ZealiD Blog

How Qualified E Signatures Support eIDAS Compliance

Written by Tomas Zuoza | Oct 07, 2026

Your firm signs documents every week. Employment contracts, engagement letters, board resolutions, NDAs. The question is whether those signatures would hold up if a regulator, a court, or a counterparty challenged them. Under the eIDAS Regulation (Regulation (EU) No 910/2014), only one signature type carries the same legal weight as a handwritten signature across all 27 EU member states: the qualified electronic signature.

This article explains what makes a signature "qualified" under eIDAS, how EU Trusted Lists work, and what professional services firms need to verify before relying on any provider. ZealiD, a Qualified Trust Service Provider listed on the EU Trusted List under Sweden, issues qualified electronic signatures after remote identity verification with no video call required.

Key Takeaways: Qualified Electronic Signatures and eIDAS

  • A qualified electronic signature is the only e-signature type with the legal equivalence of a handwritten signature under eIDAS Article 25(2).
  • The provider must appear on a national EU Trusted List for the signature to count as qualified.
  • Trust list verification is a concrete step you can perform yourself using the European Commission's browser.
  • ZealiD meets eIDAS requirements for qualified signatures, certified under ETSI EN 319 411-2 and ETSI TS 119 461.
  • Professional services firms should confirm trust service provider status before embedding any signing tool into client workflows.

What Is a Qualified Electronic Signature Under eIDAS?

The eIDAS Regulation defines three tiers of electronic signature: simple, advanced, and qualified. A simple electronic signature can be as basic as a typed name in a contract. An advanced electronic signature is uniquely linked to the signatory and created using data under the signatory's sole control.

A qualified electronic signature goes further. It is an advanced electronic signature created by a qualified electronic signature creation device and based on a qualified certificate for electronic signatures. Under eIDAS Article 25(2), a qualified electronic signature has the equivalent legal effect of a handwritten signature.

For professional services firms, this distinction matters in practice. A contract signed with a simple or advanced signature may be challenged on evidentiary grounds. A qualified electronic signature carries a legal presumption of validity that shifts the burden of proof to the party contesting it.

Why the EU Trusted List Is the Only Proof That Matters

A provider can claim eIDAS compliance on its website. That claim is not the same as appearing on a national EU Trusted List. Under eIDAS Article 22, each EU member state must establish, maintain, and publish a trusted list of qualified trust service providers and the qualified services they offer.

The trusted list has what the regulation calls "constitutive effect." A provider and its services are qualified only if they appear on a trusted list. In the Commission's words: "users, including citizens, businesses and public administrations, will benefit from the legal effect associated with a given qualified trust service only if the latter is listed as qualified in the trusted lists."

If your firm relies on a signing provider that does not appear on a trusted list, the signatures it produces do not carry the legal presumption of a qualified electronic signature, regardless of what the provider's website says.

How to Verify a Trust Service Provider on the EU Trusted List

The European Commission publishes a Trusted List browser where you can search by country and by service type. To verify a provider, select the member state, filter for "qualified" status, and look for the provider by name. The listing will show the specific services that are qualified.

ZealiD appears on the Swedish trusted list (country code SE), supervised by PTS, the Swedish Post and Telecom Authority. The ZealiD entry covers qualified certificates for electronic signatures and the qualified registration service under eIDAS Article 24(1)(c). You can verify this directly in the Trusted List browser.

This step takes two minutes and removes the guesswork. If you are evaluating a signing provider for client-facing workflows, checking the trusted list should be the first thing you do.

What Makes a Signature Creation Device "Qualified"?

A qualified electronic signature requires a qualified electronic signature creation device (QSCD). The device is the hardware or software environment that generates and protects the cryptographic key used to sign. Under eIDAS, a QSCD must meet the requirements set out in Annex II of the regulation and be certified accordingly.

In practice, most qualified trust service providers now offer remote QSCDs. The signing key stays in a certified hardware security module (HSM) operated by the provider, and the signatory authorises each signature through a secure channel, typically a mobile app with biometric authentication.

ZealiD uses a Common Criteria EAL4+ certified HSM that meets EN 419 221-5. The signatory's key is generated and stored inside the HSM. Each signing event requires biometric authentication through the ZealiD app, which acts as the sole control mechanism for the signatory.

The Role of Identity Verification in Qualified Signatures

A qualified certificate can only be issued after the trust service provider verifies the identity of the person requesting it. eIDAS Article 24(1) defines how this verification must happen. One permitted path, Article 24(1)(d) as extended by national schemes, allows certified remote identification.

ZealiD's remote identity verification process is certified under ETSI TS 119 461, the European standard for identity proofing of trust service subjects. The process involves a liveness detection selfie and a document scan, covering 150+ document types and 50+ nationalities. Verification is valid for two years and reusable across multiple signing events.

For firms onboarding clients or counterparties who need to sign qualified documents, this means the identity check happens once, at registration, and the verified identity is then available for subsequent signatures without repeating the process.

Where Professional Services Firms Encounter eIDAS Requirements

If your firm operates across EU borders, you encounter eIDAS requirements more often than you might expect. Public procurement tenders in many member states require qualified electronic signatures. The EU Public Procurement Directives reference electronic submission, and national implementations increasingly mandate QES for tender responses.

Cross-border contract execution is another trigger. A qualified electronic signature created in Sweden is recognised in Germany, France, or any other member state. The mutual recognition built into eIDAS removes the need for additional validation.

Anti-money laundering obligations add a third layer. Under the incoming AMLR (applying from 10 July 2027), firms subject to AML requirements will face tighter identity verification standards. According to ENISA's 2024 annual report on trust services security incidents, supervisory attention on qualified trust service providers is increasing across the EU.

A qualified trust service provider's certified identity proofing process can serve as part of your firm's KYC evidence chain.

What to Check Before Choosing a Signing Provider

Not every platform that offers e-signatures provides qualified electronic signatures. Many offer simple or advanced signatures, which do not carry the same legal standing under eIDAS. Before embedding a signing tool into your workflows, confirm the following.

First, check whether the provider appears on a national EU Trusted List for qualified electronic signatures, not just for another service type. Second, ask for the conformity assessment report or the name of the conformity assessment body. Under eIDAS, qualified trust service providers must be assessed by an accredited conformity assessment body at least every 24 months.

Third, verify how identity proofing is performed and which standard the registration process is certified under. ETSI TS 119 461 is the relevant standard for remote identity proofing. Fourth, confirm the QSCD certification. A certified HSM at EAL4+ or above, meeting EN 419 221-5, is the current benchmark.

How ZealiD Supports eIDAS-Compliant Signing for Professional Services

ZealiD is listed on the EU Trusted List under Sweden and holds conformity assessments from SRC Security Research & Consulting GmbH. The standards met include ETSI EN 319 401, ETSI EN 319 411-1, ETSI EN 319 411-2, and ETSI TS 119 461.

Professional services firms can use ZealiD's qualified electronic signatures through partner integrations with platforms such as Adobe Acrobat Sign and Foxit, or directly through API integration. The Trust Circle product provides a secure, identity-verified workspace for document collection and signing, built for firms that handle sensitive client materials.

According to a published case study, DLA Piper uses ZealiD qualified signatures through its signing platform integration, reporting a cost of approximately €20 per signature.

FAQs About Qualified Electronic Signatures and eIDAS Compliance

What is the difference between an advanced and a qualified electronic signature?

An advanced electronic signature is uniquely linked to the signatory and created under the signatory's sole control. A qualified electronic signature adds two requirements: a qualified certificate issued by a trust service provider on the EU Trusted List, and a certified qualified electronic signature creation device. Only the qualified type carries the legal equivalence of a handwritten signature under eIDAS.

How do I check whether a provider is on the EU Trusted List?

The European Commission publishes a Trusted List browser at eidas.ec.europa.eu. Select the country, filter for qualified status, and search for the provider. ZealiD appears on the Swedish trusted list, supervised by PTS, with qualified status for electronic signature certificates and remote registration.

Can a qualified electronic signature be used across EU member states?

Yes. Under eIDAS Article 25(3), a qualified electronic signature based on a qualified certificate issued in one member state is recognised as such in all other member states. ZealiD's qualified signatures, issued under the Swedish trusted list, carry full legal weight across the EU.

Does ZealiD require a video call for identity verification?

No. ZealiD verifies identity remotely using a certified process under ETSI TS 119 461. The registration involves a liveness detection selfie and a document scan. The process is completed through the ZealiD app, and the verified identity is reusable for two years.

What standards should a qualified trust service provider meet?

At minimum, look for conformity with ETSI EN 319 401 (general policy requirements), ETSI EN 319 411-2 (qualified certificate policy), and ETSI TS 119 461 (identity proofing). The provider should also use a QSCD certified at Common Criteria EAL4+ or above. ZealiD meets all of these, with an annual assessment by an accredited conformity assessment body.