eIDAS-compliant digital trust services: from qualified signatures to archiving

A consistent "signature to archive" process. How to ensure the authenticity, integrity and long-term verifiability of documents based on eIDAS.
eIDAS-compliant digital trust services: from QES to LTV archiving

At podpisano.pl , we help companies and institutions every day to "close" processes fully digitally - without printing, scanning and nerves. Below we explain what are digital trust services, what types they include according to EU and Polish law, and what we can realistically help you with.

What are digital trust services?

These are electronically provided services that ensure identity, integrity, confidentiality, authenticity and inviolability of data in online transactions.

The foundation is:

  • regulation eIDAS - Regulation (EU) No. 910/2014, updated in 2024 by Regulation (EU) 2024/1183 (so-called eIDAS 2) - eIDAS 2 maintains the existing catalog of services (e.g., signatures, seals, time stamps, registered deliveries, certificates for websites) and expands it with new ones (including archiving, electronic registries, management of remote QSCDs (signature tools) and electronic attestation of attributes);
  • poland Law on trust services and electronic identification. In Poland, national legislation implements and supplements eIDAS (t.j. Dz.U. 2024 item 1725), and there is a separate law in the area of electronic delivery (Dz.U. 2024 item 1045).

 

Full list of trust services

"Classic" eIDAS services (2014)

  1. Electronic signature (including qualified QES) - Proof that a specific person has made a statement of intent under a document. A QES has the force of a handwritten signature throughout the EU.
  2. Electronic seal (qualified QESeal) - "Organization signature"; secures the origin and integrity of data on the part of an entity (e.g., a company).
  3. Electronic time stamp (qualified) - Reliable proof of the moment of existence of data/document. Key to long-term verification.
  4. Registered Electronic Delivery Service (ERDS) - The digital equivalent of a registered letter "with acknowledgment of receipt" (in Poland linked to the public e-Delivery service).
  5. Certificates for website authentication (QWAC/QWeb) - assure users that they are connecting to the correct, authenticated site.
  6. Qualified signature/seal validation services - Verification of the validity and status of signatures/seals in accordance with regulations.
  7. Qualified maintenance/validity preservation services - Maintaining the evidentiary value of signatures/seals over the long term (LTV).

New/expanded services introduced by eIDAS 2 (2024):

  1. Management of remote qualified signature devices (QSCD) and seals - Secure use of a qualified key "in the cloud" with strong authentication.
  2. Qualified electronic archiving - Receiving, storing, accessing and deleting data/documents with a guarantee of integrity, legibility and provenance throughout the storage period.
  3. Qualified electronic ledger (electronic ledger) - Maintaining an ordered, unalterable sequence of records (e.g., block chains) with guaranteed integrity and sequence.
  4. Electronic attribute attestations (EAAs) - Qualified attribute attestations (e.g., service role, authority), which will also be presentable in the European Digital Identity Wallet (EUDI Wallet).

Trusted lists and surveillance

  1. Lists of trusted providers (EUTL/TL) - official registers of qualified providers of and services, published by EU countries on the basis of Article 22 of eIDAS. This is the main source of "who is qualified and for what".

Where does the national law come in?

  • Law on trust services and electronic identification (i.e., Journal of Laws 2024, item 1725) - defines, among other things, the principles of supervision, obligations of providers, proceedings in Poland.

 

  • Law on electronic delivery (i.e., Journal of Laws 2024, item 1045) - regulates the implementation of the public service of registered delivery (e-Delivery), including obligations of public entities and business.

What digital trust services can we support you with?

Podpisano.pl as authorized partner of Asseco Certum offers:

1) Qualified Signature for Persons (QES) - SimplySign, Certum Mini

  • We will advise on the choice of carrier (mobile/remote vs. card/USB), 
  • we will confirm the identity of the person to whom the qualified signature is issued (the service is also available remotely for foreigners), 
  • We will launch and train with practice (PAdES/XAdES/CAdES, LTV, countersignature/co-signature). 
  • we will provide qualified time stamp and good long-term practices.

2) Qualified stamp of the organization

  • Selection of seal type (e.g. for invoices, reports, serial letters), 
  • Implementation in systems (ERP/DMS/document circulation), 

3) e-Delivery (ERDS).

  • We explain responsibilities, help set up and configure the box (BAE/ADE), 
  • We integrate with the workflow system, 
  • We train on procedures (powers of attorney, correspondence book, rules). 

4) LTV validation and archiving

Plus.

at podpisano.pl we implement best practices for digital trust services and teach our clients to apply podpisano.pl's good practices:

  • Always add a time stamp to the signature/stamp - this is your real "insurance" for years and the basis of LTV.
  • Verify first, then add more signatures - you will avoid a cascade of errors at the end of the process.
  • Determine what the procedures require: "two signatures on a document" ≠ "the second person confirms the signature of the first" (these are different modes: co-signature vs. countersignature).
  • Check the supplier on the trusted list (EUTL) - is a simple risk control and a requirement for many tenders.
  • Updates to signature software signature software and trust lists are not a fad, but a condition for correct validation (algorithms, certificate chains, policies change).

Legal basis (most important)

  • Regulation (EU) No. 910/2014 (eIDAS). - A framework for identification and trust services in the EU. EUR-Lex
  • Regulation (EU) 2024/1183 (eIDAS 2). - New European digital identity, EUDI wallet, expanded catalog of trust services (including archiving, ledger, remote QSCD, EAA). EUR-Lex
  • Lists of trusted suppliers (Article 22 of eIDAS). - EUTL publication obligation by EU countries.List of trusted suppliers
  • Law on trust services and electronic identification - i.e. Journal of Laws. 2024 item 1725.
  • Law on electronic delivery - i.e. OJ. 2024 item 1045.

     

Do you want to implement signatures, seals, e-Delivery or prepare your company for new systems such as KseF? Write to us: signatures, seals, time stamps, LTV validation/archiving - this is our daily bread.

Call us at

and we will put you in touch with one of our representatives available virtually nationwide.

Check also:

Do you need help?

Find what you're looking for