Certification of the eIDAS conformity of QSCD (2024)

Do you have any questions or comments? Contact us!

Contact us now!

+49 201 8999-642 Mail Request an offer

  • Introduction
  • Our services
  • Standards we use to audit
  • Your benefits
  • All about trust services
  • What are QSCDs?
  • Why TÜVIT?
  • Contact us

With TÜVIT to the Qualified Signature and Seal Creation Device

Qualified electronic signature and seal creation devices (QSCDs) must satisfy the requirements of the eIDAS Regulation (Annex II) and be certified in accordance with it. Testing and certification is carried out according to an approved safety assessment procedure by an independent body notified by member states of the EU Commission. Certification by an independent and notified body is a prerequisite for the inclusion of the QSCD in the EU list of certified QSCDs.

As an accredited testing and certification body for Common Criteria and a notified certification body for QSCDs, we support you from the planning process, through assessment and certification to the final step in the publication of your QSCD by the European Commission. Depending on the QSCD type, the assessment is carried out according to Common Criteria or is based on a certification process with an equivalent level of security specifically developed by TÜVIT for this purpose.

We also offer you customized workshops in order to best prepare you for any upcoming certification or, within the framework of our eIDAS.PROFESSIONAL training, turn you into an expert on eIDAS and ETSI matters.

Our services in the field of qualified signature creation devices (QSCD)

Introduction to the world of eIDAS, relevant CEN and ETSI standards, as well as Common Criteria (CC) and CC protection profiles in the form of training sessions

Certification of the eIDAS conformity of QSCD (6)Certification of the eIDAS conformity of QSCD (7)Certification of the eIDAS conformity of QSCD (8)Certification of the eIDAS conformity of QSCD (9)

Project-specific workshops as preparation for certification

Certification of the eIDAS conformity of QSCD (14)Certification of the eIDAS conformity of QSCD (15)Certification of the eIDAS conformity of QSCD (16)Certification of the eIDAS conformity of QSCD (17)

Review & certification of QSCDs according to approved safety assessment procedures, in particular CC & relevant protection profiles of CEN

Standards we use to audit

Certification of the eIDAS conformity of QSCD (18)Certification of the eIDAS conformity of QSCD (19)Certification of the eIDAS conformity of QSCD (20)Certification of the eIDAS conformity of QSCD (21)

CID (EU) 2016/650

Standards for the security assessment of qualified signature and seal creation devices pursuant to Articles 30(3) and 39(2) of eIDAS Regulation

Certification of the eIDAS conformity of QSCD (22)Certification of the eIDAS conformity of QSCD (23)Certification of the eIDAS conformity of QSCD (24)Certification of the eIDAS conformity of QSCD (25)

eIDAS Regulation

Article 30: Certification of qualified electronic signature creation devices

Article 39: Qualified electronic seal creation devices

Certification of the eIDAS conformity of QSCD (26)Certification of the eIDAS conformity of QSCD (27)Certification of the eIDAS conformity of QSCD (28)Certification of the eIDAS conformity of QSCD (29)

Notifications of member states about designated bodies, certified qualified electronic signature and seal creation devices according to eIDAS Regulation

Certification of the eIDAS conformity of QSCD (30)Certification of the eIDAS conformity of QSCD (31)Certification of the eIDAS conformity of QSCD (32)Certification of the eIDAS conformity of QSCD (33)

ISO/IEC 15408-1
(Common Criteria)

Information technology – Security techniques – Evaluation criteria for IT security – Part 1:Introduction and general model

Certification of the eIDAS conformity of QSCD (34)Certification of the eIDAS conformity of QSCD (35)Certification of the eIDAS conformity of QSCD (36)Certification of the eIDAS conformity of QSCD (37)

ISO/IEC 15408-2
(Common Criteria)

Information technology – Security techniques – Evaluation criteria for IT security – Part 2:Security functional requirements

Certification of the eIDAS conformity of QSCD (38)Certification of the eIDAS conformity of QSCD (39)Certification of the eIDAS conformity of QSCD (40)Certification of the eIDAS conformity of QSCD (41)

ISO/IEC 15408-3
(Common Criteria)

Information technology – Security techniques – Evaluation criteria for IT security – Part 3:Security assurance requirements

Certification of the eIDAS conformity of QSCD (42)Certification of the eIDAS conformity of QSCD (43)Certification of the eIDAS conformity of QSCD (44)Certification of the eIDAS conformity of QSCD (45)

EN 419 221-5
(Common Criteria Protection Profilefor Cryptographic Modules)

CEN/EN 419 221-5:2018, Protection profiles for TSP Cryptographic modules - Part 5: Cryptographic Module for Trust Services

Certification of the eIDAS conformity of QSCD (46)Certification of the eIDAS conformity of QSCD (47)Certification of the eIDAS conformity of QSCD (48)Certification of the eIDAS conformity of QSCD (49)

EN 419 241-2
(Common Criteria Protection Profile for QSCD for Server Signing)

CEN/EN 419 241-2:2019, Trustworthy Systems Supporting Server Signing - Part 2: Protection Profile for QSCD for Server Signing

Your benefits at a glance

  • European recognition: The certificate of your QSCD will be included in the official QSCD list of the EU Commission and published on our website.
  • Objective verification of trusted status:You can provide objective evidence of the IT security of your QSCD to customers and trust service providers.
  • Entry into the European market:Successful certification of your QSCD will enable you to access the European Single Market.
  • Efficient certification process: Our security assessment process, which has been approved for QSCDs for server signatures, and support for the creation of Common Criteria-compliant documents saves you time and effort in the certification process.

All about trust services

Certification of the eIDAS conformity of QSCD (50)Certification of the eIDAS conformity of QSCD (51)Certification of the eIDAS conformity of QSCD (52)Certification of the eIDAS conformity of QSCD (53)

Events

  • eIDAS.PROFESSIONAL-Training

Certification of the eIDAS conformity of QSCD (54)Certification of the eIDAS conformity of QSCD (55)Certification of the eIDAS conformity of QSCD (56)Certification of the eIDAS conformity of QSCD (57)

Downloads

Certification Process for eIDAS conformant QSCDs of the certification body of TÜV Informationstechnik GmbH V. 1.2​​​​​​​

Certification of the eIDAS conformity of QSCD (58)Certification of the eIDAS conformity of QSCD (59)Certification of the eIDAS conformity of QSCD (60)Certification of the eIDAS conformity of QSCD (61)

News

  • REMOTE instead of ON-SITE: Possibilities of auditing in times of Corona
  • Customer information: Dealing with the Corona virus
  • TÜVITspecifies cybersecurity architecture for On-board Telematics Platform (OTP)

What are qualified electronic signature and seal creation devices?

A qualified signature or seal creation device (QSCD) is a particular combination of hardware and software that securely administers cryptographic keys and with the help of which qualified electronic signatures/seals (QES) can be created. QSCDs based on crypto modules are used specifically for server signatures. Here, the QSCD makes use of various technical procedures and means in order to ensure, among other things, that signature keys remain confidential and are generated by means of established cryptographic procedures.

In order to be officially classified as a QSCD, a QSCD must satisfy the requirements of Annex II of Regulation (EU) No. 910/2014 (eIDAS). Article 1 [CID (EU) 2016/650] makes a distinction between two types of QSCD:

  1. QSCDs where the electronic signature or seal creation data are located entirely, but not necessarily exclusively, in the user’s environment. Here, the certification is based on Common Criteria protection profiles.
  2. QSCDs where a qualified Trust Service Provider administers the electronic signature or seal creation data on behalf of a signatory or seal creator (remote QSCD or server signature QSCD). As there are no applicable standards for the assessment of remote QSCDs, approved certification procedures with a level of security that is equivalent to Common Criteria certification can be used.

Why we are a strong partner for you

Certification of the eIDAS conformity of QSCD (62)

Expertise

Our experienced experts have already successfully completed more than 500 PKI projects of various sizes, some of which were transnational.

Certification of the eIDAS conformity of QSCD (63)

Industry experience

Due to many years of experience in different branches of industry we can serve companies from a wide range of industries.

Certification of the eIDAS conformity of QSCD (64)

Everything from a single source

We offer an all-round eIDAS package: From training and workshops, planning support and audits all the way to conformity assessment (certification).

Certification of the eIDAS conformity of QSCD (65)

Tailor-made for you

We focus on individual services - and solutions - that optimally fit your current company situation and your set goals.

Certification of the eIDAS conformity of QSCD (66)

International network of experts

Around the globe: We support you both nationally and internationally. Our global network of experts is ready to help you in word and deed in all IT security issues.

Certification of the eIDAS conformity of QSCD (67)

Independence

Our employees are not subject to any conflicts of interest, as they are not committed to any product suppliers, system integrators, stakeholders, interest groups or government agencies.

You have questions? We are pleased to help!

Contact Send mail

Joshua RumiAccount Manager Trust Services
IT Infrastructure

Tel.: +49 201 8999-642
j.rumi@tuvit.de

Contact Send mail

Matthias WiedenhorstHead of Certification Division Trust Service Provider

Tel.: +49 201 8999-536
Fax: +49 201 8999-555
m.wiedenhorst@tuvit.de

Further services

Electronic SignaturesWe accompany trust service providers for electronic signatures on the way to their qualification status: from the planning of their services to the required tests up to the conformity assessment / re-certification. Read more
Website AuthenticationServers and websites available on the internet must be clearly attributed to their operators if users are to trust them. The secure identification of websites and server systems on the internet takes place using electronic certificates.Read more
Validation Services for Electronic Signatures, Seals and TimestampsValidation services are indispensable for assessing the correctness and integrity of electronically signed, sealed and timestamped documents. They review certificates in real time and ensure transparency.Read more
Electronic Archives and Archiving ServicesDocuments that are electronically signed or marked with a timestamp are subject to ageing, just like their hard copy counterparts. If the certificates or mathematical algorithms used there are no longer up to date, this results in them losing their value as evidence.Read more
Electronic Identification (eID)Electronic identification systems have the great advantage that they save companies time and expense, and significantly simplify communication for customers – provided that the systems work securely and that they are trustworthy.Read more
Electronic Registered Delivery ServicesElectronic registered delivery services transmit electronic data such as emails between third parties and provide evidence relating to sending and receiving the transmitted data at a certain date and time. Read more
Cooperative Intelligent Transport Systems (C-ITS)We support you on your way to an IT-secure C-ITS solution: from planning or further development, through testing, to successful certification according to the security requirements of the European Commission.Read more
Certification of the eIDAS conformity of QSCD (2024)
Top Articles
Latest Posts
Article information

Author: Rev. Porsche Oberbrunner

Last Updated:

Views: 6596

Rating: 4.2 / 5 (53 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Rev. Porsche Oberbrunner

Birthday: 1994-06-25

Address: Suite 153 582 Lubowitz Walks, Port Alfredoborough, IN 72879-2838

Phone: +128413562823324

Job: IT Strategist

Hobby: Video gaming, Basketball, Web surfing, Book restoration, Jogging, Shooting, Fishing

Introduction: My name is Rev. Porsche Oberbrunner, I am a zany, graceful, talented, witty, determined, shiny, enchanting person who loves writing and wants to share my knowledge and understanding with you.