Artifact GuideEU

eIDAS QWACs website authentication certificates

Qualified website authentication certificates are eIDAS trust-service certificates that authenticate a website and link it to the natural or legal person that operates the domain.

This page helps check Annex IV certificate content, QTSP qualification, trusted-list status, browser-recognition obligations, and validation evidence without treating an ordinary TLS certificate as automatically qualified.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

A is a qualified certificate for website authentication under eIDAS. To establish that status, confirm that a qualified trust service provider issued the certificate, the certificate meets the Annex IV data requirements, and the issuing service had the required status in the EU trusted-list evidence. Certificate-policy and QCStatement evidence support that review. A TLS certificate or successful handshake alone does not establish qualification.

Section 1

What a QWAC is under eIDAS

eIDAS defines a certificate for website authentication as an electronic attestation that authenticates a website and links that website to the natural or legal person to whom the certificate is issued. A qualified certificate for website authentication is that certificate type when it is issued by a qualified trust service provider and meets Annex IV.

A TLS certificate may support encrypted website connections, but eIDAS qualification depends on legal status, QTSP issuance, Annex IV certificate data, and trusted-list status. Certificate-policy evidence supports the review. ETSI EN 319 412-5 also states that the extension is not processed as part of ordinary RFC 5280 path validation, so a basic certificate-chain result cannot establish qualification.

  • Confirm that the certificate is for website authentication, not electronic signature or electronic seal use.
  • Confirm that the issuing provider is a qualified trust service provider for the relevant certificate service.
  • Confirm that the certificate includes an automated indication that it was issued as a qualified certificate for website authentication.
  • Keep the certificate, issuer details, certificate policy or CPS reference, trusted-list result, and validation timestamp together as the evidence pack.
Section 2

What Annex IV requires a QWAC to contain

Annex IV is the first content checklist. A must identify itself, in at least an automated-processing form, as a qualified certificate for website authentication. It must also identify the qualified trust service provider, the subject, address elements, operated domain name or names, validity period, certificate identity code, issuer signature or seal, and certificate-status information.

The certificate links the website to the certificate subject, but that link does not prove ownership of every statement or transaction made through the site. The review record should show the free location of the certificate supporting the issuer signature or seal and the place where certificate validity status can be checked.

  • Issuer data: Member State of establishment plus the QTSP name and, where applicable, registration number.
  • Subject data: natural-person name or pseudonym, or legal-person identifying data and registration number where applicable.
  • Website data: the domain names operated by the certificate subject.
  • Lifecycle data: validity start and end, unique certificate identity code, and validity-status service location.
  • Issuer assurance: advanced electronic signature or seal of the issuing QTSP and the free location of the supporting certificate.
Section 3

How trusted lists support QWAC validation

A certificate should not be treated as qualified only because its visible subject fields look plausible. ETSI TS 119 612 explains that let interested parties determine whether a trust service is or was operating in compliance with relevant requirements, including the current status and status history of the service.

For QWACs, check the EU List of route to the relevant Member State trusted list, the trust service provider entry, the service type and service status, and the service information extensions that indicate website authentication. ETSI TS 119 612 includes QCForWSA and For Web Site Authentication indicators for certificates or services issued for website authentication.

  • Validate the source of the trusted list and the relevant national trusted-list entry before relying on it.
  • Check that the trust service and provider had the required status on the date being assessed; current status alone is insufficient for an earlier date.
  • Look for website-authentication-specific trusted-list information such as QCForWSA or For Web Site Authentication where the list uses those extensions.
  • Retain the LOTL or national-list version, issue time, service status, status start time, selected CA entry, and validation policy used.
Section 4

Browser recognition and the certificate distinction

Article 45 says qualified certificates for website authentication issued in accordance with Article 45(1) must be recognised by web-browser providers. Those providers must display the identity data and additional attested attributes in a user-friendly manner and support and interoperate with the certificates. The support and interoperability duty has a limited exception for microenterprises or small enterprises during their first five years of operating as web-browser service providers.

Browser recognition does not establish the certificate's qualified status and does not guarantee that every browser presents identity information in the same interface. Qualification still depends on Annex IV content, QTSP issuance, the applicable Article 45 requirements, and trusted-list evidence; and CP/CPS material help automated and policy review but do not replace the legal status check.

Article 45a permits a browser provider to take precautionary measures against an identified certificate or certificate set only when it has substantiated concerns about a security breach or loss of integrity. The browser provider must notify the Commission, supervisory body, certificate subject, and issuing QTSP without undue delay. If the supervisory investigation does not withdraw qualified status, the authority must ask the browser provider to end the measures.

  • Separate browser display behavior from certificate qualification evidence.
  • Do not infer status from a padlock, ordinary domain validation, or a successful TLS handshake alone.
  • For procurement or relying-party onboarding, ask the provider for the certificate policy, CPS or disclosure material, trusted-list status evidence, and certificate-profile evidence.
  • Record whether the review is for website authentication, EUDI Wallet relying-party presentation, procurement, or internal trust-anchor configuration because the evidence use may differ.
  • If a browser blocks or limits a , retain the affected certificate set, stated security concern, browser notice, supervisory acknowledgement, investigation outcome, qualified-status decision, and date the measure ended or remained in place.
Section 5

Validation and evidence checklist

This checklist is relevant when accepting a from a supplier, configuring relying-party trust, reviewing a website authentication claim, or preparing evidence for compliance review. The aim is a reproducible validation record, not a general certificate inventory.

A record should show that the certificate was qualified for website authentication at the relevant time, the issuing service had granted qualified status in the trusted-list evidence used, and the certificate content matches the domain and subject identity facts relied on by the business.

Is every TLS certificate a under eIDAS?

No. A is a qualified certificate for website authentication issued by a qualified trust service provider and meeting Annex IV. Ordinary TLS certificate validation does not by itself prove eIDAS qualified status.

What should a team check first when reviewing a claim?

Start with the certificate's website-authentication purpose, the issuing QTSP, Annex IV data fields, and trusted-list status for the relevant date. Then review certificate policy, CPS, QCStatement, and status-service evidence.

  • Capture the certificate chain, leaf certificate, subject identity data, domain names, validity period, serial or identity code, and status-service URL.
  • Verify Annex IV elements and flag missing or conflicting issuer, subject, domain, validity, signature or status-service data.
  • Check QCStatement evidence for EU qualified-certificate status and website-authentication type, including the id-etsi-qct-web purpose where available.
  • Check trusted-list evidence for the issuing QTSP, service type, qualified status, website-authentication extension, status history, and list issue time.
  • Review the issuer CP, CPS, terms or PKI disclosure statement for the certificate policy asserted in the certificate and the web-authentication service it covers.
  • Save the validation result, validation time, trusted-list source and version, certificate-status result, reviewer, and the reason the certificate is accepted, rejected, or escalated.
Primary sources

References and citations

etsi.org
Referenced sections
  • Supports the CP, CPS, subscriber, relying-party, and web-authentication certificate-policy evidence expected for certificate issuing services.
"Certification Practice Statement"
etsi.org
Referenced sections
  • Supports checking QCStatement evidence that a certificate is an EU qualified certificate and is issued for website authentication.
"id-etsi-qct-web"
etsi.org
Referenced sections
  • Supports the trusted-list checks for qualified status, service status history, CA selection, and website-authentication indicators.
"For Web Site Authentication"
Related guides

Explore more topics

eIDAS 2 deadlines and compliance calendar for EUDI Wallet and trust services
eIDAS 2 calendar separating binding EUDI Wallet, reporting, and trust-service dates from implementation milestones and technical programme updates.
eIDAS 2.0 vs eIDAS: EUDI Wallet and trust-service changes
Compare the original eIDAS electronic identification and trust-service framework with the eIDAS 2.0 amendments for EUDI Wallets, relying parties, attestations, QWACs, and supervision.
eIDAS Certificates and Authentication: qualified certificates, QWACs, and validation checks
Official source guide to eIDAS qualified certificates, website authentication certificates, trusted lists, relying-party checks, and validation evidence.
eIDAS checklist and evidence pack for trust services, signatures, and EUDI Wallet relying parties
Build an eIDAS evidence pack for qualified trust services, electronic signatures, trusted-list checks, certificate validation, supervisory records, and EUDI Wallet relying-party controls.
eIDAS compliance guide for trust services, QTSPs, signatures, and EUDI Wallet relying parties
Official source eIDAS compliance guide for trust-service classification, QTSP supervision evidence, qualified signatures, seals, time stamps, certificates, trusted-list validation, and EUDI Wallet relying-party records.
eIDAS electronic signatures: SES, AES, QES legal effect and evidence
An official source guide to eIDAS electronic-signature legal effect: SES, AES, QES, qualified certificates, QTSP trusted-list checks, validation, recognition, and evidence records.
eIDAS penalties and fines for trust service providers
Guide to eIDAS Article 16 fine floors, national penalty rules, supervisory action, qualified-status withdrawal, and trusted-list evidence.
eIDAS QES validation checks for relying parties
How to validate a qualified electronic signature under eIDAS: certificate, QTSP, trusted-list, QSCD, integrity, validation result, and evidence records.
eIDAS Qualified Trust Services: QTSP Selection
How to select an EU eIDAS qualified trust service provider: identify the qualified service type, verify trusted-list status, review supervision evidence, and retain certificate-policy records.
eIDAS remote signature and cloud HSM controls for QTSPs
Source-grounded guide to eIDAS remote signature controls: remote QSCD scope, server-side signing, QTSP evidence, signer authentication, certificate validation, and trusted-list checks.
eIDAS signature legal effect selector: SES, AES, AES-QC, or QES
Compare eIDAS signature levels by legal effect, governing form rules, qualified certificate status, QTSP evidence, QSCD use, validation, and public-service recognition.
eIDAS trust service role scoping workflow: TSP, QTSP, validator, relying party, or QTSP customer
Classify an eIDAS role by evidence: trust service provider, qualified trust service provider, signature or seal validator, EUDI Wallet relying party, relying party, or customer of a QTSP.
eIDAS trusted list validation: LOTL, QTSP status, and evidence
How to validate EU eIDAS trusted-list evidence: start from the Commission LOTL, confirm QTSP and qualified-service status, check certificate path and revocation data, and retain validation reports.
eIDAS vs ESIGN and UETA: EU qualified signatures vs U.S. e-signature laws
Compare eIDAS with ESIGN and UETA for electronic signatures, qualified certificates, trust services, cross-border recognition, validation evidence, and source gaps.
eIDAS vs ETSI EN 319 401: legal supervision and TSP policy requirements
Compare eIDAS and ETSI EN 319 401 for trust services: legal scope, QTSP supervision, conformity assessment, audits, incident evidence, and operational controls.
eIDAS vs GDPR for identity data: wallet, trust-service, and privacy obligations
Compare eIDAS identity, trust-service, and EUDI Wallet rules with GDPR duties for personal-data processing, minimisation, lawful basis, evidence, security, and user rights.
eIDAS vs NIS2 for trust service providers: QTSP and cybersecurity obligations
Compare eIDAS trust-service and QTSP duties with NIS2 cybersecurity risk-management, incident reporting, supervision, and evidence duties for trust service providers.
Electronic Attestations of Attributes under EU eIDAS: EAA, QEAA, issuers, wallets, and validation
Official source guide to electronic attestations of attributes under amended EU eIDAS: EAA, QEAA, public-sector authentic-source attestations, wallet use, issuer checks, relying-party validation, revocation, and legal effect.
EU eIDAS Applicability Test for Trust Services, Wallets, and Certificates
An official source eIDAS scope test for QTSPs, trust services, electronic signatures, seals, timestamps, QWACs, EUDI Wallet relying parties, and cross-border recognition evidence.
EU eIDAS attribute attestations: EAA, QEAA, wallet, and relying party checks
What electronic attestations of attributes mean under eIDAS, how QEAAs differ from public-sector and non-qualified attestations, and what issuers, wallets, and relying parties should verify.
EU eIDAS checklist for signatures, trust services, and wallets
Checklist for eIDAS trust-service and EUDI Wallet controls: qualified status, trusted lists, certificates, signatures, seals, timestamps, validation evidence, and relying-party records.
EU eIDAS FAQ: signatures, QTSPs, trusted lists, QWACs, wallets, and validation
FAQ on eIDAS trust services and the European Digital Identity framework, covering advanced and qualified electronic signatures, QTSP status, trusted lists, QWACs, EUDI Wallet relying parties, attestations of attributes, and validation evidence.
EU eIDAS QTSP authorization and supervision guide
How qualified trust service providers obtain and keep qualified status under eIDAS, including conformity assessment reports, supervision, trusted lists, incidents, and evidence.
EU eIDAS QTSP Due Diligence Workflow for Trusted Lists, Certificates, and Evidence
Check a qualified trust service provider under eIDAS by validating trusted-list status, qualified service scope, certificates, policies, supervision, audits, and retained evidence.
EU eIDAS Requirements for Trust Services, Signatures, Seals, Wallets, and Evidence
Official source guide to core eIDAS requirements for trust service providers, qualified trust services, electronic signatures, seals, time stamps, trusted lists, and EUDI Wallet relying parties.
EU eIDAS Trusted Lists FAQ: LOTL, QTSP status, and validation evidence
How EU eIDAS Trusted Lists and the Commission LOTL support QTSP and qualified trust-service validation, with practical evidence checks for relying parties.
EUDI Wallet readiness for service providers under eIDAS
Readiness guide for organisations preparing to request or verify data from European Digital Identity Wallets: roles, registration, ARF alignment, selective disclosure, implementing acts, and evidence.
EUDI Wallet Relying Parties under eIDAS
What EUDI Wallet relying parties must do under eIDAS, when the harmonised registration rules apply, and how to control requested data, identification, validation, and evidence.
EUDI Wallet Relying Party Onboarding Workflow under eIDAS
Prepare an eIDAS wallet-relying-party registration, intended-use record, access-certificate controls, attribute request, validation evidence, and intermediary safeguards.
EUDI Wallet Relying Party Registration Under eIDAS
What eIDAS Article 5b and the EUDI Wallet ARF say about wallet relying party registration, intended uses, attribute requests, certificates, evidence, and Member State gaps.
EUDI Wallet Technical Architecture Guide under eIDAS
Technical guide to the EUDI Wallet architecture: ARF roles, wallet units, PID and attestations, relying parties, trust model, certificates, protocols, privacy, and security controls.
QES vs AdES under EU eIDAS: legal effect, certificates, QTSPs, and validation evidence
Compare qualified electronic signatures (QES) and advanced electronic signatures (AdES) under EU eIDAS, including legal effect, qualified certificates, QTSP status, QSCDs, and validation evidence.
What eIDAS Covers: eID, Trust Services, EUDI Wallet, and QWACs
A source-grounded guide to the systems and services covered by EU eIDAS: notified electronic identification, trust services, signatures, seals, time stamps, registered delivery, website authentication, trusted lists, the EUDI Wallet, and attribute attestations.
What is a qualified trust service provider under eIDAS?
How to verify QTSP status under eIDAS using the qualified service, supervisory body decision, trusted list entry, conformity assessment evidence, and service-specific records.
What is a QWAC under the EU eIDAS Regulation?
Plain-language FAQ on qualified website authentication certificates under eIDAS, including website identity, QTSP trusted-list checks, browser recognition, and validation evidence.