Qualified trust service providers
QTSPs deliver qualified services: signatures, seals, timestamps, website authentication and eID services. They face supervision by national authorities and must demonstrate security, availability and incident notification.
As a customer
Verify EU Trust List status, contractual SLAs, subprocessors and exit. Link to vendor register and ISO 27001 supplier reviews, especially when QES is business-critical.
As a provider
QTSPs often combine ISO 27001, ETSI standards and eIDAS technical specs. Keep evidence separated per service (QES vs timestamp) and show supervisory and audit results in management review.
Checklist
- Inventory eID, QES and QTSP use
- Map vendors and trust list status
- Link to ISMS, GDPR and risk register
- Plan DPIA where wallet or identity data
- Test fallback and incident scenarios
Practical next step
For qualified trust services eIDAS, ISO Ready links identity, trust and security measures in one ISMS, with actions, evidence and vendors toward audit. Run the readiness scan on iso-ready.nl.
More on eIDAS 2.0
- Eidas2 Compliance
- Qualified Electronic Signature
- Eidas2 Compliance Iso 27001
- Vendor Management Iso 27001
- Iso 27701 Privacy Management
- Dora Compliance