QTSP authorization is not finished after the initial trusted-list entry. eIDAS Article 24 requires a QTSP to inform the supervisory body before changes to qualified trust services or intended cessation, maintain appropriate risk-management measures, use trustworthy systems, keep relevant issued and received information accessible, and maintain an up-to-date termination plan.
For security breaches or disruptions that have a significant impact on the trust service or personal data maintained in it, eIDAS requires notification to the supervisory body, affected identifiable individuals, other relevant competent bodies where applicable, and, if the supervisory body determines that disclosure is in the public interest, the public. The notification must be made without undue delay and in any event within 24 hours after the provider becomes aware of the breach or disruption.