A CA verifies identity and issues digital certificates. Responsible for identity proofing, certificate issuance, key management, and revocation handling.
The trust-service ecosystem
Digital signatures rely on a layered ecosystem of trusted organisations. Certificate Authorities (CAs) issue certificates. Trust Service Providers (TSPs) offer signature-related services. Qualified TSPs (QTSPs) are accredited to issue qualified certificates that carry the highest legal weight under eIDAS.
CA vs TSP vs QTSP
| Role | Key function | |
|---|---|---|
| CA | Issues digital certificates | Identity verification and certificate lifecycle |
| TSP | Provides trust services | Signatures, timestamps, seals, registered delivery |
| QTSP | Qualified TSP (accredited) | Same as TSP plus qualified certificates with legal presumption |
What each role does in practice
The roles often overlap — a single organisation may be a CA, TSP, and QTSP.
A TSP provides electronic trust services: signature creation, validation, timestamping, registered delivery, and certificate management. Many CAs are also TSPs.
A QTSP is a TSP accredited by a national supervisory body under eIDAS. Only QTSPs can issue qualified certificates that enable QES and QSeal with legal presumption.
Examples across jurisdictions
Different countries have different trust service ecosystems.
EU trust list
The European Commission maintains the EU Trusted List — a public registry of all accredited QTSPs in member states. Check this list to verify whether a TSP is qualified under eIDAS.
China CA system
China's CA system is regulated by MIIT and SCA. Licensed CAs include eSign, BJCA, and others. Under T/CQAE 11034-2025, CAs must directly handle identity verification and key management.
Singapore IMDA
IMDA accredits CAs under the ETA. Netrust is a prominent licensed CA. IMDA oversees the trust framework for digital signatures in Singapore.
Cross-border recognition
eIDAS allows EU member states to recognise QTSPs from third countries if they meet equivalent standards. Most APAC CAs are not eIDAS-accredited.
Trust service provider selection: EU Trusted List and APAC equivalents
Practical data for evaluating and selecting TSPs.
EU Trusted List statistics (2026)
The EU Trusted Lists are the authoritative source for checking whether a provider and a specific trust service hold qualified status. Counts change as services are added, suspended, withdrawn, or renewed, so procurement teams should verify the live list rather than rely on a static total.
APAC TSP equivalents
APAC markets use their own legal and supervisory models. Singapore maintains a voluntary accreditation framework for certification authorities under the ETA; Hong Kong recognises certification authorities and certificates under the ETO; Malaysia licenses certification authorities under the Digital Signature Act; China regulates electronic certification services and commercial cryptography; and Indonesia maintains a registered PSrE framework. These local statuses are not the same as qualified status under eIDAS and must be checked with the relevant regulator.
Common questions
A TSP provides services related to electronic signatures and trust — certificate issuance, timestamping, signature validation, and registered delivery. Under eIDAS, TSPs can be qualified (accredited) or non-qualified.
How eSign.AI applies this in practice
eSign.AI supports certificate-backed digital-signature workflows and confirmed local integrations including Singpass in Singapore, iAM Smart in Hong Kong, Trustgate in Malaysia, VNPT in Vietnam, and Vinotek in Indonesia. Each integration must still be described using the local legal framework and certificate status; APAC recognition is not eIDAS-qualified status.







