AssoCertificatori is the Association of Italian Qualified Trust Service Providers and Certified Service Providers. Assocertificatori is a non-profit organization that brings together the vast majority of providers pursuant to EU Regulation 910/2014 eIDAS such as digital signatures, digital identities, electronic delivery, electronic timestamps and digital preservation of documents.
EU consultation
General requirements for qualified trust service providers
13 submissions from 13 organizations told the European Commission what they think about this file. Here is what each of them said, in their own words.
The Commission lists 20 submissions on this file. Shown here: the 13 from organizations. Not shown, by design: submissions from private individuals, which we never publish, and anything filed since our last weekly refresh.
Who showed up
9 submissions from industry — companies and their trade associations — against 1 from civil society: NGOs, consumer organizations, environmental groups and trade unions. That is 9 industry submissions for every one from civil society.
Groupings use the respondent type each organization selected when filing. Counting submissions, not organizations — a body that filed twice is counted twice.
The file, right now
The consultation closed on 2 Oct 2025 — it ran from 4 Sept 2025.
- Policy area
- Digital & tech (DG CNECT)
- Where it stands
- Awaiting adoption
- Adoption expected
- 31 Dec 2025
How it got here
- Draft implementing regulation2 Oct 2025
Also on the Commission’s pipeline for this file, with no date recorded: Initiative planned, Implementing regulation.
13 positions
TeamSystem is a leading technology company for the development of business management solutions for SMEs and professionals. The Group supports its customers in the digital transformation of the entire supply chain through a comprehensive and integrated offering of innovative technologies based on AI, SaaS, and cloud designed to manage and optimize internal processes and strengthen collaboration with their reference…
Bitkom underlines the importance of keeping compliance and security requirements for qualified trust service providers proportionate and practical. Excessive or overly broad notification duties, redundant provisions, and unclear references risk creating legal uncertainty, administrative overload, and operational inefficiencies without adding supervisory value.
The German Banking Industry Committee (GBIC) fully supports the attached comments of the European Credit Sector Associations (European Association of Co-operative Banks, European Banking Federation, and European Savings and Retail Banking Group ECSAs) on the draft implementing regulation concerning the requirements for qualified trust service providers (QTSPs) providing qualified trust services in the context of…
www.marcobava.it
· · filed 1 Oct 2025 · source
This initiative establishes a list of reference rules, specifications and procedures for qualified trust service providers. The rules specifically address the functioning and management practices of qualified trust service providers.
Filed in Italian · English published by the European Commission
Implementing Regulation concerning QTSP Compliance Please find below the comments of the European Signature Dialog (ESD). ESD stands as the pinnacle consortium of leading European Qualified Trust Service Providers (QTSPs). We are pleased to provide our contribution in relation to the implementing regulations of eIDAS 2 Regulation, in the spirit of supporting a clear, effective, and future-proof framework.
Bundesagentur für Arbeit
· · filed 1 Oct 2025 · source
Article 1 None in Article 24(2) nor is there a definition of reaction times for the supervisory body. These need to be supplemented. The term “changes” is far too generic, see the following comments on individual numbers. In this formulation, each QTSP must consult with its supervisory authority. Are clarifications on national law or supervisory requirements planned?
Filed in German · English published by the European Commission
The European Credit Sector Associations (European Association of Co-operative Banks, European Banking Federation, and European Savings and Retail Banking Group - ECSAs) are supportive of the ambition to establish a coherent Europe-wide framework for digital identity (eIDAS 2.0).
Namirial S.p.A. is a leading provider of secure digital transaction management services and solutions. Established in 2000 in Italy, the company is now a multinational company that provides software solutions and Digital Trust Services for the digitalization of businesses and public administration entities.
The obligation to notify supervisory bodies the changes should be limited to relevant changes, meaning with an objective impact on the risk analysis, or creating a real impact to end users. ClubPSCo has experimented such procedures with French ANSSI for more than a decade, and it appears to be realistic, strong enough and practicable for QTSP.
Bundesdruckerei
· · filed 30 Sept 2025 · source
- In general: Harmonized regulations regarding liability coverage according to Art 24 Abs. 2 lit. c) eIDAS should be integrated into this Implementing Regulation, in particular through liability insurance. Currently, there is still a great deal of fragmentation in the supervisory practices of the member states in this field. Harmonization through uniform requirements is absolutely essential. - Art 1 Nr.
At Penneo A/S we fully support the harmonisation of qualified trust services, in order to create a level playing field for qualified trust service providers across all Member States. We acknowledge and support the objective of the draft amendment to Article 24(2)(a), which is to ensure that supervisory bodies are adequately informed about modifications to qualified trust services.
Our feedback presents targeted proposals to strengthen the draft Implementing Regulation for Qualified Trust Service Providers (QTSPs) under eIDAS 2.0. We advocate for enhanced legal certainty, global interoperability, and robust cybersecurity by embedding core principles like exclusive control over digital records, immutable metadata audit trails, and the mandatory use of globally recognised identifiers (e.g.…
Method. Every quote is verbatim from the organization’s own submission to the European Commission, trimmed to its opening passage and never summarized by a model. Where a submission was filed in another EU language we show the English text the European Commission publishes alongside it, labeled on the quote; the original is one click away at the source. Groupings use the respondent type the organization itself selected when filing. We deliberately do not label anyone “supportive” or “opposed” — you read what they wrote and draw your own conclusion. Organizations only, never individuals. Reused under Commission Decision 2011/833/EU; the European Commission is not liable for this reuse.