What supervision and operating evidence matters?
QTSP status is supervised, not self-declared. eIDAS requires qualified trust service providers to be audited at their own expense at least every 24 months by a conformity assessment body, with the conformity assessment report submitted to the supervisory body within three working days of receipt. Supervisory bodies may also audit or require additional conformity assessment at any time.
The operating evidence should prove that the service still meets the qualified-service requirements after onboarding, certificate issuance, identity or attribute verification, revocation, incident handling, subcontracting, cloud hosting, termination planning, and service changes. Where qualified certificates are issued, eIDAS requires revocation status publication in a timely manner and in any event within 24 hours after receipt of the request.
- Conformity assessment report scope, date, assessment body, and the qualified services covered.
- Supervisory body grant or withdrawal evidence and any conditions, remediation requests, or change approvals.
- Policies for identity verification, attribute verification, certificate issuance, revocation, status services, cryptographic controls, logging, staff competence, subcontractors, and termination.
- Incident and disruption records, including notifications required by applicable eIDAS, NIS2, and data-protection rules.
- Contract and architecture evidence showing the deployed product uses the listed qualified service, not a non-qualified variant or separate reseller service.
What is the minimum evidence pack for using a QTSP in a regulated workflow?
Keep the trusted-list proof, the service description, the conformity assessment scope, the supervisory body status evidence, the certificate or trust-service policy, the relying-party validation result, the contract or order form for the exact service, and logs showing issuance, validation, revocation, or timestamp events relevant to the transaction.
When should QTSP evidence be rechecked?
Recheck QTSP evidence when the supplier, Member State, certificate policy, service type, service status, signing or validation architecture, subcontractor, wallet integration, revocation process, or relying-party legal requirement changes. Also refresh it on a planned cadence because trusted-list status and certificate status information can change.
Article 20 sets recurring conformity assessment and supervisory powers; Article 24 covers identity checks, trustworthy systems, records, termination planning, and certificate revocation-status publication.
ENISA guidance supports supervisory practice and technical oversight of qualified trust service providers.
ETSI baseline policy standard for trust service providers, useful for mapping operational controls to TSP evidence.