In order to ensure that qualified trust service providers and the services they provide comply with the requirements set out in eIDAS – they must conduct a conformity assessment and submit a report issued by the conformity assessment body to the supervisory authority. Our company can provide support in preparing for the conformity assessment and in commenting on the documentation. We can provide support in the standard conformity of future solutions as part of a consultation.
Commission Implementing Decision 2016/650 defined mandatory standards for the certification of QSCDs, where the creation data is stored entirely, but not necessarily exclusively, in an environment managed by the user (e.g. smart cards, USB tokens). The protection profiles/standards had not yet been defined for remote qualified electronic signatures (e.g. HSM, signing server) at the time of the regulation, therefore eIDAS provides the possibility for alternative certification methods. Our company can conduct tests on QSCD devices in accordance with the requirements of eIDAS.