What is a qualified website authentication certificate under eIDAS 2.0?

EU passport beside a laptop showing a secure browser padlock and official certification seal on cream paper in a European government office.

A qualified website authentication certificate (QWAC) is a specific type of digital certificate issued by a qualified trust service provider (QTSP) under eIDAS 2.0 that cryptographically confirms the legal identity of the organisation behind a website. Unlike standard SSL/TLS certificates, a QWAC carries a legally recognised level of assurance across all EU Member States, giving website visitors verified proof of who they are dealing with.

Under eIDAS 2.0, QWACs play a growing role in the broader digital identity landscape, particularly as organisations prepare for the European Digital Identity Wallet. The sections below answer the most common questions about how QWACs work, who needs them, and how to get one.

How does a QWAC differ from a standard SSL/TLS certificate?

A QWAC differs from a standard SSL/TLS certificate primarily in its legal status and the depth of identity verification behind it. While any SSL/TLS certificate encrypts the connection between a browser and a server, a QWAC also provides legally recognised proof of the organisation’s identity under EU law, issued by a QTSP that is listed on a national trusted list.

Standard SSL/TLS certificates come in several types. Domain Validation (DV) certificates only confirm that the applicant controls the domain. Extended Validation (EV) certificates go further with organisational checks, but they carry no legal standing under EU regulation. A QWAC, by contrast, meets strict requirements defined in eIDAS 2.0 and is backed by a qualified trust service provider accountable under European law.

In practical terms, this means a QWAC communicates something more meaningful to both users and relying parties: not just that the connection is encrypted, but that the identity behind the website has been formally verified and is legally attributable.

What requirements must a QWAC meet under eIDAS 2.0?

Under eIDAS 2.0, a qualified website authentication certificate must be issued by a qualified trust service provider listed on an EU Member State’s trusted list, and it must contain a verified set of identity attributes about the organisation operating the website. The certificate must conform to the reference standards established by the European Commission’s implementing regulations.

Specifically, a QWAC issued under eIDAS 2.0 must include:

  • The full legal name of the organisation
  • The country of establishment
  • The domain name(s) the certificate covers
  • An indication that it is a qualified certificate for website authentication
  • The identity of the issuing QTSP and a reference to its qualified status

The QTSP issuing the QWAC must verify the organisation’s identity before issuance, following defined procedures. This is a significant step beyond the automated domain checks used for standard certificates. The European Commission has published implementing regulations covering reference standards for qualified certificates for website authentication, providing the technical baseline that QTSPs must follow.

Which organisations are required to use a QWAC?

Under eIDAS 2.0, certain categories of websites operated by public sector bodies and regulated service providers are required to support qualified website authentication certificates. The regulation specifically addresses websites that need to provide users with a high level of assurance about the organisation’s identity, particularly in contexts where trust is critical.

In practice, the organisations most directly affected include:

  • Public sector bodies offering digital government services
  • Financial institutions and banks operating online platforms
  • Healthcare providers handling sensitive personal data
  • Any organisation acting as a relying party in the EUDI Wallet ecosystem

Beyond regulatory obligations, many private sector organisations in trust-sensitive industries are choosing to adopt QWACs voluntarily. If your organisation operates in financial services or government services, a QWAC signals to your users and counterparties that your identity has been formally verified under EU law. This is increasingly relevant as digital interactions replace in-person processes and users become more aware of identity fraud risks.

How does a QWAC interact with the EUDI Wallet?

A QWAC plays a direct role in the EUDI Wallet ecosystem by enabling wallet users to verify the identity of the website or service they are interacting with before sharing any personal data. When a user presents credentials from their European Digital Identity Wallet to a relying party, the wallet can check the QWAC of the receiving website to confirm its legal identity before releasing any information.

This is a critical trust mechanism. The EUDI Wallet is designed to give users control over their data, but that control is only meaningful if users can also verify who is requesting their data. A QWAC provides that assurance on the relying party side of the interaction.

For organisations preparing to become relying parties in the EUDI Wallet ecosystem, having a valid QWAC is therefore not just a compliance checkbox. It is a foundational element of the trust infrastructure that makes wallet-based interactions possible. Organisations exploring their approach to digital identity readiness should factor QWAC adoption into their broader eIDAS 2.0 preparation.

What is the difference between a QWAC and a QSeal certificate?

A QWAC and a QSeal (qualified electronic seal certificate) serve different purposes within the eIDAS 2.0 trust framework. A QWAC authenticates a website and confirms the legal identity of the organisation operating it. A QSeal is used to protect the integrity and origin of data or documents issued by an organisation, functioning as a digital equivalent of a company stamp.

The key distinction comes down to what is being authenticated and in which direction. A QWAC tells a user visiting a website: “This site is operated by this verified legal entity.” A QSeal tells a recipient of a document or data package: “This content was issued by this verified legal entity and has not been altered.”

In the EUDI Wallet context, both certificates often work together. A relying party website might use a QWAC to identify itself to a wallet user, while also using a QSeal to sign the attestations or data it issues back to users. Understanding both is important for organisations building digital identity solutions that need to cover authentication, data integrity, and regulatory compliance in one coherent architecture.

How can an organisation obtain a QWAC?

To obtain a qualified website authentication certificate, an organisation must apply to a qualified trust service provider that is authorised to issue QWACs and is listed on an EU Member State’s trusted list. The process involves identity verification of the legal entity, domain ownership validation, and review of the application against the requirements defined in eIDAS 2.0.

The steps typically follow this sequence:

  1. Identify a qualified trust service provider on the EU Trusted List (EUTL) that offers QWAC issuance in your jurisdiction.
  2. Submit an application with documentation confirming your organisation’s legal identity, registration details, and the domain names to be covered.
  3. Complete the identity verification process as required by the QTSP, which may include document checks and verification against official registers.
  4. Receive and install the certificate on your web server, replacing or supplementing your existing SSL/TLS certificate.
  5. Maintain and renew the certificate in line with the validity period set by the issuing QTSP, typically one to two years.

Organisations in healthcare, pharmaceutical and life sciences, and other regulated sectors should also consider how QWAC issuance fits into their wider compliance programme, particularly where eIDAS 2.0 obligations overlap with sector-specific regulations.

How TrustTech helps with qualified website authentication certificates

Preparing for eIDAS 2.0 involves more than obtaining a single certificate. It requires aligning your identity infrastructure, trust services, and compliance processes with a rapidly evolving regulatory framework. That is where TrustTech adds value.

TrustTech supports organisations in regulated sectors with the full scope of digital identity and trust service readiness, including:

  • Assessing your current certificate and trust service landscape against eIDAS 2.0 requirements
  • Guiding your organisation through QWAC and QSeal adoption as part of a broader identity strategy
  • Connecting your systems to the EUDI Wallet ecosystem as a compliant relying party
  • Enabling reusable, wallet-ready digital identity flows that reduce friction and improve compliance
  • Supporting cross-sector interoperability for organisations operating across EU Member States

Whether you are just beginning to understand what eIDAS 2.0 means for your organisation or are ready to move into implementation, TrustTech provides the expertise and technology to make that transition practical and secure. Get in touch with TrustTech to discuss how we can support your qualified trust service journey.