Skip to main content
PolicySpeak
← All files

EU consultation

Qualified certificates for electronic signatures and electronic seals

25 submissions from 19 organizations told the European Commission what they think about this file. Here is what each of them said, in their own words.

The Commission lists 29 submissions on this file. Shown here: the 25 from organizations. Not shown, by design: submissions from private individuals, which we never publish, and anything filed since our last weekly refresh.

Who showed up

24 submissions from industry — companies and their trade associations — against 1 from civil society: NGOs, consumer organizations, environmental groups and trade unions. That is 24 industry submissions for every one from civil society.

Industry 24Civil society 1Public authorities, academia, other 0

Groupings use the respondent type each organization selected when filing. Counting submissions, not organizations — a body that filed twice is counted twice.

The file, right now

The consultation closed on 13 May 2025 — it ran from 15 Apr 2025.

Policy area
Digital & tech (DG CNECT)
Where it stands
Awaiting adoption

How it got here

  1. Draft implementing regulation13 May 2025

Also on the Commission’s pipeline for this file, with no date recorded: Implementing regulation.

25 positions

IT

In.Te.S.A. SpA

· · filed 13 May 2025 · source

PDF

Enclosed, please find the detailed feedback from In.Te.S.A. SpA a Kyndryl Company, regarding the third set of draft Implementing Acts pertaining to the eIDAS 2 Regulation. We appreciate the opportunity to provide our input during this significant stage of regulatory advancement and remain available for any subsequent questions or dialogue.

LinkedInX
GB

German Banking Industry Committee (GBIC)

· · filed 13 May 2025 · source

PDF

The German Banking Industry Committee (GBIC) fully supports the attached comments of the European Credit Sector Associations (European Association of Co-operative Banks, European Banking Federation, and European Savings and Retail Banking Group ECSAs) on the draft implementing regulation concerning reference standards for qualified certificates for electronic signatures and qualified certificates for electronic…

LinkedInX
C

Cleverbase

· · filed 13 May 2025 · source

PDF

Cleverbase is a Dutch qualified trust service provider, offering identification and qualified trust services. We appreciate the opportunity to provide feedback on the third batch of eIDAS 2 implementing acts, as Cleverbase is closely involved in discussions around the eIDAS regulation and related standards.

LinkedInX
A

Assocertificatori

· · filed 13 May 2025 · source

PDF

AssoCertificatori is the Association of Italian Qualified Trust Service Providers and Certified Service Providers. Assocertificatori is a non-profit organization that brings together the vast majority of providers pursuant to EU Regulation 910/2014 eIDAS such as digital signatures, digital identities, electronic delivery, electronic timestamps and digital preservation of documents.

LinkedInX
IS

IT Security Association Germany (TeleTrusT)

· · filed 13 May 2025 · source

Annex Nr. 1 (3) und Nr. 2 (3) OVR-5.3-01: If any changes are made to a CP as described in clause 4.2.2 which affects the applicability, then the policy identifier shall be changed. Policy identifiers are not the same as document identifiers. Policy identifiers should never change. The requirement must be changed accordingly.

LinkedInX
EC

European Credit Sector Associations

· · filed 13 May 2025 · source

PDF

The European Credit Sector Associations (European Association of Co-operative Banks, European Banking Federation, and European Savings and Retail Banking Group, ECSAs) are supportive of the ambition to establish a coherent Europe-wide framework for digital identity (eIDAS 2.0).

LinkedInX
SA

Signicat AS

· · filed 13 May 2025 · source

Signicat's has not had time to provide detailed feedback to this implementing act and its annex, but a look reveals the same problems as the other implementing acts in this batch. Most important: - Add a provision to update to accommodate new versions of standards - Do not overrule standards' requirements unless absolutely necessary and justified - Several proposals are highly problematic to existing providers -…

LinkedInX
B

Bundesdruckerei

· · filed 13 May 2025 · source

In general, it should be noted that additional requirements that deviate from the referenced standards should be viewed critically because they interfere with professional discussions and autonomy. Technical standards are written and approved by a large group of experts after thorough discussions and scrutinization.

LinkedInX
TV

TÜV NORD CERT GmbH

· · filed 13 May 2025 · source

Standards versioning Definition of a specific version of the standards prohibits or at least significantly delays benefitting from future developments of the standard. After adoption of a new standard version, the time-consuming process of adapting the implementing act would be necessary. Hence we suggest adding "or later" to the definition of norm versions to include future releases of the standards.

LinkedInX
GZ

Gospodarska zbornica Slovenije

· · filed 13 May 2025 · source

Versions of ETSI standards and their compliance with the eIDAS Regulation The proposals for implementing acts reference ETSI standards that are relevant to individual trust services, while also amending the provisions outlined in those reference ETSI standards.

LinkedInX
GZ

Gospodarska zbornica Slovenije

· · filed 13 May 2025 · source

Revised Requirements for HSMs used by Trust Service Providers (TSPs) The eIDAS Regulation does not specify particular requirements for Hardware Security Modules (HSMs) that Trust Service Providers (TSPs) must use, unlike the requirements for Qualified Signature Creation Devices (QSCDs). There is no doubt that the private cryptographic keys used by TSPs are protected with the highest level of security.

LinkedInX
GZ

Gospodarska zbornica Slovenije

· · filed 13 May 2025 · source

Loosely defined standards for Key activation on HSMs certified under EUCC or EN 419221-5:2018 Protection profiles for Trust Service Provider cryptographic modules Part 5: Cryptographic module for Trust services Use of Private Keys Requires Authentication via HSM Mechanisms The use of private keys requires prior authentication through mechanisms provided by the Hardware Security Module (HSM).

LinkedInX
GZ

Gospodarska zbornica Slovenije

· · filed 13 May 2025 · source

Qualified electronic seal creation devices: When held by a legal entity that is not a TSP The eIDAS Regulation and the published draft implementing acts do not clarify the requirements for QSCD when such a device is used by a legal entity that is not a Trust Service Provider (TSP), and where the device is not operated as a remote QSCD.

LinkedInX
GZ

Gospodarska zbornica Slovenije

· · filed 13 May 2025 · source

EPRELs new Legal entity identifier format vs ETSI EN 319 412-1 V1.5.1 As of 22 April 2025, the EPREL (European Product Registry for Energy Labelling) requires that identifiers for legal entities be provided in a different format than the one currently defined in ETSI EN 319 412-1 V1.5.1. The basis for the new format is the Regulation L_202400994SL.000101.fmx.xml.

LinkedInX
GZ

Gospodarska zbornica Slovenije

· · filed 13 May 2025 · source

Versioning of standards ETSI standards should consistently include version numbers. Currently, some are versioned while others are not. In the absence of a version, the latest valid version is assumed during implementation.

LinkedInX
GZ

Gospodarska zbornica Slovenije

· · filed 13 May 2025 · source

Transition periods in standards implementation/Lifecycle of standards: Implementing acts enter into force 20 days after publication. Existing systems cannot adapt that quickly. Therefore, whenever a change occurs, there must be a longer transition period to allow for proper implementation.

LinkedInX
IG

INTESI GROUP

· · filed 12 May 2025 · source

PDF

Intesi Group, an Italian Qualified Trust Service Provider, expresses its gratitude for the opportunity to provide feedback on the draft of the Implementing Act included in the attached document. We hope our proposals will be carefully considered by policymakers.

LinkedInX
Z

Zetes

· · filed 12 May 2025 · source

1) Please take into account the existing eIDAS ecosystem and the need of all stakeholders for continuity and stability. 2) Please define and clarify the meaning of "presumption of compliance" and how and when this IR is to be adhered to by QTSPs, CABs and Supervisory Bodies. 3) Allow for continuity for commonly accepted and previously approved standards, policies and practices.

LinkedInX
C

ClubPSCo

· · filed 12 May 2025 · source

ClubPSCo members thank the European Commission for the excellent work carried out on the new regulations. These implementing acts will be very effective in improving safety and interoperability and developing the internal market on a fair and competitive basis. ClubPSCo members nevertheless propose the following few modifications.

LinkedInX
IG

IN Groupe

· · filed 12 May 2025 · source

Comment to Annex I, article 1, 13 covering GEN-6.5.2-02 and Annex II, article 1, 13, covering GEN-6.5.2-02. Existing QTSP may use cryptographic modules which are not CC or EUCC certified but according to one of the schemes ISO/IEC 19790 [3], FIPS PUB 140-2 [13] level 3 or FIPS PUB 140-3 [16] level 3.

LinkedInX
BM

Belgian Mobile ID - itsme

· · filed 12 May 2025 · source

PDF

Since itsme is committed towards user friendly and secure identity and trust services, we would like eIDAS 2 to be a big success. We are very glad about the new possibilities that eIDAS 2 brings, however, we see a few potential issues with the current drafts. So, we are very happy we are given the opportunity to deliver the feedback in the joint PDF, hoping that those issues can be avoided.

LinkedInX
S

Sectigo

· · filed 12 May 2025 · source

PDF

Setigo believes that some of the new requirements are very difficult to meet unless there´s a transition period of some years, for example, those related to the HSMs. Also consider that changing some of the "should" with "shall" it will go against usability and manageability of the different systems and solutions, for example, the use of the "algo paper", TS 119 312.

LinkedInX
PC

První certifikační autorita, a.s.

· · filed 9 May 2025 · source

Based on our experience with HSM devices, we do not consider it reasonable to completely eliminate the recognition of HSM certification according to FIPS, because the main HSM manufacturers (Entrust, Safenet, DocuSign, etc.) come from the USA, and if they decide for any reason not to perform certification or recertification according to ISO/IEC15408 and EUCC, their QTSP users will be forced to replace all relevant…

LinkedInX
EP

Česká pošta, s.p.

· · filed 7 May 2025 · source

We have two comments: 1st: (8) 6.3.10 Certificate Status Services In our opinion, there will be an enormous increase the size of the CRL which will result in a higher load on the systems on the TSP side and also an increase in the size of electronically signed documents where the CRL will be stored for verification purposes.

LinkedInX
ST

Swisscom Trust Services

· · filed 2 May 2025 · source

There are 2 observations to the Annex: =====Observation 1=========== COMMISSION IMPLEMENTING REGULATION (EU) .../... laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards reference standards for qualified certificates for electronic signatures and qualified certificates for electronic seals (thus the "general" Implementing Act) As well as in the…

LinkedInX
Take the dataCSV — all 25 submissionsJSONFull text, not the excerpt. Free to cite.Search every submission →

Follow this file

Get an email when a new organization files a position here: one email on Tuesdays, only when there is something new. Free.

We use your email for updates on this file, and PolicySpeak may contact you about the product. Unsubscribe in one click. Privacy policy.

Method. Every quote is verbatim from the organization’s own submission to the European Commission, trimmed to its opening passage and never summarized by a model. Where a submission was filed in another EU language we show the English text the European Commission publishes alongside it, labeled on the quote; the original is one click away at the source. Groupings use the respondent type the organization itself selected when filing. We deliberately do not label anyone “supportive” or “opposed” — you read what they wrote and draw your own conclusion. Organizations only, never individuals. Reused under Commission Decision 2011/833/EU; the European Commission is not liable for this reuse.