conformity assessment scope, the supervisory body status evidence, the certificate or trust-service policy, the relying-party validation result, the contract or order form for the exact service, and logs showing issuance, validation, revocation, or timestamp events relevant to the transaction.

When should QTSP evidence be rechecked?

Recheck QTSP evidence when the supplier, Member State, certificate policy, service type, service status, signing or validation architecture, subcontractor, wallet integration, revocation process, or relying-party legal requirement changes. Also refresh it on a planned cadence because trusted-list status and certificate status information can change.

Citations
What is a QWAC under the EU eIDAS Regulation?

What does a QWAC prove under eIDAS?

A certificate for website authentication makes it possible to authenticate a website and link that website to the natural or legal person to whom the certificate is issued. A QWAC adds the eIDAS qualified layer: the certificate must be issued by a qualified trust service provider and meet Annex IV requirements.

A working TLS connection does not complete the QWAC check. The evidence should show who the certificate identifies, which domain names are covered, which qualified trust service provider issued it, and where relying parties can check certificate validity or revocation status.

  • Confirm that the certificate is explicitly indicated as a qualified certificate for website authentication.
  • Check that the subject identity, address elements, and domain names match the website or service being authenticated.
  • Record the certificate validity period, serial or certificate identity code, issuer, and status-service location.
  • Treat QWAC evidence as website identity evidence, not as proof that the whole transaction, application, or message payload has been sealed or signed.

What is a QWAC under the EU eIDAS Regulation?

A QWAC is a qualified certificate for website authentication. eIDAS defines it as a website-authentication certificate issued by a qualified trust service provider that meets Annex IV. It links the website to the named natural or legal person and carries required certificate information such as qualified-certificate indication, issuer identity, subject identity, domain names, validity period, certificate identity code, issuer signature or seal, and certificate-status service information.

Is a QWAC the same as an ordinary TLS certificate?

No. A QWAC can be used in the website-authentication context, but its eIDAS significance comes from qualified status, the qualified trust service provider, and Annex IV content. A normal TLS certificate may secure a connection without being a qualified certificate for website authentication under eIDAS.

Citations
What is a QWAC under the EU eIDAS Regulation?

How should a relying party validate a QWAC?

Validation should combine certificate checks with eIDAS status checks. First confirm that the issuer and service are qualified for the relevant trust service on an EU trusted list, because eIDAS allows a qualified trust service provider to provide a qualified trust service after qualified status appears in the trusted lists.

Then validate the certificate itself: domain match, certificate chain, validity period, certificate-status endpoint, revocation status, and the QWAC-specific qualified-certificate statements. eIDAS requires qualified trust service providers issuing qualified certificates to publish revocation status and provide validity or revocation information to relying parties.

  • Use the EU and national trusted-list information to confirm the QTSP and qualified service status.
  • Check the website domain against the certificate's domain-name information before treating it as the authenticated endpoint.
  • Use the certificate validity-status service, such as the CRL or OCSP location identified in the certificate profile, before relying on the certificate.
  • Keep validation logs that show the certificate examined, trusted-list result, revocation or validity status, validation time, and any exception decision.

Where do EU trusted lists fit into QWAC validation?

Trusted lists are the source for qualified trust service provider and qualified service status. eIDAS requires Member States to establish, maintain, and publish trusted lists for the qualified trust service providers and qualified trust services for which they are responsible. A QWAC review should therefore verify both the certificate contents and the issuer/service status shown through the trusted-list framework.

What records should a team keep after validating a QWAC?

Keep the certificate or fingerprint, covered domain names, issuer and QTSP name, trusted-list status result, validation timestamp, revocation or validity-status result, renewal or expiry date, and the system or website that relied on the certificate. Those records make later renewal, incident, and relying-party reviews traceable.

Citations
ETSI TS 119 612 - Trusted Lists

Specifies trusted-list structure and service information used by validators to interpret qualified trust service provider and qualified service status.

What is a QWAC under the EU eIDAS Regulation?

What changed for browsers and QWACs under eIDAS 2?

The eIDAS 2 amendments add browser-facing duties for qualified certificates for website authentication. Providers of web browsers must recognise QWACs issued in accordance with Article 45 and display the identity data and additional attested attributes in a user-friendly way. The small-enterprise exception applies only to the support and interoperability duty.

That browser rule should not be read as a guarantee that every deployed browser, user interface, certificate store, or relying-party application already presents QWAC identity information in the same way. For implementation work, keep the distinction clear: the certificate may satisfy eIDAS QWAC requirements, while browser support and display behaviour are separate deployment and interoperability checks.

Commission Implementing Regulation (EU) 2025/2527 is in force but applies from 6 January 2027. It sets different reference standards for QWACs used for TLS authentication outside a web-browser and for other QWACs, including browser contexts. Before that application date, do not present those listed 2025 standards as already mandatory under the implementing regulation.

  • For website owners, confirm whether the intended browser and client environment recognises and displays the QWAC identity information needed for the user journey.
  • For relying-party systems, do not rely on browser display alone; keep machine-readable validation evidence for issuer, service status, certificate status, and domain match.
  • For incidents, remember that eIDAS allows browser precautionary measures only for substantiated concerns about security breaches or loss of integrity of an identified certificate or set of certificates.
  • For procurement, ask certificate providers how the QWAC profile, trusted-list status, revocation publication, and renewal process will be evidenced.

Does eIDAS require browsers to recognise QWACs?

Yes, Article 45 as amended requires providers of web browsers to recognise qualified certificates for website authentication issued in accordance with Article 45 and to display attested identity data and additional attested attributes in a user-friendly manner. The limited exception for microenterprises and small enterprises during their first five years as providers of web-browsing services applies to the support and interoperability duty.

Can a QWAC replace an electronic seal or signature under eIDAS?

No. A QWAC authenticates a website endpoint and links it to the named person or legal entity. It is not the same artifact as a qualified electronic seal or qualified electronic signature, which are used for different eIDAS trust-service purposes and evidence models.

Citations
Page 2 of 2