A sovereign qualified electronic signature (QES) combines a legally binding cryptographic proof of authorship with an infrastructure that remains entirely under the jurisdiction of the organisation and its member state, from the certificate authority and Hardware Security Module (HSM) through the time-stamping authority (TSA) to the archival layer. For documents that must remain legally enforceable over decades, that sovereignty is not optional: it determines whether a signature can be verified, enforced, and defended in court long after the underlying algorithms have aged.
What eIDAS 2.0 demands from QTSPs and why foreign providers create exposure
Regulation (EU) 2024/1183 (eIDAS 2.0) raises the bar for qualified trust service providers on several fronts that directly affect organisations relying on signing services provided from outside the EU.
Under eIDAS 2.0, a qualified signature must be created using a Qualified Signature Creation Device (QSCD) certified against Common Criteria EAL 4+ or equivalent, with the private key generated and stored exclusively within that device. QTSPs must maintain complete, tamper-evident audit logs of every signing event and must submit to conformity assessment by an accredited body. The QTSP must appear on the national Trusted List of an EU member state.
The problem with non-EU providers, including US-headquartered cloud signing services that operate EU data centres, is structural rather than operational. The US CLOUD Act (18 U.S.C. § 2713) gives US authorities the power to compel a US-controlled entity to produce stored data or communications regardless of where those data are physically held. FISA Section 702 allows warrantless collection of communications involving non-US persons where the provider is a US electronic communications service. A QTSP that is ultimately owned by or legally subject to a US parent cannot guarantee that signing keys, signing event logs, or the identity records of signatories are beyond foreign reach. eIDAS 2.0 does not directly address this gap, which means the compliance burden falls on the data controller to conduct a Transfer Impact Assessment and accept the residual risk, or to migrate to a genuinely sovereign QTSP.
Long-term signature formats and the infrastructure behind them
ETSI EN 319 132 (XAdES), EN 319 122 (CAdES), and EN 319 142 (PAdES) each define a hierarchy of signature profiles that culminates in the LTA (Long-Term Archive) variant. The LTA profile solves the problem of algorithm ageing: it embeds not just the signature and the signer’s certificate chain, but also a periodic archive time-stamp that re-anchors the cryptographic proof to a fresh TSA hash before any component algorithm is deprecated. As long as the archive time-stamp chain is renewed on schedule, the original document remains verifiable even if the original signing algorithm (for example RSA-2048) is later broken.
Operating a compliant TSA requires more than running an RFC 3161 service. ETSI EN 319 421 defines the policy and security requirements for a trusted time-stamp authority, including physical security for the TSA signing key (which must itself reside in a certified HSM), key ceremony procedures, audit logging, and regular conformity assessment. For sovereign operations, this means either establishing an in-house TSA under EN 319 421 or contracting with a QTSP whose TSA is on the national Trusted List and whose legal seat is within EU jurisdiction.
The quantum threat to archived signatures and the ENISA migration roadmap
Classical RSA and ECDSA signatures on legal and regulatory documents are vulnerable to Shor’s algorithm, which a sufficiently powerful quantum computer could run to reconstruct private keys from public keys. A document signed today with RSA-4096 or ECDSA-P384 and stored for 30 years may be retroactively forgeable once a cryptographically relevant quantum computer (CRQC) exists.
According to ENISA’s analysis, a CRQC is plausible within 10 to 15 years. For documents that must remain enforceable beyond that window, the risk is not theoretical. The ENISA EU PQC Transition Roadmap 2026-2030 recommends that critical infrastructure and regulated sectors begin algorithm migration no later than 2026, with hybrid signing (combining a classical algorithm with a post-quantum algorithm in a single document) as an interim measure and full PQC-only signing as the target state by 2030.
NIST FIPS 205, published in 2024, standardises SPHINCS+ under the name SLH-DSA (Stateless Hash-Based Digital Signature Algorithm). SLH-DSA is conservative: it relies exclusively on the security of hash functions, which are not broken by Shor’s algorithm, and it has a long academic track record. ML-DSA (Module Lattice Digital Signature Algorithm, standardised as NIST FIPS 204) offers smaller signatures and faster verification, making it suitable for high-volume operational signing. For archival purposes, where signature size matters less than long-term security assurance, ENISA guidance leans toward SLH-DSA or hybrid schemes combining ML-DSA with a classical algorithm.
| Algorithm | Standard | Quantum resistance | Recommended use in archival context |
|---|---|---|---|
| RSA-4096 | PKCS#1 | None against Shor’s algorithm | Deprecated for new archival signatures; renew with LTA time-stamp before 2030 |
| ECDSA-P384 | ANSI X9.62 | None against Shor’s algorithm | Same as RSA: phase out for new long-lived documents |
| ML-DSA (Dilithium) | NIST FIPS 204 | High (lattice-based) | Operational signing; suitable for hybrid schemes with ECDSA |
| SLH-DSA (SPHINCS+) | NIST FIPS 205 | High (hash-based) | Primary recommendation for long-term archival signing under ENISA roadmap |
Designing sovereign signing infrastructure under eIDAS 2.0 and FADP
A complete sovereign signing stack covers four layers: certificate issuance, private key storage, time-stamping, and archival format management. Each layer must be assessed for both EU and Swiss jurisdiction if the organisation operates across both frameworks. Switzerland’s revised Federal Act on Data Protection (FADP), which entered force in September 2023, aligns with GDPR’s adequacy standard, and the Federal Data Protection and Information Commissioner (FDPIC) has stated that the revised FADP places Switzerland in a position offering a high level of protection comparable to the EU. That alignment means Swiss hosting can satisfy GDPR adequacy conditions, but only if the provider is not subject to extraterritorial foreign law.
For certificate issuance, the organisation must either operate a sub-CA under an EU member state root CA listed on the Trusted List, or contract with an EU-jurisdictional QTSP. The root of trust must not be hosted on infrastructure controlled by a US cloud hyperscaler. Private keys for both signing certificates and the TSA must reside in HSMs certified to FIPS 140-3 Level 3 or Common Criteria EAL 4+. The HSMs must be physically located within the EU or Switzerland, and access must be governed by a key ceremony policy documented under EN 319 421.
The TSA must operate under ETSI EN 319 421, with its own QSCD, and must be synchronised to a trusted time source (UTC traceability via GPS or national time services). Audit logs from the TSA must be retained in a tamper-evident store that is itself jurisdiction-controlled. This is the layer most often outsourced carelessly: organisations that delegate TSA to a US cloud-hosted service expose their entire archival signature chain to foreign jurisdiction.
Tensions between long-term signature validity and GDPR, NIS-2, and sector retention rules
Three legal regimes create contradictory pressures on the archival signature infrastructure.
GDPR Article 17 (right to erasure) requires that personal data be deleted when the legal basis for processing expires. But a qualified signature is, by design, a permanent cryptographic binding of a person’s identity to a document. Erasing the certificate or its subject attributes can invalidate the signature and destroy the document’s legal standing. The reconciliation is technical: the LTA-format signature can be de-identified at the certificate attribute level by replacing identifying fields with pseudonymous references, provided the pseudonymisation is documented and a separate record links the pseudonym to the identity for authorised legal disclosure only.
NIS-2 (Directive EU 2022/2555) requires incident reports within 24 hours of a significant event and a full report within 72 hours. Signing infrastructure, which is critical to the legal operation of regulated entities, qualifies as an essential service component. Incident logs from the signing and TSA systems must therefore be retained in a form that supports post-incident forensic reconstruction, which means they must themselves be time-stamped and tamper-evident. That forensic archive must coexist with GDPR erasure obligations, typically by scope-separating the personal data elements from the event metadata.
Sector-specific retention rules add further complexity. Healthcare records in many EU member states carry 30-year retention obligations. Financial instruments under MiFID II require five to seven years. Legal contracts under national civil codes may require 10 to 30 years. All of these exceed the operational lifetime of current signing algorithms, making the LTA renewal cycle under EN 319 132/122/142 not merely good practice but a legal necessity.
The EUDI Wallet and the displacement of foreign identity providers
eIDAS 2.0 Article 5a mandates that member states offer every citizen a European Digital Identity (EUDI) Wallet by 2026. The wallet will carry verified identity attributes issued by notified eID schemes and will support the authentication of signatories to qualified signing workflows. For organisations that currently depend on US-headquartered identity providers (Microsoft Azure AD, Google Identity, or Okta) to authenticate signatories, the EUDI Wallet offers a migration path that keeps the authentication event within EU jurisdiction.
The practical implication is significant: when a user authenticates to a signing service using a foreign identity provider, the authentication event, including timestamp, IP address, and device fingerprint, may be logged by that provider under its own privacy policy and potentially accessible under US law. Replacing that with a EUDI Wallet assertion removes the foreign intermediary from the authentication chain entirely. The wallet communicates directly with the relying party using selective disclosure, meaning the signing service receives only the attributes it needs (for example, a verified legal name and date of birth) without creating a profile at the identity provider.
Organisations integrating EUDI Wallet authentication into their sovereign signing infrastructure should map the wallet’s OpenID4VP (OpenID for Verifiable Presentations) protocol to their existing signing gateway and verify that the relying party registration is managed under EU legal entities. This closes the last jurisdictional gap in a fully sovereign QES workflow.
FAQ
Does a qualified electronic signature from a non-EU QTSP remain legally valid under eIDAS 2.0?
A signature from a QTSP on the EU Trusted List remains technically valid, but if that QTSP is incorporated in or controlled from a jurisdiction subject to US extraterritorial law (CLOUD Act, FISA 702), signing keys and audit logs may be compelled without notice. eIDAS 2.0 does not currently bar non-EU QTSPs, but organisations handling sensitive or legally privileged documents should conduct a Transfer Impact Assessment and consider the residual jurisdictional risk.
What is the minimum archival signature format for documents that must be verifiable in 30 years?
ETSI EN 319 132 (XAdES-LTA), EN 319 122 (CAdES-LTA) and EN 319 142 (PAdES-LTA) all define a Long-Term Archive profile that embeds periodic archive time-stamps from an accredited TSA. This allows the cryptographic chain to be renewed before any underlying algorithm is deprecated, preserving legal validity without re-signing the original content.
When should organisations begin migrating archived document signatures to post-quantum algorithms?
The ENISA EU PQC Transition Roadmap sets 2026 to 2030 as the migration window for critical sectors. Because documents signed today with RSA or ECDSA will still exist when quantum computers become viable, ENISA recommends adding PQC counter-signatures or dual-algorithm archive time-stamps to high-value archives now, before algorithm deprecation is formally mandated.
How does the EUDI Wallet change how organisations authenticate signatories for qualified signatures?
Under eIDAS 2.0 and the EUDI Wallet framework, member states must provide citizens with a wallet that can assert verified identity attributes. Organisations that rely on foreign identity providers to authenticate signatories can replace that dependency with EUDI Wallet assertions, keeping the identity chain within EU jurisdiction and removing foreign intermediaries from the signing event log.
How does GDPR Article 17 interact with qualified signature archives?
Erasing the certificate subject attributes that bind a person’s identity to a signature can invalidate the document’s legal standing. The practical resolution is to pseudonymise identifying certificate fields within the archival record and maintain a separately controlled linkage table under strict access controls, so that the erasure obligation and the document’s legal enforceability can be managed independently without destroying either.
