What lies behind the “Sign” button: what eIDAS requirements really mean

For users, signing a document electronically seems simple: upload a document, choose a signing method, verify your identity and, a few moments later, receive the signed file. But for a business that integrates electronic signatures into its processes, it is not only the convenience of the “Sign” button that matters. Just as important is understanding what ensures that the entire service remains reliable, secure and available when it is needed.

Article by Justina Dešriūtė, Product Manager at Elpako.

This less visible side of electronic signatures was the focus of my presentation at ESET Security Day 2026, held at LITEXPO on 10 September 2026. This year’s event, themed “Move Smarter. Stay Secure.”, brought cybersecurity professionals together to discuss current security topics and practical challenges.

eIDAS defines qualified trust services, which may only be provided by qualified trust service providers (QTSPs). Achieving this status involves far more than obtaining a certificate or passing a one-off audit. Behind it are technologies, processes, responsibilities and continuous supervision – much of which remains invisible to the user clicking “Sign”.

When choosing an electronic signature solution, businesses should also consider this less visible side of the service. A convenient interface or quick integration is something we notice immediately, but long-term reliability also depends on who provides the individual components of the service, how they are managed and what requirements apply to the service provider.

How does a provider become qualified?

The need to become a qualified trust service provider arises when business processes involve important documents, higher levels of risk and the need to ensure a high level of security and reliability. In such cases, it is no longer enough for a provider simply to state that its service is secure and reliable – compliance has to be assessed independently.

This is where it becomes clear that existing ISO standards or other certifications are not sufficient. A dedicated eIDAS conformity assessment is required, and it can only be carried out by an accredited CAB (Conformity Assessment Body). There are currently no such bodies in Lithuania, Latvia or Estonia, which means auditors have to be engaged from other European countries. The assessment covers much more than the service itself: it includes company documentation and a wide range of internal processes, from employee onboarding and the systems in use to access management and physical infrastructure.

This is also where one important difference between eIDAS and more general security requirements becomes apparent. eIDAS includes detailed technical requirements that define not only how a service must be managed, but also the standards that the software and physical equipment used to provide it must meet. Simply declaring that a system is secure is therefore not enough – security must be reflected in the technical implementation of the service itself.

The journey from the first contact with auditors to obtaining qualified status can take between 6 and 18 months. And the process does not end once the audit has been completed successfully. The audit report is also reviewed by the Communications Regulatory Authority of Lithuania (RRT), which, if no non-compliance is identified, adds the specific service to the list of qualified trust services.

Qualification is a process, not a finish line

“The audit is dead – long live the audit” is quite a fitting description here. A full conformity assessment audit must take place no later than 24 months after the certificate is issued, while a surveillance assessment is typically carried out after around 12 months. In practice, however, monitoring is continuous. Teams change, suppliers change, tools change, security incidents occur – and every such development has to be assessed in the context of eIDAS requirements.

Qualified status is therefore not a diploma that allows the paperwork to be filed away once it has been obtained. More importantly, having QTSP status does not mean that every service offered by the provider automatically becomes qualified. eIDAS covers different categories of qualified services – from electronic signature certificates and timestamps to electronic archiving and other services introduced under eIDAS 2. Each has its own technical requirements and is assessed separately. It is therefore very rare for a single provider to be qualified for every type of service at the same time.

This distinction matters: QTSP status is not a general “trusted provider” label covering everything a company does. Qualification always applies to a specific service. This can be checked in practice through the EU Member States’ Trusted Lists, which show both the provider and the status of each specific qualified service it offers.

One electronic signature – an entire chain of services

To the user, an electronic signature may appear to be a single service. Technically, however, the electronic signing process consists of several interconnected elements: a certificate confirming a person’s identity; a timestamp recording when the signature was created; validation confirming that the signature was valid at the time of signing; and long-term preservation mechanisms that help retain this proof over time. More information about the individual components of electronic signature services is also available from the RRT’s electronic signature information.

A single provider will usually not deliver all of these components itself. Several different providers may participate in the service chain, and companies that compete in one area may become partners in another. Clients do not need to see this entire chain in their everyday use of the service – what matters to them is that the service works reliably. But our responsibility does not end when the “Sign” button is clicked.

It continues through periodic timestamp renewals, archiving strategies and preparation for the possibility that algorithms considered secure today may become vulnerable in the future. A problem with one link in the chain can affect the entire service, which means we must be prepared for both technological and market changes and have alternatives available for individual components.

What does “trust” really mean?

The word Trust in the QTSP acronym may sound abstract, but in practice trust becomes very tangible. It is not simply one relationship between the service provider and the client. There are several relationships involved, and each of them matters in its own way to the electronic signature infrastructure as a whole.

First, there is trust between the individual and the service provider. Users need to know that their electronic signature will work when they need it and that its legal validity and reliability will not be called into question. Even a minor technical issue experienced by the user can undermine confidence in the entire service, because an error appearing in our system will naturally be perceived as the provider’s problem. In an RRT survey, respondents also identified a lack of information about electronic signatures as one of the barriers to using them.

Another relationship exists between the service provider and the RRT. This communication is not limited to the certification process. The RRT provides information about changes to the infrastructure, clients may contact the authority regarding how a service operates, and the authority itself may alert a provider to problems observed in a client’s system. There is therefore an ongoing exchange of information between the supervisory authority, service providers and clients.

Trust between other QTSPs operating in the market is equally important. Qualified European providers are included in national Trusted Lists, while the European Commission publishes the LOTL (List of Trusted Lists), which brings together the national trusted lists. In Lithuania’s list, Elpako is listed under UAB NEVDA, the company that provides the Elpako service. If the status of one provider involved in our service chain changes, or if that provider ceases operations, other participants in the same chain may be affected directly.

Finally, there are the third parties involved in the supply chain – cloud service providers, data centres, network infrastructure providers and suppliers of physical equipment. Outsourcing part of the service does not mean outsourcing our responsibility along with it. Even when third parties are involved, we still need to assess their risks, monitor them and define specific security obligations in our contracts.

All of these relationships are connected by one principle: trust is not a one-off achievement granted together with a certificate.

A QTSP is more than a technology provider

Another side of QTSP work becomes visible when a client’s needs go beyond technology alone. For example, a client may have a company branch in Latvia and want to use QSeal so that documents can be signed on behalf of the company there in the same way as in Lithuania. In such a case, providing a technically functioning service is not enough. We also need to understand Latvia’s regulatory infrastructure, work with a provider operating there and ensure that the entire service chain on both sides meets QTSP requirements.

At that point, the work becomes much more than an IT project. In practice, QTSPs also have to deal with questions of business logic, legal requirements and organisational processes, particularly when a service needs to operate across several countries and different regulatory environments.

These requirements also extend into our own organisation. Employee selection becomes more stringent, training is required before access to systems is granted, we need to continuously ensure that only authorised individuals can access certain parts of the infrastructure, and working system backups must be maintained. Ultimately, a QTSP must be able to demonstrate at any time that people, processes and technology together form a reliable system that operates 24/7.

We take eIDAS seriously

Most of this work will never be visible to the person clicking “Sign”. Behind that action are audits, technical requirements, supplier management, supervisory authorities, internal processes and continuous responsibility for the entire service chain.

That is why eIDAS requirements play an important role in how we build and develop Elpako. They influence not only technical decisions, but also our processes, our choice of partners and the time required to develop the service. Qualified status is not a one-time milestone in the product development journey. It requires continuous compliance monitoring and the ability to adapt as technology, markets and regulation evolve.

For the user, however, all of this ultimately needs to come down to one simple action – “Sign”.


If you are considering how an electronic signing solution could work within your organisation’s processes, feel free to contact me. We can discuss your situation, the requirements imposed by eIDAS and how we address them at Elpako.

Justina Dešriūtė, Product Manager at Elpako
[email protected]