eSign.AIeSign.AI

Glossary

What Is the EU Trusted List (EUTL)?

The EU Trusted List is the official machine-readable register of qualified trust service providers in Europe. Here is how it works, why Acrobat and e-signature platforms consume it, and how to check a provider against it.

eSign.AI Digital Trust Research Team6 min read

Europe's master register of trust

When a PDF shows a green checkmark in Adobe Acrobat declaring a signature 'valid and trusted', Acrobat is not guessing. It checked the signer's certificate against a chain of trust that terminates in an official register: the EU Trusted List (EUTL) — a machine-readable, XML-based list of trust service providers that the European Commission and national supervisory bodies maintain under the eIDAS Regulation. If a qualified timestamp, seal, or signature was issued by a provider listed there, the software can treat it as trustworthy across every member state without anyone manually importing certificates. The EUTL is what makes 'qualified' status verifiable at scale.

At a glance

Five facts that cover most EUTL questions.

01

Each EU member state publishes its own national trusted list; the Commission aggregates them into the master EUTL format.

02

The list is machine-readable XML with defined schemas — PDF readers and e-signature platforms download and cache it automatically.

03

Inclusion means a national supervisory body has assessed the provider as qualified under eIDAS — it is a regulatory status, not a membership anyone can buy.

04

Adobe Acrobat ships with EUTL integration enabled by default, which is why qualified European signatures validate 'out of the box'.

05

The list changes constantly: providers are added, services extended, or revoked — which is why validators refresh their cached copy rather than trusting a static bundle.

How the EUTL actually works

The mechanism in three moves.

1. National lists roll up

Every member state designates a supervisory body (usually its communications or digital-agency authority). That body audits trust service providers operating on its territory and publishes a national trusted list in the harmonised format specified by Commission Implementing Decision.

2. The Commission aggregates

The European Commission consolidates the national lists into the master EUTL, applying consistency rules so downstream software only needs one entry point. The list marks each provider's qualified services — QES, qualified seals, qualified timestamps, website authentication (QWACs), and under eIDAS 2.0, emerging wallet-related services.

3. Software consumes it

Validation software — Acrobat is the best-known example — periodically fetches the EUTL, builds a trust store from the listed providers' service certificates, and validates signatures against it. A signature chained to a listed QTSP gets the 'qualified' treatment; one chained elsewhere needs manual trust decisions.

Listed vs not listed: what it means for a signature

The practical difference when you open a signed document.

Provider on the EUTLProvider not on the EUTL
Signature status shownValid, qualified (where applicable) with automatic trustValid from a technical standpoint, but 'trust not established' warning
Cross-border treatmentRecognised in all EU/EEA member states by regulationDepends on the receiving party manually deciding to trust the issuer
Evidence weightQualified presumption: strong legal default under eIDASOrdinary evidentiary weight, must be argued from the audit trail
Typical useQES, qualified e-seals, qualified timestamps for regulated workflowsAdvanced or simple signatures for general B2B contracting
How to fix a warningUsually just update the validator's trusted-list cacheManually add the issuer to the trust store — a one-off, not a policy

What changes with eIDAS 2.0

The trusted-list architecture survives and extends.

Wallet services join the register

As the EU Digital Identity Wallet (EUDI) ecosystem deploys through 2026 and beyond, trust services that support wallet-based signing and identity attestations appear in the trusted lists alongside classic QES and seal services. The register is the natural place for enterprises to watch who is officially wallet-ready.

Verification becomes a product requirement

eIDAS 2.0 obliges relying parties in certain scenarios to verify qualified attestations — and the trusted list is the mechanism that verification uses. If your business receives signed documents or wallet-presented attributes from the EU, your validation stack will touch the EUTL whether you planned to or not.

Non-EU providers and trust lists

Other jurisdictions maintain analogous lists — national trusted lists exist across Asia and the Americas, and Adobe consumes several of them by region. A non-EU provider being absent from the EUTL is not a defect; it may simply be certified under a different regime, which matters for cross-border contracts choosing which trust route to use.

Common questions

The European Commission publishes the list of qualified trust service providers, and most national supervisory bodies offer searchable versions. For the practical walkthrough including where each country's list lives, see our guide to qualified trust service providers on the EU trusted list.

Team discussing the right eSignature approach for a business

Explore the right eSignature approach for your business

Talk to our team about eSignature requirements, compliance considerations, and document workflows across your target markets.