---
title: What is a QTSP and how do you become one? | Ascertia | Blog
description: In a digital world, Qualified Trust Service Providers (QTSPs) are crucial, but what is a QTSP and how do you become one? This blog has the answers:
image: https://blog.ascertia.com/hubfs/what-is-QTSP-blog-080424.jpg
---

[![](https://blog.ascertia.com/hubfs/asc-blog-logo-detail.png)](https://blog.ascertia.com/)

##### [View all posts](https://blog.ascertia.com/)

[Contact Us](https://www.ascertia.com/company/contact-us/)

# What is a Qualified Trust Service Provider (QTSP)?

Posted by [Nick Glass](https://blog.ascertia.com/author/nick-glass) on Apr 9, 2024, 10:00:00 AM

![](https://blog.ascertia.com/hubfs/Nick%20Glass%20Headshot%202024.png)

## A complete guide to eIDAS and Qualified Trust Services

A Qualified Trust Service Provider (QTSP) is a regulated provider of one or more qualified trust services that has been granted ‘qualified’ status. Under the EU’s [eIDAS framework](https://digital-strategy.ec.europa.eu/en/policies/eidas-regulation), these services include qualified certificates for e‑signatures and eSeals, timestamps, and other services that help establish and ensure trust in digital transactions.

![](https://blog.ascertia.com/hubfs/what-is-QTSP-blog-080424.jpg)

QTSPs provide trusted infrastructure for secure, high assurance digital transactions. Their services help establish identity, authenticity, integrity and evidence, forming an important part of Europe’s digital trust infrastructure. This guide explains what QTSP’s do, detailing the role they play in the digital world, how to become one and how to choose one, the legislative backbone of these providers, and much more.

- A QTSP is a regulated provider of digital trust services that has been granted qualified status under a framework such as the EU’s trust services scheme, eIDAS.
- QTSPs deliver services that help establish identity, authenticity, integrity and evidence in digital transactions. These cover areas including qualified electronic signatures (QES), electronic seals (eSeals), and timestamps.
- Qualified trust services meet higher regulatory and security requirements than unqualified services and can carry specific legal effects and recognition.
- Qualified status does not automatically apply to every service a QTSP provides. The specific services holding qualified status can be verified on the relevant Trusted List.

### Table of contents

- [What is a Qualified Trust Service Provider?](https://blog.ascertia.com/what-is-a-qtsp#what-is-a-qtsp)
- [What does a QTSP do, and why does it matter?](https://blog.ascertia.com/what-is-a-qtsp#what-does-a-qtsp-do)
- [TSP vs QTSP vs CA vs RSSP](https://blog.ascertia.com/what-is-a-qtsp#tsp-vs-qtsp-vs-ca-vs-rssp)
- [What qualified trust services can a QTSP provide?](https://blog.ascertia.com/what-is-a-qtsp#qualified-trust-services)
- [How can an organisation verify and choose a QTSP?](https://blog.ascertia.com/what-is-a-qtsp#verify-and-choose-a-qtsp)
- [What are the legal, security and operational requirements for a QTSP?](https://blog.ascertia.com/what-is-a-qtsp#legal-security-operational-requirements)
- [How do you become a QTSP?](https://blog.ascertia.com/what-is-a-qtsp#how-to-become-a-qtsp)
- [What technology does a QTSP need?](https://blog.ascertia.com/what-is-a-qtsp#technology-a-qtsp-needs)
- [How does qualified remote signing work?](https://blog.ascertia.com/what-is-a-qtsp#how-qualified-remote-signing-works)
- [How should a QTSP choose its technology platform?](https://blog.ascertia.com/what-is-a-qtsp#choosing-a-technology-platform)
- [How is eIDAS 2.0 changing the QTSP landscape?](https://blog.ascertia.com/what-is-a-qtsp#eidas-2-0-and-the-qtsp-landscape)
- [How Ascertia supports Trust Service Providers and QTSPs](https://blog.ascertia.com/what-is-a-qtsp#how-ascertia-supports-tsps-and-qtsps)
- [QTSP Buyer’s Guide](https://blog.ascertia.com/what-is-a-qtsp#qtsp-buyers-guide)
- [Next steps for becoming or scaling a QTSP](https://blog.ascertia.com/what-is-a-qtsp#next-steps)
- [FAQ](https://blog.ascertia.com/what-is-a-qtsp#faq)

## What is a Qualified Trust Service Provider?

### The formal eIDAS definition of a QTSP

Under eIDAS, a QTSP is a Trust Service Provider that has been granted qualified status by the relevant supervisory body to provide one or more qualified trust services.

### What does ‘qualified’ status actually mean?

Under eIDAS, being qualified means that the provider and at least one of its trust services have met the regulatory requirements and been granted ‘qualified’ status by its relevant national supervisory body. Qualified services have to meet additional requirements, and they can benefit from legal effects or presumptions in the EU.

National authorities oversee QTSPs and ensure their services are included on an official [trusted list](https://digital-strategy.ec.europa.eu/en/policies/eu-trusted-lists). Qualified status also requires ongoing compliance and audit obligations.

### Is qualified status attached to the provider or the service?

The qualified status applies to both the TSP and the specific trust service. This is an important distinction; an organisation becomes a QTSP when a national supervisory body grants qualified status to the provider **and** at least one of its trust services.

This distinction is vital to understand as an organisation being a QTSP does not mean that each of its offered services are qualified. The qualified status of an organisation and its individual services holding qualified status can be verified through the relevant trusted list.

### EU eIDAS, UK eIDAS and other trust frameworks

This guide will focus on QTSPs within the context of the European Union’s eIDAS framework.

It’s worth noting that, following the United Kingdom’s departure from the EU, the UK operates its own [UK eIDAS](https://www.legislation.gov.uk/eur/2014/910/contents) regime where the Information Commissioner’s Office (ICO) supervises the country’s trust service providers and manages the nation’s Trusted List.

The UK government opened a call for evidence in 2025 into why the domestic market hasn’t produced a registered QTSP, so it is worth treating the UK position as an evolving picture.

Other jurisdictions have their own digital trust and e‑signature frameworks, with qualification and supervision requirements differing between markets. As a result, QTSP status in one jurisdiction does not automatically mean that the same status is recognised in another.

## What does a QTSP do, and why does it matter?

Qualified Trust Service Providers provide services that serve as the backbone of digital interactions between people, organisations, and systems. They can help establish and verify those involved in a transaction, safeguard the integrity of information, provide evidence that certain digital activities have taken place, and much more.

### Establishing trust in digital identities and transactions

QTSPs help establish core elements of digital trust: identity, authenticity, and integrity. Depending on the service, this may include verifying an individual or organisation’s identity, establishing the origin and integrity of a document, or providing evidence of when information was sent, received, signed, or sealed.

These services allow society to evolve processes that have traditionally been dependent on physical identification, handwritten signatures, and paper records. These processes are increasingly happening in digital environments, and it is qualified trust services that provide a high level of assurance around identity, authenticity, and integrity.

### Supporting secure, cross‑border digital services

Qualified trust services are particularly important where organisations need higher levels of assurance, including in sectors such as:

- Government
- Financial services
- Healthcare
- Legal and professional services

The eIDAS framework also supports cross‑border digital transactions across the EU. Qualified trust services can therefore help people and organisations interact securely across Member States within a common legal and technical framework.

## TSP vs QTSP vs CA vs RSSP: What is the difference?

There are several types of providers in the digital trust ecosystem, and their roles can overlap. Some of the main terms you’ll come across are:

- Trust Service Providers (TSPs)
- Qualified Trust Service Providers (QTSPs)
- Certificate Authorities (CAs)
- Remote Signing Service Providers (RSSPs)

These organisation types all play different roles in the digital trust ecosystem, and these terms are not interchangeable.

### TSP, QTSP, CA and RSSP comparison

The table below summarises the basic functions of these organisation types, what services they offer, and how they differ from each other.

| Role | Primary function | Regulated qualified status? | Typical services |
| --- | --- | --- | --- |
| Certificate Authority | Issues and manages certificates | Not automatically | Certificate issuance and lifecycle management |
| Trust Service Provider | Provides trust services | Not necessarily | Electronic signatures, seals, timestamps |
| Qualified Trust Service Provider | Provides qualified trust services | Yes, for the provider and the specified service(s) | One or more qualified trust services |
| Remote Signing Service Provider | Provides remote signing capabilities | May be qualified or non‑qualified | Remote signature creation and authorisation |

### Can one organisation fulfil several roles?

While these digital trust categories are not interchangeable, they often overlap and complement each other.

For example, a single organisation can provide qualified trust services as a QTSP, issue qualified certificates as a CA, and also provide remote signing capabilities to its customers.

The key distinction here is that the TSP and QTSP terms describe the provider and its standing under regulations like eIDAS, whereas the CA and RSSP terms describe the services and functions that an organisation may provide.

### When is a QTSP required?

Fundamentally, the dependency on a Qualified Trust Service Providers depends on the trust service and level of assurance needed. It’s not the case that every e‑signature, eSeal, or timestamp needs to be provided by a QTSP.

As per the [eIDAS](https://ico.org.uk/for-organisations/guide-to-eidas/what-is-the-eidas-regulation/) framework, a QTSP is required where a qualified trust service is needed. For example, a Qualified Electronic Signature (QES) has to be delivered on the basis of a qualified certificate, issued by a QTSP, and created using a Qualified Electronic Signature Creation Device (QSCD).

There are many instances where unqualified trust services suffice. The appropriate level of assurance depends on factors including:

- Applicable legislation
- Contractual requirements
- Required evidence
- Risk

Organisations are responsible for determining the level of assurance and legal requirements of a given transaction, rather than assuming that every digital transaction requires the services of a QTSP.

<iframe style="margin: 0px auto; display: block;" title="YouTube video player" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" xml="lang" src="https://www.youtube-nocookie.com/embed/gOOiK-nTtj0?si=K9yacGqULNl5vhb2" width="680" height="330" frameborder="0" allowfullscreen></iframe>

## What qualified trust services can a QTSP provide?

A QTSP can provide one or more qualified trust services depending on which of its services have been granted qualified status. These services help establish evidence and trust around identity, authenticity, and integrity in digital transactions.

Under eIDAS, qualified trust services must meet regulatory requirements and can benefit from particular legal effects. It’s important to remember that a QTSP can still provide an unqualified service, so this special status applies to specific services that can be found on national Trusted Lists.

### Established qualified trust services under eIDAS

Under the eIDAS framework, qualified trust services cover areas including electronic signatures and seals, timestamps, validation, and more.

The legal effects of qualified status differ by service. For example, a qualified electronic timestamp benefits from a presumption of the accuracy of its date and time of the data to which it is bound. Qualified electronic registered delivery similarly provides presumptions concerning data integrity, sender, recipient, and the times of sending and receipt.

| Qualified trust service | What does it do? | Example application |
| --- | --- | --- |
| Qualified certificates for electronic signatures | Links signature validation data to an identified individual and supports the creation of qualified electronic signatures. | An individual signing a regulated agreement or official application. |
| Qualified certificates for electronic seals | Links seal validation data to an identified organisation, helping establish the origin and integrity of data. | A business sealing invoices, certificates, or official records. |
| Qualified electronic timestamps | Provides trusted evidence that specific electronic data existed at a particular point in time and has not been altered since. | Establishing when a contract, record, or intellectual property existed. |
| Qualified electronic registered delivery services | Provides evidence of the sending and receipt of electronic data while protecting its integrity. | Sending legally or commercially significant documents electronically. |
| Qualified certificates for website authentication | Links a website to an identified person or organisation. | Establishing the identity behind an online service. |
| Qualified validation services | Verifies and confirms the validity of qualified electronic signatures or seals. | Checking whether a digitally signed document remains valid and trustworthy. |
| Qualified preservation services | Preserves the trustworthiness of qualified electronic signatures and seals beyond their initial technological validity period. | Maintaining verifiable signed records over long retention periods. |

The legal effects of qualified status differ by service. For example, a qualified electronic timestamp benefits from a presumption of the accuracy of its date and time of the data to which it is bound. Qualified electronic registered delivery similarly benefit from provides presumptions concerning data integrity, sender, recipient, and the times of sending and receipt.

### New and expanded services under eIDAS 2.0

The amended eIDAS framework, known as [eIDAS 2.0](https://blog.ascertia.com/eidas-1.0-eidas-2.0-differences), expanded the role of QTSPs to become part of Europe’s wider digital identity infrastructure.

It introduced additional qualified trust services in areas that have become increasingly important as digital transactions and identities evolve.

These additional qualified trust services include:

- **Qualified electronic attestations of attributes:** Digitally attest characteristics, qualifications, rights, or other attributes relating to a person, organisation or object.
- **Qualified electronic archiving:** Preserves electronic data and documents while maintaining their integrity, origin, durability, and legibility throughout the required preservation period.
- **Qualified electronic ledgers:** Record electronic data in a way designed to establish its integrity, chronological ordering, and accuracy over time.
- **Qualified management of remote signature and seal creation devices:** Provides a regulated framework for managing remote qualified electronic signature and seal creation devices on behalf of users.

## How can an organisation verify and choose a QTSP?

When choosing a QTSP, start by verifying its qualified status and the specific services covered by that status. You should then assess whether those services meet your legal, operational and technical requirements.

### Check the relevant Trusted List

As part of the EU’s eIDAS framework, organisations can search national Trusted Lists, accessible through the European Commission, to verify that a trust service provider is indeed qualified.

These lists identify the provider, its legal identity, and the specific trust services that hold qualified status.

### Confirm that the service matches the intended use case

Qualified status should not be the only selection criterion. Organisations should establish which trust service and level of assurance their use case requires.

Other pertinent considerations may include:

- Scalability
- Data residency
- Identity verification
- Supported formats
- Applicable legislation
- Integration requirements
- Certificate lifecycle processes

The key is to make sure every level of the service you’re identifying suits the legal, technical, and operational requirements of the use case.

## What are the legal, security and operational requirements for a QTSP?

Organisations must meet a range of legal, security, governance and operational requirements to obtain and maintain Qualified Trust Service Provider status.

The EU established such strict rules for QTSPs with eIDAS to ensure that those offering qualified trust services provide trust and a consistently high level of assurance.

### The eIDAS and European Digital Identity regulatory framework

The eIDAS regulation (EU No 910/2014), which was later amended by the European Digital Identity Framework or eIDAS 2.0 (EU 2024/1183) is what governs QTSPs in the EU. This framework lays out the requirements for these services and providers.

The requirements vary according to the services being provided, meaning QTSPs have to identify the regulatory and technical obligations that apply to each service.

### Conformity assessment, notification and supervision

Before becoming ‘qualified’, Trust Service Providers have to undergo an assessment by an accredited Conformity Assessment Body (CAB). From there, they must submit the [conformity assessment](https://www.enisa.europa.eu/publications/assessment-of-qualified-trust-service-providers) report to its applicable national supervisory body.

Qualified status brings ongoing supervision. QTSPs and their qualified trust services must undergo a conformity assessment at least every 24 months, at the provider’s own expense, to confirm that they continue to meet the requirements.

### Security, incident management and operational resilience

Qualified Trust Service Providers must use appropriate measures to manage security risks, protect their services, and reduce the likelihood and impact of security incidents. These may include:

- Monitoring threats and security events
- Protecting cryptographic keys
- Controlling access to data and systems
- Maintaining secure infrastructure
- Incident response and notification
- Business continuity and disaster recovery

### Records, liability and termination planning

A major responsibility of a QTSP is the retention of information regarding the services they provide. This information must be retained for an appropriate period, including evidence which may be needed to support legal proceedings.

For example, certificate and key lifecycle records (such as event logs, key generation data, and subscriber documentation) must be retained for at least seven years after a certificate’s validity expires–as per industry standards like ETSI–specifically ETSI EN 319 411-1 clause 6.4.6, which sets this seven‑year minimum for certificate‑related records.

QTSPs must maintain an up‑to‑date termination plan to minimise disruption if a service or the provider itself ceases operation. These plans must be approved by their national supervisory body and, if a QTSP ceases operations, its records and validation data must remain accessible or transferable, so the legal validity of its services is intact.

When a QTSP ceases operations, or discontinues a qualified trust service, affected users and relevant authorities must be informed when these significant changes occur.

## How do you become a QTSP?

Before looking at how to become a QTSP, it is worth asking a more fundamental question, why do you want to become one?

Understanding what you want to achieve, whether that is expanding the trust services you offer, entering new markets, meeting customer demand or creating new revenue opportunities, will help shape the services you choose to provide and the route you take.

From there, your organisation needs to define the qualified trust service or services it intends to provide, build the right environment to meet the relevant regulatory and technical requirements, demonstrate compliance through a conformity assessment, and receive qualified status from the relevant national supervisory body.

It is a significant undertaking, but the process follows a clearly defined regulatory journey.

### Step 1 — Define the qualified services and jurisdiction

Start by identifying which qualified trust service(s) you intend to provide. This could be certificates, timestamps, or remote e‑signatures. Also identify the EU Member State you will be established and supervised in.

The regulatory requirements and standards you’ll need to meet are determined by the qualified services being provided and the organisation’s operating model.

### Step 2 — Design the operating model

You must then establish the appropriate and applicable governance, policies, and procedures that apply to those operating as a QTSP.

This includes areas such as risk management, security, qualified personnel, incident management, and service termination.

All of these considerations and more must be thoroughly mapped out while you design your service, as opposed to elements addressed only in preparation for the assessment.

### Step 3 — Build the infrastructure

Your chosen service(s) will dictate the infrastructure and technological setup you ultimately need. This may include PKI and certificate management, HSMs, QSCDs, timestamping, remote signing and audit capabilities.

Your infrastructural and technological choices should also align with the applicable eIDAS requirements and technical standards, while also maintaining a high level of security and scalability.

### Step 4 — Engage an accredited Conformity Assessment Body

Before you can offer your qualified trust service(s), you have to be assessed by an accredited Conformity Assessment Body (CAB).

They will assess your organisation and its proposed trust services against regulatory requirements, subsequently producing a conformity report.

### Step 5 — Complete assessment and notify the supervisory body

Should you pass the assessment, you must then submit the conformity report and your notification to your relevant national supervisory body.

The supervisory body will then verify compliance and, if all requirements are met, grant your organisation and your chosen service(s) qualified status and list on the relevant Trusted List.

### Step 6 — Qualified status & Trusted List entry

Being qualified and listed on the Trusted List is not the end. Your standing as a Qualified Trust Service Provider remains subject to ongoing requirements the entire time it is operating as a provider of qualified services.

You must continuously meet the applicable requirements, manage changes to your services over time, and undergo a conformity assessment every 24 months to maintain qualified status.

The biggest thing organisations underestimate is that becoming a QTSP is not simply a certification project. Getting through the conformity assessment and onto the Trusted List is a major milestone, but the real challenge is building something that can operate compliantly every day after that.

From my experience working with QTSPs, the technology is only part of it. You need clear ownership across security, operations, compliance, and service delivery, with the right processes around certificate lifecycle management, key management, identity verification, incident handling and change control.

It is also important to think ahead. Services evolve, regulations change, customer requirements grow and infrastructure needs to scale. A change that looks relatively small from a technical perspective can have compliance implications that need to be understood before it is made.

The strongest QTSP projects I see are the ones where compliance, technology, and operations are designed together from the beginning. That makes the initial qualification easier, but more importantly, it makes maintaining qualified status much more manageable over the long term.

**Nick Glass, Senior Sales Manager, Ascertia**

## What technology does a QTSP need?

The technology that a QTSP requires is dependent on the services it’s providing.

Most trust environments combine PKI, cryptographic hardware, certificate management, validation, and auditing capabilities.

### PKI and certificate lifecycle management

Public Key Infrastructure (PKI) is the foundation for many qualified trust services, allowing QTSPs to issue and manage certificates that tie identities to cryptographic keys.

When certificate services are part of the trust solution, the infrastructure needs to support the full certificate lifecycle: issuance, renewal, suspension, revocation, and status checking.

### HSMs, QSCDs and cryptographic key protection

A foundational element of delivering trust services is protecting cryptographic keys. Hardware Security Modules, HSMs, provide a secure environment for generating, storing, and using these keys.

When a Qualified Electronic Signature or Seal is generated, Qualified Signature/Seal Creation Devices (QSCDs) provide the additional controls that eIDAS requires.

### Remote signature and seal creation

Providers that offer remote signatures need to have infrastructure in place that ensures centrally held keys can only be used when authorised by the appropriate user.

This requires user authentication, signature activation, policy enforcement, and signing key protection.

### Timestamping, OCSP, CRLs, validation and preservation

There are other trust services outside of certificate issuance and signature creation. QTSPs are increasingly offering services like timestamping, certificate status, and validation to establish when a transaction happens and whether a certificate or signature can be trusted.

These services can include:

- Timestamp Authorities
- Online Certificate Status Protocol (OCSP)
- Certificate Revocation Lists (CRLs)
- Long‑term validation and archiving

For example, Ascertia’s ADSS Server provides services including CA, timestamping, OCSP, CRL, and validation alongside other qualified trust services. We also provide solutions for integration with external identity providers, together with out‑of‑the‑box standard connectivity for CSC v1 and CSC v2 remote signing environments.

### Identity proofing, authentication and authorisation

For qualified trust services involving individuals or organisations, the infrastructure may also need to link digital credentials and transactions to the correct identity.

As a result, processes must be in place for identity proofing and authentication, two crucial elements of remote signing, where the system must establish the user’s identity and confirm they are authorised to use a particular signing key.

### APIs, standards and interoperability

Qualified trust services often need to operate in conjunction with identity providers, signature platforms, other PKI environments, and business applications.

Standards‑based APIs and interfaces support these integrations, including the [Cloud Signature Consortium API](https://www.ascertia.com/products/cloud-signature-consortium/) and other formats like PAdES, XadES, and CAdES.

### Deployment, data residency and scalability

Service deployment and data residency are significant considerations and technological differences that QTSPs must consider.

There are on‑premise, cloud, or hybrid deployment models, a growing concern over data sovereignty and residency, and the ability to scale as users and technological demands grow. These considerations need to be addressed by QTSPs when planning their architecture and infrastructure, rather than waiting until ‘qualified’ status has been reached–especially as QTSPs need to remain compliant throughout their entire operational lifecycle.

## How does qualified remote signing work?

Qualified remote signing allows a signer to create a Qualified Electronic Signature (QES) without the signing key being held on a local, physical device. Instead, the key is securely held within centrally managed infrastructure, with controls in place to make sure that it can only be activated by the authorised signer.

### Local versus remote qualified signing

Traditionally, a signer could only utilise a qualified e‑signature if they had the creation data on a smartcard, USB token, or another QSCD. Remote signing changed that, allowing a document to be signed with a QES without the signer carrying dedicated hardware, with the signature creation data being held by a remote QSCD.

### How sole control is maintained remotely

A remote signing system must guarantee that the signing key can only be used by the authorised signer. This requires strong authentication and controls that require the signer to explicitly authorise the signature.

Audit records, cryptographic key protection, and policy enforcement provide additional controls that ensure the security of this centralised infrastructure.

### Why remote signing matters commercially to QTSPs

Remote signing is commercially attractive as a qualified service for QTSPs as it significantly simplifies the delivery and scalability of these highly secure e‑signatures.

By removing the need to issue and manage physical signing hardware, onboarding is simpler and customers can access secure signing services remotely. QTSPs can also integrate qualified remote signing into applications and workflows, extend services to a wider user base, and develop and deliver new trust services around the same infrastructure.

### Certified remote signing infrastructure

Qualified remote signing requires specialist infrastructure for key protection, user authentication, and secure signature activation. Ascertia’s [ADSS SAM Appliance](https://www.ascertia.com/products/adss-server-sam-appliance/) is designed specifically for this purpose and is certified to meet the applicable security standards and requirements expected of a QSCD used for qualified remote signing.

It is a Common Criteria‑certified Remote Qualified Signature Device that can be supplied with a certified Hardware Security Module to support qualified remote signatures and seals.

## How should a QTSP choose its technology platform?

Choosing the right technology platform is a major decision for a Qualified Trust Service Provider. The platform must support the relevant regulatory, security, and operations requirements, while also giving the organisation room to scale, support new services, and adapt as standards evolve.

### Regulatory and standards coverage

A good starting point is determining whether the platform supports the regulations and standards that are relevant to the qualified service(s) on offer. These often include eIDAS requirements, ETSI and CEN standards, and QSCD requirements.

A QTSP should also consider how the platform is maintained as regulatory and technical requirements evolve over months and years.

### Service breadth and modularity

QTSPs should also consider which trust services the platform can support, both now and in the future. Trust services can vary significantly, and different services can place very different demand on the underlying technology.

A modular platform allows QTSPs to deploy the capabilities they need initially and then add further services as their requirements develop.

### Scalability, availability and lifecycle governance

Qualified trust services can serve as critical infrastructure for particular businesses, so platforms need to be assessed from multiple angles:

- Capacity
- Availability
- Security and resilience
- Monitoring
- Disaster recovery
- Lifecycle management

When considering these factors, QTSPs are recommended to consider current transaction volumes **and** whether the platform infrastructure is suited to scale as customer numbers, service usage, and business requirements grow.

### Integration and interoperability

The platform should integrate with the QTSP’s wider technology environment, including existing PKI, HSMs, identity providers, signing applications, and business systems.

Assessing APIs and SDKs, integrations with identity providers, and compatibility with existing PKI and HSM infrastructure should all form part of the assessment.

### Deployment and data sovereignty and commercial flexibility

Deployment model is an important consideration when choosing a QTSP platform. Cloud, on‑premise, and hybrid approaches can have different implications for security, operational control, data residency, and sovereignty.

### Vendor expertise and support

The technology provider should also be assessed on its experience with QTSP deployments, knowledge of relevant regulations and standards, implementation support, and evidence of ongoing product development. The aim should be to choose a platform that supports both the immediate qualification requirements and the QTSP’s longer‑term service roadmap.

## How is eIDAS 2.0 changing the QTSP landscape?

The second iteration of eIDAS (often referred to as eIDAS 2.0) and also known as the European Digital Identity Framework, expanded the role of trust services within Europe’s digital identity framework and creates new requirements and opportunities for QTSPs.

### Integration with European Digital Identity Wallets

The introduction of European Digital Identity (EUDI) Wallets enables citizens and businesses to identify themselves, share information, and access both public and private services across borders.

QTSPs have a significant role in this technology and ecosystem. Providers of qualified electronic attestations of attributes must support [EUDI Wallets](https://blog.ascertia.com/digital-identity-wallets-digital-signature-adoption), for example, and these wallets will enable users to sign documents with Qualified Electronic Signatures.

### New qualified trust service opportunities

The evolution of eIDAS also delivered a new range of trust services, including:

- Qualified electronic attestations of attributes
- Qualified electronic archiving
- Qualified electronic ledgers
- Qualified management of remote electronic signature and seal creation devices

These additional services generate new opportunities for QTSPs, especially in expanding beyond certificate, signature, and timestamping services. New areas of commercial opportunity include:

- Verified attributes
- Long‑term digital records
- Trusted data exchange

### Interoperability and cross‑border reach

The EU’s digital identity framework is intended to support greater interoperability between digital identity and trust services across EU Member States. Qualified trust services provided in one Member State benefit from recognition across the EU in accordance with eIDAS. The amended framework also explicitly provides cross‑border recognition for newer services including qualified electronic attestations of attributes, qualified electronic archiving and qualified electronic ledgers.

### Operational resilience and cryptographic agility

The update to eIDAS provided another reason for QTSPs to assess their service offering and overall infrastructure. They need to be able to adapt as requirements evolve, and this includes being able to adapt to new services and standards without having to overhaul their underlying trust infrastructure.

For QTSPs in particular, this increases the importance of interoperability, scalability, and crypto‑agility. The latter is particularly pertinent when considering developments in post‑quantum cryptography, although this is not a specific requirement under eIDAS 2.0.

## How Ascertia supports Trust Service Providers and QTSPs

Ascertia provides the technology infrastructure that Trust Service Providers and QTSPs use to develop, operate, and scale digital trust services.

Our technology spans PKI and certificate management, remote signing, timestamping, validation, signing and workflows. It is designed to integrate with existing trust infrastructure and business applications, allowing providers to add or extend services without replacing their entire environment.

### PKI and trust‑service infrastructure

[ADSS Server](https://www.ascertia.com/product-documentation/adss-server/) is Ascertia’s modular platform for delivering digital trust. TSPs and QTSPs can utilise it for:

- Certificate issuance, management, and validation
- Digital signing
- Verification
- Timestamping
- Long‑term archiving and evidence

Trust service providers can build a host of services on a single trust infrastructure with Ascertia, rather than deploying separate technologies for each offering.

### Qualified remote signing and eSealing

Ascertia’s ADSS [SAM Appliance](https://www.ascertia.com/products/adss-server-sam-appliance/) provides a remote QSCD component needed to support qualified remote e‑signatures and eSeals.

This service is Common Criteria EAL4+ certified against EN 419 241-2 and works with certified Hardware Security Modules (HSM) to hold and protect remote signing and sealing keys.

### Customer‑facing signing workflows

[SigningHub](https://www.signinghub.com/) by Ascertia is the application that allows providers to deliver signing and document approval to customers at scale. It can connect to, and integrate with, QTSP infrastructure and supported both qualified and advanced e‑signature workflows.

TSPs can choose to offer SigningHub as a self‑branded service, enabling them to deliver remote signing directly to their own customers.

### Flexible deployment and interoperability

Ascertia’s technology is designed to integrate with existing PKI, HSMs, trust infrastructure, and business applications, making it easier than ever for TSPs to integrate services without replacing their entire technology stack.

### Proven deployments

Ascertia’s technology is used by QTSPs, CAs, and other digital trust organisations worldwide. [DigiCert + QuoVadis](https://blog.ascertia.com/ascertia-digicert-quovadis-first-qtsp-to-deliver-eidas-certified-qualified-remote-signing-with-level-2-sole-control) and [MISA](https://blog.ascertia.com/misa-ascertia-case-study) utilise our ADSS SAM Appliance for qualified remote signing.

Our technology is also used by organisations including Iron Mountain, a QTSP in Cyprus, and Malaysia Certification Authority [MSC Trustgate](https://blog.ascertia.com/msc-trustgate-signinghub-case-study) to enhance their service offering.

## Next steps for becoming or scaling a QTSP

So, what’s your next step? It depends on whether you’re working towards becoming qualified or if you’re already operating as a TSP. In either case, regulatory planning, operating model and technology need to be considered together.

### Planning to become a QTSP?

Pursuing qualified status? Begin by defining the service you intend on providing, your target jurisdiction, and the regulatory requirements facing you. From there, you can begin to develop governance, policies, and technical infrastructure before undergoing your conformity assessment.

**Our QTSP Roadmap provides a more in‑depth, practical overview of this journey from defining the service through to conformity assessment, qualified status and Trusted List entry.**

### Already operating as a TSP or QTSP?

If you’re an existing provider, you’re possibly here as you look to modernise your infrastructure, introduce a new service like remote signing, or considering steps for scalability as your organisation grows.

## Frequently asked questions

**What does QTSP stand for?**

QTSP stands for Qualified Trust Service Provider. Under eIDAS, a QTSP is a Trust Service Provider that has been granted qualified status by a national supervisory body to provide qualified trust services.

**How can I check whether a provider is a QTSP?**

Check the Trusted List of the EU Member State in which the provider is established, which is accessible through the European Commission’s List of Trusted Lists. This confirms both the provider and which of its individual trust services currently hold qualified status.

**Is a Certificate Authority the same as a QTSP?**

No. A Certificate Authority (CA) issues and manages digital certificates, while QTSP describes a trust services provider with a particular regulatory status. A QTSP may also be a CA, but operating a CA does not automatically make an organisation a QTSP.

**Does a Qualified Electronic Signature require a QTSP?**

Yes. Under eIDAS, a Qualified Electronic Signature (QES) must be based on a qualified certificate for e‑signatures issued by a QTSP and created using a Qualified Electronic Signature Creation Device (QSCD).

**What is a Qualified Signature Creation Device?**

A Qualified Signature Creation Device (QSCD) is a signature creation device that meets the requirements established under eIDAS. It protects the data used to create qualified electronic signatures and can take different forms, including appropriately certified remote signing systems.

**How often are QTSPs audited?**

Under eIDAS, QTSPs must be audited by a Conformity Assessment Body at least every 24 months–at their own expense–to confirm that they, and their qualified trust services, continue to meet requirements. Supervisory bodies can also require additional assessments.

**Can a QTSP provide non‑qualified services?**

Yes, a QTSP can provide both qualified and non‑qualified trust services. Being qualified does not automatically apply to everything the organisation offers; it applies to the specific services recorded with qualified status on the relevant Trusted List.

**What is the difference between EU eIDAS and UK eIDAS?**

EU eIDAS applies across the European Union, while UK eIDAS is a separate UK regulatory regime retained following Brexit. The UK has its own supervisory arrangements and Trusted List, so qualification and recognition should not be assumed to operate identically between the two.

As of 2026, that UK Trusted List has no QTSPs registered on it. UK organisations needing a qualified trust service currently rely on EU‑qualified QTSPs, which UK eIDAS permits to operate in the UK as if they were UK‑based.

**Can an organisation outside the EU become an EU QTSP?**

Under eIDAS, qualified status is tied to the EU regulatory and supervisory framework. Trust services provided by organisations established outside the EU may be recognised as equivalent where the conditions for international recognition under eIDAS are met.

**What is the difference between a QTSP and an electronic signature platform?**

A QTSP provides regulated trust services, while an electronic signature platform provides the application and workflow through which users may sign documents. A signature platform can integrate with a QTSP to provide qualified signatures without being a QTSP itself.

[Visit Ascertia.com](https://www.ascertia.com/)

This is a search field with an auto-suggest feature attached.

 Search

- There are no suggestions because the search field is empty.

### Recent Posts

### Posts by Topic

- [News (64)](https://blog.ascertia.com/tag/news)
- [Digital Trust (53)](https://blog.ascertia.com/tag/digital-trust)
- [Esignatures & Digital Signatures (41)](https://blog.ascertia.com/tag/esignatures-digital-signatures)
- [Case Study (32)](https://blog.ascertia.com/tag/case-study)
- [Esignatures, Digital Signatures & Digital Signing (25)](https://blog.ascertia.com/tag/esignatures-digital-signatures-digital-signing)
- [Remote Signing (21)](https://blog.ascertia.com/tag/remote-signing)
- [Ascertia Partners (16)](https://blog.ascertia.com/tag/ascertia-partners)

### Subscribe to Blog

### Download this essential eBook

Choosing the right type of e-signature  
for your business

[![Download your eBook](https://no-cache.hubspot.com/cta/default/2937299/065619c2-b2d6-4c65-9820-92c7e0dceaa8.png)](https://cta-redirect.hubspot.com/cta/redirect/2937299/065619c2-b2d6-4c65-9820-92c7e0dceaa8)

- Signing
- EU eIDAS Compliant Advanced & Qualified Signatures
- [SigningHub](https://www.ascertia.com/products/signinghub/)
- [ADSS Signing Server](https://www.ascertia.com/products/adss-signing-server/)

- PKI
- Modular solution for your Trust Service needs
- [ADSS Certificate Authority](https://www.ascertia.com/products/adss-ca-pki-server/)
- [ADSS Registration Authority](https://www.ascertia.com/products/adss-ra-server/)
- [ADSS Validation Authority](https://www.ascertia.com/products/adss-ocsp-server/)
- [ADSS Time Stamp Authority](https://www.ascertia.com/products/adss-tsa-server/)
- [ADSS Archive Authority](https://www.ascertia.com/products/adss-ltans-evidence-server/)

- Tools
- Integrate, test & monitor your Trust Services
- [ADSS Auto File Processor](https://www.ascertia.com/products/adss-auto-file-processor/)
- [ADSS Client SDK](https://www.ascertia.com/products/adss-client-sdk/)

- Solutions
- [Mobile Signatures](https://www.ascertia.com/solutions-by-technology/mobile-signing/)
- [Remote (Cloud) Signing](https://www.ascertia.com/solutions-by-technology/remote-signing/)
- <https://www.linkedin.com/company/ascertia> <https://www.youtube.com/user/ESIGNwithAscertia>

[Terms of Use](https://www.ascertia.com/terms-of-use/)   |   [Privacy Policy](https://www.ascertia.com/company/privacy-policy/)   |   © Ascertia. All rights reserved. ISO 9001:2015 Certified