A qualified trust service provider (QTSP) is a trust service provider that has been granted qualified status by a supervisory body in an EU Member State, following a conformity assessment against the requirements set out in the eIDAS regulation. Qualified status is the highest level of recognition a trust service provider can achieve under EU law, and it signals that the provider meets strict technical, security, and organisational standards. This article answers the most common questions about QTSPs, what they do, how they differ from regular providers, and why their status matters for your organisation.

What qualifies a trust service provider under eIDAS 2.0?

A trust service provider becomes a qualified trust service provider under eIDAS 2.0 by successfully completing a conformity assessment carried out by an accredited conformity assessment body and by being granted qualified status by the national supervisory authority in its Member State. Once granted, the provider is listed on the national Trusted List, which is published and recognised across the EU.

The requirements for qualified status are detailed and demanding. Under eIDAS 2.0, providers must demonstrate that they meet specific standards covering security management, personnel reliability, technical infrastructure, and service continuity. The updated regulation has introduced additional implementing regulations that specify requirements in areas such as protocols and interfaces, certification of wallet solutions, and the management of remote qualified signature creation devices. These requirements reflect the broader scope of eIDAS 2.0 compared to the original regulation.

Importantly, qualified status is not a one-time achievement. Providers must undergo regular audits to maintain their status and must notify their supervisory body before initiating new qualified trust services. This ongoing accountability is what makes the QTSP designation meaningful and trustworthy.

What services can a qualified trust service provider offer?

A qualified trust service provider can offer a defined set of qualified trust services under eIDAS 2.0. These services carry the highest legal weight within the EU framework and are accepted across Member States without additional verification.

The range of qualified trust services includes:

  • Qualified electronic signatures (QES): The digital equivalent of a handwritten signature, with the highest legal standing under EU law
  • Qualified electronic seals: Used by organisations to guarantee the origin and integrity of a document or dataset
  • Qualified electronic time stamps: Binding a precise date and time to data in a legally recognised way
  • Qualified certificates for website authentication: Confirming the identity of a website operator to users
  • Qualified electronic registered delivery services: Providing legally recognised proof of sending and receiving data
  • Qualified preservation services: The long-term preservation of qualified electronic signatures and seals
  • Qualified electronic ledgers: A newer service type introduced under eIDAS 2.0, providing tamper-evident records
  • Qualified electronic archiving services: Ensuring the long-term integrity and accessibility of electronic documents
  • Remote qualified signature creation device management: A new category introduced in eIDAS 2.0, enabling remote signing without compromising security

This expanded list under eIDAS 2.0 reflects how digital interactions have evolved. The original eIDAS regulation covered a smaller set of services, but the updated framework recognises that organisations need trusted infrastructure for a much wider range of digital processes.

How does a QTSP differ from a regular trust service provider?

The key difference between a qualified trust service provider and a non-qualified (regular) trust service provider is the level of legal recognition and the rigour of oversight they are subject to. A regular trust service provider can offer trust services without a conformity assessment, while a QTSP has been independently audited and formally recognised by a national supervisory authority.

In practical terms, this distinction has significant consequences:

  1. Legal presumption: Services provided by a QTSP carry a legal presumption of validity across the EU. A qualified electronic signature, for example, is presumed to have the same legal effect as a handwritten signature. Non-qualified signatures do not carry this presumption automatically.
  2. Cross-border recognition: Qualified trust services are automatically recognised in all EU Member States. Non-qualified services may not be accepted in other jurisdictions without additional verification.
  3. Trusted List inclusion: Only QTSPs appear on the national Trusted Lists, which are published by Member States and monitored at EU level. This makes it easy for organisations and individuals to verify a provider’s status.
  4. Audit and accountability: QTSPs are subject to regular conformity assessments and must report security breaches to their supervisory body. Non-qualified providers operate under lighter requirements.

For organisations in regulated sectors such as finance, healthcare, or government, the distinction is not just technical. Working with a QTSP means relying on services that will hold up legally, be accepted across borders, and meet the compliance expectations of regulators.

Who oversees and supervises qualified trust service providers?

Qualified trust service providers are supervised by a national supervisory body in each EU Member State. Each country designates its own authority responsible for overseeing trust service providers, granting qualified status, maintaining the national Trusted List, and responding to security incidents or non-compliance.

Under eIDAS 2.0, the supervisory framework has been strengthened. Supervisory bodies now operate under clearer obligations and timelines, and the regulation introduces formal requirements for how they handle notifications, conduct peer reviews of eID schemes, and publish information on qualified providers. The implementing regulations that accompany eIDAS 2.0 also set out specific formats and procedures for annual reporting by supervisory bodies, adding further transparency to the oversight process.

At the European level, the European Commission maintains oversight of the broader framework, including the publication of the EU Trusted Lists that aggregate national lists. This creates a layered system of accountability: national authorities handle day-to-day supervision, while the EU framework ensures consistency and cross-border recognition.

For organisations choosing a QTSP, this supervisory structure is a practical reassurance. It means the provider’s qualified status has been independently verified, is publicly visible, and is subject to ongoing scrutiny.

Why does QTSP status matter for organisations using digital identity services?

QTSP status matters because it directly affects the legal validity, cross-border acceptance, and regulatory compliance of the digital identity and signing services your organisation relies on. If your processes depend on electronic signatures, identity verification, or trusted data exchange, the qualified status of your provider determines whether those interactions will stand up legally and be accepted by counterparties, regulators, and public authorities across the EU.

For organisations in sectors such as financial services or healthcare, this is especially relevant. Regulations such as AML, KYC, and PSD2 require verifiable and auditable identity processes. eIDAS 2.0 is now adding further requirements on top of those, particularly around the use of the European Digital Identity Wallet and the trust services that support it. Relying on a QTSP ensures your organisation is working within a framework that regulators recognise and accept.

There is also a practical dimension. When your customers or partners have already verified their identity through a trusted source, a QTSP-backed infrastructure allows that verified identity to be reused securely, reducing friction and avoiding repeated verification steps. This is one of the core promises of the EUDI Wallet ecosystem: that a person or organisation verified once can be trusted everywhere, provided the underlying trust services meet the qualified standard.

Finally, as eIDAS 2.0 continues to reshape the digital identity landscape across Europe in 2026 and beyond, organisations that build their processes on qualified trust infrastructure are better positioned to adapt as new requirements come into force. The qualified framework is not just a compliance checkbox; it is the foundation for scalable, future-ready digital interactions.

How TrustTech helps with qualified trust service providers and eIDAS 2.0

Understanding the QTSP framework is one thing. Implementing it in a way that works for your organisation is another. TrustTech’s solutions are built specifically to help organisations navigate the requirements of eIDAS 2.0 and connect to qualified trust infrastructure without having to rebuild their existing systems from scratch.

Working with TrustTech means your organisation gets:

  • A platform that connects identity verification, reusable credentials, and qualified electronic signatures in one trusted flow
  • Support for regulated sectors including finance, government, healthcare, and pharmaceuticals, where compliance requirements are most demanding
  • Wallet-ready digital identity infrastructure aligned with the EUDI Wallet and eIDAS 2.0 by design
  • Faster onboarding and fewer drop-offs, with verified identity that can be reused across organisations and processes
  • A production-ready setup, typically live within five months, built on European digital identity standards

Whether you are just starting to explore what QTSP-backed services mean for your organisation or are ready to move into implementation, TrustTech combines deep regulatory knowledge with practical delivery expertise. Get in touch with TrustTech to find out how we can help your organisation build on trusted, qualified digital identity infrastructure.