Ga naar inhoud

Qualified trust services under eIDAS 2.0

Qualified trust services under eIDAS 2.0: practical guide on eIDAS 2.0, trust services and compliance — for IT, privacy and leadership.

Book an informal conversation

ISO Ready helps you align policy, risk, and evidence — without endless document churn.

Run the ISO 27001 readiness scan

Qualified trust service providers

QTSPs deliver qualified services: signatures, seals, timestamps, website authentication and eID services. They face supervision by national authorities and must demonstrate security, availability and incident notification.

As a customer

Verify EU Trust List status, contractual SLAs, subprocessors and exit. Link to vendor register and ISO 27001 supplier reviews — especially when QES is business-critical.

As a provider

QTSPs often combine ISO 27001, ETSI standards and eIDAS technical specs. Keep evidence separated per service (QES vs timestamp) and show supervisory and audit results in management review.

Checklist

  • Inventory eID, QES and QTSP use
  • Map vendors and trust list status
  • Link to ISMS, GDPR and risk register
  • Plan DPIA where wallet or identity data
  • Test fallback and incident scenarios

Practical next step

For qualified trust services eIDAS, ISO Ready links identity, trust and security measures in one ISMS — with actions, evidence and vendors toward audit. Run the readiness scan on iso-ready.nl.

More on eIDAS 2.0

Key takeaways

  • Inventory trust services and wallet use before major projects.
  • Link eIDAS to ISMS, GDPR and vendor register — one trail.
  • Test fallback and logging; QES outage is a business continuity scenario.

Veelgestelde vragen

When does eIDAS 2.0 apply to Qualified trust services under eIDAS 2.0?
When you offer or consume digital identity, wallet attributes, QES or qualified trust services in the EU — alongside national implementation timelines.
Does eIDAS replace ISO 27001?
No. eIDAS regulates trust services; ISO 27001 helps the ISMS and evidence for security controls around PKI, logging and vendors.
How does this relate to national eID schemes?
National schemes remain; eIDAS 2.0 adds the EUDI wallet and EU-wide interoperability. Plan transition and fallback.
What role does GDPR play?
Identity and attribute data are personal data. DPIA, records and minimisation remain leading.
How do we start with Qualified trust services under eIDAS 2.0?
Inventory current trust services, map vendors and link to ISMS and privacy records before rolling out new wallet or QES processes.

Run the ISO 27001 readiness scan

See where you stand before investing in documents or consultants.

Start the readiness scan