Qualified trust service providers
QTSPs deliver qualified services: signatures, seals, timestamps, website authentication and eID services. They face supervision by national authorities and must demonstrate security, availability and incident notification.
As a customer
Verify EU Trust List status, contractual SLAs, subprocessors and exit. Link to vendor register and ISO 27001 supplier reviews — especially when QES is business-critical.
As a provider
QTSPs often combine ISO 27001, ETSI standards and eIDAS technical specs. Keep evidence separated per service (QES vs timestamp) and show supervisory and audit results in management review.
Checklist
- Inventory eID, QES and QTSP use
- Map vendors and trust list status
- Link to ISMS, GDPR and risk register
- Plan DPIA where wallet or identity data
- Test fallback and incident scenarios
Practical next step
For qualified trust services eIDAS, ISO Ready links identity, trust and security measures in one ISMS — with actions, evidence and vendors toward audit. Run the readiness scan on iso-ready.nl.
More on eIDAS 2.0
- Eidas2 Compliance
- Qualified Electronic Signature
- Eidas2 Compliance Iso 27001
- Leveranciersbeheer Iso 27001
- Iso 27701 Privacy Management
- Dora Compliance