A reliable trust services ecosystem requires certainty throughout the lifecycle of certified signature and seal creation devices. ESD calls for greater transparency and oversight of QSCD certification plans, enabling QTSPs to anticipate changes, protect investments and maintain continuity of critical digital services across Europe.
Paper Type: Consultation Responses
-
Commission Implementing Regulation Proposal on Initiation of Qualified Trust Services
Effective supervision should be rigorous, proportionate and responsive to the circumstances of each case. ESD proposes that supervisory bodies retain the discretion to determine when on-site verification is necessary before granting qualified status, avoiding unnecessary costs and delays while maintaining robust oversight of qualified trust services.
-
Commission Implementing Regulation Proposal on Management of Remote Qualified Electronic Signature Creation Devices and of Remote Qualified Electronic Seal Creation Devices as Qualified Trust Services
Europe’s new framework for remote qualified signatures should strengthen security while preserving the services and digital processes that already work at scale. ESD calls for realistic transition periods, technologically workable requirements and sufficient flexibility for established use cases such as automated and batch signing, supporting a secure, interoperable and innovative European trust services ecosystem.
-
ESD Comment on the Commission Draft Implementing Regulation Based on the Cyber Resilience Act (CRA)
Strong cybersecurity is essential for Europe’s digital infrastructure — but stronger security does not necessarily mean adding overlapping regulatory layers. In its comments on the CRA Implementing Regulation, ESD highlights that Qualified Trust Service Providers already operate under a comprehensive high-assurance security, supervision and conformity-assessment framework under eIDAS and related standards. Applying additional CRA requirements to the same regulated services and their necessary software components risks duplicating compliance obligations without delivering corresponding cybersecurity benefits. ESD therefore calls for a clear delineation between the horizontal CRA framework and the sector-specific eIDAS regime.
-
European Commission Consultation on the European Digital Identity Wallets (EUDIW) – Recommendations on the Commission Draft Implementing Regulations
The European Digital Identity Wallet can become a cornerstone of Europe’s trusted digital ecosystem — provided its implementation builds on solutions that already work. In its response to five draft Implementing Regulations, ESD calls for a coherent and practical framework that leverages existing eIDAS trust infrastructure, qualified trust services and proven industry standards rather than creating unnecessary new mechanisms. Across issues ranging from security incidents and cross-border identity matching to relying-party registration and electronic attestations of attributes, ESD’s recommendations aim to strengthen security, interoperability and user trust while enabling efficient implementation of the EUDI Wallet across Europe.
-
European Commission Consultation on the European Digital Identity Wallets (EUDIW) – ESD Recommendations on the Commission Draft Implementing Regulations
The European Digital Identity Wallet should deliver on one of eIDAS 2.0’s central promises: secure and seamless digital identity across the Single Market. In its response to five draft Implementing Regulations, ESD calls for greater harmonisation, clearer technical standards and a consistent European certification approach to prevent fragmentation into national wallet ecosystems. Building on proven industry standards and Europe’s existing qualified trust infrastructure can strengthen security and interoperability while preserving competition and cross-border choice for users and service providers.
-
Comments of the European Signature Dialog (ESD) on the Draft of NIS2 Implementing Regulation
Effective cybersecurity regulation needs to be both ambitious and workable in practice. In its response to the draft NIS2 Implementing Regulation, ESD calls for clearer and more proportionate requirements that recognise the different functions and criticality of individual trust services. ESD advocates realistic incident-reporting thresholds, precise legal definitions and greater reliance on established standards, particularly ETSI EN 319 401 for qualified trust services. A harmonised, standards-based approach can strengthen cybersecurity while supporting consistent supervision, cross-border trust services and a functioning Digital Single Market.