- Supports the supervision lens for qualified trust services and the relationship between supervisory authorities, QTSPs, and conformity assessment.
"guidelines on supervision of qualified trust service providers pursuant to Art.20"
Review this workflow before relying on a qualified trust service provider for signatures, seals, timestamps, website authentication certificates, attestations, archiving, ledgers, or related qualified trust services.
The checks focus on trusted-list validation, exact qualified service scope, certificate and revocation evidence, published policies, supervision, audits, termination planning, incident posture, and records to retain.
Structured answer sets in this page tree.
Cited legal and guidance references.
Select a only after the relevant Member State shows both the provider and the exact qualified service you will use. Qualified status is service-specific: the same provider may offer qualified and non-qualified services. This workflow helps procurement, product, security, legal, and compliance teams verify that status, test the service evidence, review operating terms, and define monitoring before onboarding or continued reliance.
Start with the Member State and the Commission List Of Trusted Lists, not with a vendor certificate bundle or sales deck. eIDAS requires Member States to establish, maintain, and publish trusted lists that identify qualified trust service providers and the qualified trust services for which they are responsible.
Record the legal provider name, Member State, trusted-list location, scheme operator, service name, service type identifier, service digital identity, current service status, status start time, and relevant service history. If the exact service is not shown with a suitable qualified status, do not treat it as qualified. A vendor explanation can resolve an identity or scope mismatch, but it cannot replace the trusted-list indication required before a qualified trust service may begin.
A can provide more than one service, and only some services may be qualified. Scope the review to the exact certificate, timestamp, validation, preservation, registered delivery, attestation, archiving, ledger, or remote signing service that the product will consume.
For certificate-based services, review the certificate policy, , certificate profile, usage limits, revocation mechanism, validity information, and any qualified-certificate statements that indicate the applicable legal framework and certificate purpose. These checks do not apply unchanged to every trust service. For timestamps, registered delivery, attestations, archiving, ledgers, validation, preservation, or remote-device management, use the service-specific policy and requirements instead of forcing a certificate-issuance checklist onto the service.
Qualified certificate diligence must distinguish electronic signature, electronic seal, and website authentication uses. A can help identify a certificate's declared status, purpose, or QSCD relationship, but the certificate extension does not replace the trusted-list check for the issuing qualified service.
The operational review should connect provider claims to the eIDAS supervision cycle. A must undergo a conformity-assessment-body audit at least every 24 months, notify its supervisory body at least one month before a planned audit, and submit the resulting report to that body within three working days of receipt. The law requires delivery to the supervisory body, not publication to customers, so record the report or scope statement only when it is lawfully made available.
The monitoring plan should also cover planned service changes, cessation, significant security incidents, supply-chain dependencies, and termination arrangements. A must notify its supervisory body at least one month before a change to a qualified service and at least three months before intended cessation. Reopen diligence when the relied-on service changes, its qualified status changes, or the provider announces cessation.
Keep the record useful for a later customer question, audit, dispute, incident, or migration. The evidence should show why the provider and exact qualified service were acceptable at onboarding and what would trigger a new review.
For ongoing monitoring, separate static onboarding evidence from time-sensitive status evidence. Trusted-list status, service scope, revocation availability, incident posture, and material provider changes can change after the initial selection.
Sorena can help structure the trusted-list checks, certificate evidence, policy review, supervision questions, and monitoring triggers into a reusable QTSP diligence record.
Ask questions tied to cited sources about QTSP status, qualified services, trusted lists, certificates, revocation evidence, and supervision using the cited sources on this page.
Review your provider shortlist, trusted-list evidence, certificate scope, policy gaps, and monitoring triggers with Sorena.
"guidelines on supervision of qualified trust service providers pursuant to Art.20"
"Collection of evidence"
"Information on how to validate the certificate"
"The qcStatements certificate extension can contain any statement by the certificate issuer"
"at a given time in the past"
"audited at their own expense at least every 24 months"