European Trust Decisions Should Not Be Controlled by Browsers Alone
Who should decide which digital trust services Europe can rely on? Following the eIDAS 2.0 trilogue agreement, ESD supports the compromise reached on Article 45 and Qualified Website Authentication Certificates (QWACs). The paper argues that recognition of EU-regulated QWACs should not depend exclusively on the proprietary root-store policies of browser companies. Instead, the agreed framework combines regulatory oversight of QTSPs and the EU Trusted List with the ability of browsers to challenge individual QWACs or issuers where security concerns arise. ESD sees this shared approach as an important step towards transparent European governance of digital trust and greater European digital sovereignty.
Leave a Reply