A qualified trust service provider is an organisation supervised by a member state and granted qualified status for one or more specific trust services. Those include issuing qualified certificates, timestamps and attestations of attributes, and managing remote signature and seal creation devices. Its status and the services it covers appear on the national trusted list.
Qualified status is not self-declared. A provider goes through conformity assessment, is supervised by a national body, and may not begin providing the qualified service until that status is on the trusted list. The listing is what lets a verifier anywhere in the EU rely on its output without a direct relationship. Audits repeat at least every 24 months.
QTSPs anchor the qualified tier across eIDAS. Qualified signatures, seals, timestamps and attestations all depend on one somewhere in the chain.
For most integrators a QTSP is a supplier rather than something to become. Becoming one is a regulated undertaking with continuing audit obligations.
Defined in
Regulation (EU) No 910/2014 Art. 3(16), 3(20), 20(1), 21 and 22, as amended by Regulation (EU) 2024/1183
Whether your signature carries qualified legal effect depends on having a QTSP in the chain. Settle that during procurement, not during a dispute.
Authbound handles the protocols, formats, trust lists and revocation checks behind these terms. See what people build with them.