Paper Type: Position Papers

  • ESD Contribution to the Article 49 Review of eIDAS

    In the context of the Article 49 review, ESD proposes targeted amendments to make the eIDAS framework more effective and workable in practice. Drawing on the operational experience of Europe’s trust service industry, the paper identifies legal and practical obstacles and proposes concrete solutions to strengthen legal certainty, avoid duplicative compliance and support a coherent European Digital Identity ecosystem.

  • Position of the European Signature Dialogue on the Free Signatures Concept under Art. 5a(5)(g) of eIDAS 2.0

    Free signing through the European Digital Identity Wallet needs a clear, workable and sustainable framework. ESD calls for a common interpretation of Article 5a(5)(g), with clearly defined responsibilities for wallet providers and QTSPs, transparent rules for non-professional use, and appropriate financing mechanisms. The objective is a framework that delivers free wallet signing for citizens while ensuring legal certainty, fair competition and a sustainable European trust ecosystem.

  • Trust Services as an Enabling Layer for the Digital Product Passport – Contributions to Legal Certainty, Data Integrity and Interoperability under the ESPR

    A trusted Digital Product Passport does not require Europe to build a new trust framework from scratch. ESD calls for existing eIDAS trust services to serve as the enabling layer for the DPP, providing legal certainty, data integrity and interoperability while avoiding duplicate compliance structures and unnecessary costs.

  • Streamlining Digital Obligations and Compliance in the EU Digital Omnibus

    Europe needs a simpler and more coherent digital regulatory framework that strengthens competitiveness without compromising trust and security. ESD proposes a single-audit approach, mutual recognition of existing certifications and better alignment across eIDAS, NIS2, CRA, DORA and other EU digital rules — reducing duplicative compliance while allowing providers to focus resources on innovation and secure digital services.

  • Embedding Trust Services Across EU Digital Regulation – From Omnibus to Future Legislative Initiatives

    Europe already has a trusted foundation for simpler, more secure and interoperable digital regulation. ESD calls for Qualified Trust Services to be embedded by default across EU digital legislation, using the existing eIDAS framework to reduce compliance costs, strengthen legal certainty and interoperability, and support Europe’s digital sovereignty and competitiveness.

  • Clarification on the Scope and Limitations of Free Qualified Electronic Signatures under the EUDI regulation

    Free qualified electronic signatures under the EUDI Wallet are designed for citizens acting in their personal capacity. ESD calls for a harmonised implementation of Article 5a(5)(g) across Europe, clearly distinguishing private from professional and representative use in order to preserve legal certainty, fair competition and a consistent Digital Single Market for trust services.

  • Browsers Make One More Effort to Stop eIDAS Article 45 Changes After Trilogue Is Over

    Who should decide which digital trust services Europe can rely on? Following the eIDAS 2.0 trilogue agreement, ESD supports the compromise reached on Article 45 and Qualified Website Authentication Certificates (QWACs). The paper argues that recognition of EU-regulated QWACs should not depend exclusively on the proprietary root-store policies of browser companies. Instead, the agreed framework combines regulatory oversight of QTSPs and the EU Trusted List with the ability of browsers to challenge individual QWACs or issuers where security concerns arise. ESD sees this shared approach as an important step towards transparent European governance of digital trust and greater European digital sovereignty.

  • QWACs Explained Simply: What Are the Facts Regarding the Statement About Spying on EU Citizens?

    The debate around Article 45 eIDAS and Qualified Website Authentication Certificates (QWACs) is accompanied by unsubstantiated claims that the new framework could facilitate surveillance of EU citizens and undermine internet security. ESD publishes this fact-based explainer to put these claims into perspective and clarify how QWACs and the proposed governance framework actually work. At its core, the controversy is about governance: should QWACs that comply with EU law and are issued by supervised and audited Qualified Trust Service Providers be subject to an additional layer of proprietary browser requirements? ESD argues that compliance with the European regulatory framework should provide the basis for recognition of QWACs, while browsers remain free to perform operational security checks and act on genuine security concerns.

  • ESD Experts Support Trilogue Compromise and Emphasize Necessity for Highest Security of the Internet

    As the eIDAS 2.0 negotiations enter their final phase, claims emerge that the proposed Article 45 compromise would weaken internet security and force browsers to accept insufficiently secure certificates. ESD experts respond to these claims point by point, explaining why QWACs are not new, why Qualified Trust Service Providers are subject to rigorous European supervision and security requirements, and why the trilogue compromise provides a sound basis for secure website authentication. At the heart of the debate is also a question of governance: additional requirements affecting EU-regulated trust services should not be imposed unilaterally through proprietary browser policies, but developed through transparent, consensus-based standards and the European regulatory framework.

  • Google Returns to Anti-Competitive Behavior by Limiting All Certificates to 90 Days Only – Will This Kill Identity Certificates and Make eIDAS Obsolete?

    A seemingly technical change can have far-reaching consequences for Europe’s digital trust ecosystem. Following Google’s proposal to reduce the maximum validity of TLS certificates, including QWACs, to 90 days, ESD raises concerns about its impact on identity-based website authentication, competition and the objectives of eIDAS. ESD argues that rules affecting EU-regulated trust services should not be determined unilaterally through proprietary browser policies, particularly where they may conflict with European standards and favour particular technological or business models. Changes of this significance should be based on demonstrated security needs and developed through transparent, consensus-based processes that respect Europe’s regulatory framework and digital sovereignty.