▷ What Are Digital Trust Services? - EADTrust
Inicio > Regulation > What Are Digital Trust Services and What Are They Used For?

What Are Digital Trust Services and What Are They Used For?

Qué son los servicios de confianza digital

Suscríbete:

Any executive or legal officer should know how to answer this: what exactly makes a digital document have the same legal value as a paper document? Not the fact of printing it and signing it with a pen (that is turning it into paper). But the fact that it remains in electronic format and is still fully valid as evidence, fully admissible in a court, fully recognised by any public administration in the European Union.

The short answer is: digital trust services. They are the instruments that Regulation (EU) 2024/1183 (eIDAS2) creates and regulates to give legal value to electronic transactions. Without them, the digital world would be a collection of easily modifiable files that are difficult to prove. With them, electronic documents can have a legal presumption of authenticity, integrity and a certain date, exactly what physical documents bearing a notarial signature have.

I want to explain what they are, which ones exist under eIDAS2, what each one does and why your company probably already needs them, even if it does not know it.

Key Concepts for Understanding Digital Trust Services

Trust Service

An electronic service normally provided for remuneration, consisting of the creation, verification and validation of electronic signatures, electronic seals, electronic timestamps, electronic registered delivery services and certificates related to these services.

Qualified Trust Service

A trust service that meets the applicable requirements of the eIDAS Regulation and whose qualification has been recognised in the EU Trusted List of the corresponding Member State. Its services have an automatic legal presumption throughout the EU.

SHA-256 Hash

A cryptographic function that calculates a unique digital fingerprint of the contents of a file. The slightest modification produces a different hash, ensuring the detection of any alteration. The technical basis of integrity in all qualified services.

rPaaS (regulated Platform as a Service)

A service model through which EADTrust deploys its QTSP infrastructure as a service that can be integrated into the client’s organisation, via API, in Oracle’s sovereign cloud, in AWS or in the client’s own data centre.

EAD Factory

EADTrust’s digital trust platform that integrates eIDAS services (signature, timestamp, registered delivery, qualified archiving) into the client’s business processes, acting as the organisation’s own QTSP infrastructure.

The Problem of Distrust in the Digital Environment

Recital 1 of the eIDAS Regulation states it clearly: creating a climate of trust in the online environment is essential for economic and social development. Distrust, particularly due to perceived legal uncertainty, makes consumers, businesses and public authorities hesitate when carrying out transactions electronically.

The problem is not technological. It is legal. A digital document can be modified without leaving a visible trace. An email can be spoofed. A scanned signature inserted into a PDF can be copied into any other PDF. Today’s file may not be yesterday’s file. And before a court, all of this creates reasonable doubts that can destroy any contract, any notification, any agreement that has been managed exclusively through digital channels.

Digital trust services resolve these doubts through three combined mechanisms: identification (who the sender was), integrity (the content has not changed) and a certain date (exactly when it happened). When all three are present and have been certified by a qualified trust service provider (QTSP) supervised by the State, the result has a legal presumption.

A qualified digital trust service is, in essence, an independent third party, supervised by the State, that certifies that something happened, when it happened and who did it, with full legal validity throughout the European Union.

QTSPs (EADTrust) and the EU Trusted List

Trust services cannot be provided by just any company. The Regulation distinguishes between non-qualified providers (which may provide services without prior verification of requirements, but are subject to subsequent supervision) and qualified providers (QTSPs), which must pass a prior compliance verification and whose inclusion in the EU Trusted List (the trusted list) is the condition that activates the legal presumption of their services.

A signature provider that is not included in the EU Trusted List may provide valid services, but without the automatic legal presumption that the Regulation grants to qualified services. The procedural difference is relevant: with a qualified service, whoever challenges the signature or seal must prove that it is not authentic. Without it, whoever submits it must prove that it is authentic.

In Spain, QTSPs are supervised by the Ministry of Economic Affairs and Digital Transformation. EADTrust is included in the EU Trusted List and supervised by this Ministry, authorised to operate in all countries of the European Union and the European Economic Area.

EAD Factory: Digital Trust Infrastructure Integrated into Your Company

Most companies contract digital trust services in the same way they contract any other SaaS: they pay per transaction, depend on an external provider and expect everything to work. EAD Factory proposes a different model.

EAD Factory is a regulatory integration as a service (rPaaS) that brings the infrastructure of a qualified trust service provider directly into a company’s processes, integrable through REST API with any existing system (ERP, CRM, document platform) without the company itself having to become a qualified provider. Developed together with g-digital and deployed on Oracle’s sovereign cloud in the European Union, it operates under a flat rate: no transactional model, no costs that scale with volume, no surprises on the invoice.

The simplest way to understand it is with the metaphor we use internally: the platform is the base, and the services are Lego pieces. Each module (Signature Manager, eArchiving, Notice Manager, GoCertius) is added according to what the organisation needs, at the moment it needs it, on the same qualified infrastructure. The result is what we call preventive digital legal certainty integrated into the operational core of the company, not added on top as a last-minute compliance layer.

Below are some of the modules that currently make up EAD Enterprise Suite and the capabilities of each one.

Trust Services Available Under eIDAS

Spanish Law 6/2020, which complements the eIDAS Regulation, lists them precisely: electronic seal for legal entities, qualified signature and seal validation service, qualified signature and seal preservation service, electronic timestamping service, electronic registered delivery service and website authentication certificate issuance service. To these, eIDAS 2.0 adds qualified electronic archiving and qualified electronic attestations of attributes.

Each one solves a different problem. Together, they cover practically all the cases involving digital business transactions that require legal certainty.

Electronic Signature (Signature Manager)

The electronic signature is the instrument through which a natural person expresses their will in a digital document. The eIDAS Regulation regulates three levels (simple, advanced and qualified), each with different technical requirements and different legal effects.

The simple signature is valid as evidence, but it is easily challengeable. The advanced signature has high evidential value thanks to the audit trail. The qualified signature has a legal effect equivalent to a handwritten signature throughout the European Union and activates the reversal of the burden of proof.

In Spain, there is also the advanced signature with a qualified certificate, a type that combines the advanced level with a certificate issued by a QTSP, without the need for a qualified signature creation device (QSCD). It has an iuris tantum presumption of authenticity in Spain and is the signature accepted for most procedures with the Spanish public administration.

It is needed for contracts between companies, employment contracts, informed consent forms, confidentiality agreements, public tenders, procedures with the public administration.

Electronic Seal

While the signature is for natural persons, the electronic seal is for legal entities, companies and organisations. Law 6/2020 establishes the new paradigm: only natural persons are authorised to sign electronically; electronic seals are reserved for legal entities.

The qualified electronic seal has a presumption of data integrity and correctness of origin. Certified by a QTSP (EADTrust), it guarantees that the document comes from that specific company and has not been modified since it was sealed. In the context of EPREL, for example, it is the instrument that manufacturers and importers need to verify their identity as suppliers in the European Commission’s database.

It is needed for issuing electronic invoices, verifying suppliers in EPREL, authenticating corporate documents, electronic communications from legal entities, accessing European regulatory systems, possibly for the authenticity of data in the Digital Product Passport.

Qualified Electronic Timestamp

The qualified electronic timestamp links an exact date and time to an electronic document or item of data, so that any subsequent modification can be detected. Its legal effect: presumption of the accuracy of the date and time and of the integrity of the linked data.

Article 41 of the eIDAS Regulation establishes this presumption. Article 326.4 of the Spanish Civil Procedure Act, in the wording given by Law 6/2020, turns it into a reversal of the burden of proof: if someone challenges the date or integrity of a document with a qualified electronic timestamp, the verification is at their expense, and if it is unsuccessful, so are the costs.

The technological process that makes this possible is specific: the SHA-256 hash of the document is calculated (a unique digital fingerprint of its contents). The QTSP (EADTrust) issues a qualified electronic timestamp associated with that hash, signed with its key and certificate. Any subsequent modification of the document produces a different hash, which makes the alteration undetectable.

In GoCertius, the qualified electronic timestamp is also complemented by registration on blockchain (on the Omega DLT network, managed by LACNet), which adds an additional layer of immutability: the record cannot be altered, follows a verifiable order and remains redundantly available across all nodes in the network.

It is needed to prove that a document existed on a specific date, interrupt limitation periods, provide reliable evidence of deliveries or communications, support contractual deadlines, certify digital evidence such as photographs, videos or chat conversations.

Electronic Registered Delivery (Notice Manager)

The electronic registered delivery service makes it possible to transmit data between third parties by electronic means with proof of sending, receipt and content integrity. It is, in essence, the digital equivalent of a burofax.

Article 44 of the eIDAS Regulation establishes the requirements for the qualified version: identification of the sender with a high level of reliability, identification of the recipient before delivery, protection of the sending and receipt through the advanced signature or seal of the QTSP, and indication of the date and time through a qualified electronic timestamp.

Notice Manager provides this service in certified form (not qualified in the strict sense of Article 44), backed by EADTrust as a QTSP: it certifies the exact content sent through a cryptographic hash, the date and time with a qualified electronic timestamp, and the opening of the message when the channel allows it. The result is a completion certificate with full validity as evidence in judicial or arbitration proceedings.

It may be needed for employment communications with legal significance (dismissals, sanctions, notices), payment demands, contract terminations, compliance notifications, any communication where it is necessary to prove that it was sent, when and with what content.

Website Authentication (QWAC)

Qualified website authentication certificates (QWACs) guarantee the identity of the entity behind a website. Recital 67 of the Regulation explains their purpose: services that help create trust and confidence in carrying out online commercial transactions, given that users will trust a website that has been authenticated.

The difference from an ordinary SSL certificate is the verification of the legal identity of the entity operating the website: a QWAC certifies that the website belongs to the company it claims to belong to, with the backing of EADTrust as a supervised QTSP.

Above all, it is needed for online banking services, electronic administration platforms, any website where the identity of the operating entity has legal relevance for the user.

Qualified Signature Validation

The qualified validation service for qualified electronic signatures makes it possible to verify automatically that a qualified signature is authentic, that the certificate was valid at the time of signing and that it had not been revoked.

It can only be provided by a QTSP that performs the validation in accordance with Article 32 of the Regulation and allows relying parties to receive the result automatically, reliably and efficiently, signed or sealed with the QTSP’s own advanced signature or seal.

It may be needed in contracting processes that receive documents signed by third parties and need to verify their authenticity, B2B e-commerce platforms, tenders and competitions that require a qualified signature, any automated process for receiving signed documents.

Signature Preservation

The qualified preservation service for qualified electronic signatures (also called a preservation service) guarantees that a qualified signature remains valid and verifiable beyond the period of technological validity of the cryptographic algorithms with which it was created.

Cryptographic algorithms have functional expiry dates: what is secure today may not be secure in ten years when quantum computing advances. The preservation service guarantees that the signature remains valid by periodically resealing the documents with more modern algorithms, without losing traceability to the original signature.

It is needed for long-term contracts whose legal validity must be maintained for decades, medical records, digital notarial documents, any signed document whose regulatory retention exceeds the technological validity periods of current algorithms.

Qualified Electronic Archiving (eArchiving)

Qualified electronic archiving is the newest service in the eIDAS catalogue: it was introduced by the eIDAS 2.0 Regulation (Regulation (EU) 2024/1183) as a qualified service with its own legal presumption. Article 45 of the amended Regulation defines it: it guarantees the receipt, storage, retrieval and deletion of electronic data and electronic documents to ensure their durability and legibility, as well as to preserve their integrity, confidentiality and proof of origin throughout the retention period.

Documents preserved through a qualified electronic archiving service benefit from the presumption of their integrity and origin during the retention period. Implementing Regulation (EU) 2025/2532 establishes the technical requirements: the data must be preserved and protected against loss or alteration, with procedures capable of ensuring its durability beyond the period of technological validity, and through qualified electronic timestamps that certify the moment when custody began.

EADTrust’s eArchiving service provides this service: deployed in Oracle’s EU Sovereign Cloud, it certifies the existence, integrity, permanence and immutability of electronic documents throughout their lifecycle through a qualified electronic timestamp. The applicable technical standards are ETSI EN 319 421, ETSI EN 319 422, ETSI TS 119 511 and ETSI TS 119 512.

It is needed, and greatly, for the regulatory retention of documents (contracts, invoices, records), retention obligations under MiFID II, PSD2 or DORA in the financial sector, backup of the Digital Product Passport, archiving of legal and compliance evidence, due diligence documentation and data rooms.

Electronic Attestations of Attributes

Qualified electronic attestations of attributes are the newest service and the one that will have the greatest impact in the coming years. Introduced by eIDAS 2.0, it allows specific entities (universities, professional associations, public bodies) to issue verifiable attestations about people’s attributes: academic qualifications, professional authorisations, powers of representation, specific qualifications.

The EUDI Wallet will be the instrument that allows citizens and companies to store and present these attestations to third parties, so that the recipient can verify their authenticity cryptographically without needing to contact the issuing entity.

It is needed for verifying professional authorisations in recruitment processes, proving powers of representation in corporate transactions, verifying academic qualifications, any process where it is necessary to prove a personal attribute in a verifiable way without physical presence.

How the Services Work Together: The Power of Integration

Law 6/2020 explicitly states that these services can be combined with each other for the provision of complex and innovative services. This combination is exactly what EAD Factory does: integrating several qualified services into a single business workflow.

A corporate contract signing process in Signature Manager combines an advanced signature (for the will of the individuals) with a qualified electronic timestamp (for the certain date of each step) and electronic archiving (for preservation with a legal presumption during the regulatory period). The result is not the sum of three services: it is a complete process where each element reinforces the others.

A notification process in Notice Manager combines electronic registered delivery (for proof of the communication) with a qualified electronic timestamp (for the exact date) and a cryptographic hash (for the integrity of the content). The completion certificate is the synthesis of all these elements in a single evidential document.

And EAD Factory acts as QTSP infrastructure integrated directly into the client’s processes (through API, as rPaaS (regulated Platform as a Service) or deployed in the client’s own data centre, making digital trust not an external service that is consulted occasionally, but a cross-cutting layer that runs through the organisation’s entire back office.

The Complete Table: Trust Services Under eIDAS and eIDAS 2.0

ServiceFor whomWhat it guaranteesLegal effectEADTrust service
Electronic signatureNatural personsWill and identity of the signatorySimple/advanced: valid as evidence. Qualified: equivalent to a handwritten signature throughout the EUSignature Manager
Electronic sealLegal entitiesOrigin and integrity of the documentPresumption of integrity and correctness of origin throughout the EUQSealC with NTR (EPREL, DPP)
Qualified electronic timestampAny operatorDate, time and integrity at that momentPresumption of time accuracy and integrity. Reversal of the burden of proof in SpainGoCertius, Evidence Manager, eArchiving
Electronic registered deliverySenders and recipientsSending, receipt and integrity of the communicationValid as evidence; qualified version with full legal presumptionNotice Manager
Website authentication (QWAC)Website operatorsLegal identity of the operating entityRecognised throughout the EU
Qualified signature validationRecipients of signed documentsAutomatic and verifiable authenticity of qualified signaturesValidation result with the QTSP’s sealEADTrust validation service
Signature preservationLong-term custodiansValidity of the signature beyond the technological cyclePresumption maintained over time
Qualified electronic archivingAny operatorIntegrity and origin throughout the entire custody periodPresumption of integrity and origin during custodyeArchiving
Electronic attestations of attributesIssuing entities, usersVerifiability of personal and professional attributesLegal effect equivalent to a paper attestation when qualifiedUnder development (EUDI Wallet ready)


Frequently Asked Questions About Trust Services

What Is the Difference Between a Qualified and a Non-Qualified Trust Service?

A qualified service meets the requirements of the eIDAS Regulation, is provided by a QTSP included in the EU Trusted List and has an automatic legal presumption. A non-qualified service also has legal validity (the Regulation prohibits denying it legal effects merely because it is not qualified), but without an automatic presumption: whoever submits it must prove its authenticity if it is challenged.

Can Several Trust Services Be Combined in the Same Process?

Yes, and that is precisely what EAD Factory does. A signature process with Signature Manager combines an advanced signature, a qualified electronic timestamp and electronic archiving. A notification with Notice Manager combines registered delivery, a timestamp and a cryptographic hash. Law 6/2020 expressly recognises that these services can be combined to provide complex services.

Are the Trust Services of a Spanish QTSP Valid in Germany or France?

Yes. Article 3 of the eIDAS Regulation establishes that qualified services based on certificates issued in one Member State are recognised as qualified in all other Member States. GoCertius, for example, has full legal effect throughout the European Union and the United Kingdom.

What Happens If the QTSP Ceases to Exist? Do the Documents It Certified Remain Valid?

Documents with a qualified electronic timestamp or archived through a qualified electronic archiving service remain valid regardless of whether the QTSP continues to operate: the timestamp is a cryptographic signature that can be independently verified using public domain tools. For archiving services, the obligation to ensure continuity and availability even after operations cease is established in the service terms themselves.

Does My Company Need All These Services?

Not necessarily all at the same time. The decision depends on each company’s critical processes: which ones require proof of intent (signature), which ones require proof that they originate from the company (seal), which ones require proof of a certain date (timestamp), which ones require proof that the communication was delivered (registered delivery) and which ones require preservation with a legal presumption (archiving). An assessment of the processes with the greatest legal exposure is the starting point for determining which services are a priority.

Digital trust services are the legal infrastructure of the digital world

Every contract your company signs without an advanced signature, every critical notification it sends by ordinary email, every document it stores on a server without qualified archiving is a latent legal risk. Not because the process is illegal (it is not), but because the moment someone challenges it, the burden of proving its authenticity will fall on your company.

Qualified digital trust services resolve that. They do not add bureaucracy: they add certainty. And certainty, in the world of legal relations, is worth money. At EADTrust, we are a qualified trust service provider included in the EU Trusted List. We offer advanced signatures, qualified electronic timestamps, electronic registered delivery and qualified electronic archiving, individually or integrated into your company’s processes through EAD Factory.

Fecha de publicación:

Última actualización:

10 de June de 2026

26 de August de 2026