Each EU member state publishes its own national trusted list; the Commission aggregates them into the master EUTL format.
Europe's master register of trust
When a PDF shows a green checkmark in Adobe Acrobat declaring a signature 'valid and trusted', Acrobat is not guessing. It checked the signer's certificate against a chain of trust that terminates in an official register: the EU Trusted List (EUTL) — a machine-readable, XML-based list of trust service providers that the European Commission and national supervisory bodies maintain under the eIDAS Regulation. If a qualified timestamp, seal, or signature was issued by a provider listed there, the software can treat it as trustworthy across every member state without anyone manually importing certificates. The EUTL is what makes 'qualified' status verifiable at scale.
At a glance
Five facts that cover most EUTL questions.
The list is machine-readable XML with defined schemas — PDF readers and e-signature platforms download and cache it automatically.
Inclusion means a national supervisory body has assessed the provider as qualified under eIDAS — it is a regulatory status, not a membership anyone can buy.
Adobe Acrobat ships with EUTL integration enabled by default, which is why qualified European signatures validate 'out of the box'.
The list changes constantly: providers are added, services extended, or revoked — which is why validators refresh their cached copy rather than trusting a static bundle.
How the EUTL actually works
The mechanism in three moves.
1. National lists roll up
Every member state designates a supervisory body (usually its communications or digital-agency authority). That body audits trust service providers operating on its territory and publishes a national trusted list in the harmonised format specified by Commission Implementing Decision.
2. The Commission aggregates
The European Commission consolidates the national lists into the master EUTL, applying consistency rules so downstream software only needs one entry point. The list marks each provider's qualified services — QES, qualified seals, qualified timestamps, website authentication (QWACs), and under eIDAS 2.0, emerging wallet-related services.
3. Software consumes it
Validation software — Acrobat is the best-known example — periodically fetches the EUTL, builds a trust store from the listed providers' service certificates, and validates signatures against it. A signature chained to a listed QTSP gets the 'qualified' treatment; one chained elsewhere needs manual trust decisions.
Listed vs not listed: what it means for a signature
The practical difference when you open a signed document.
| Provider on the EUTL | Provider not on the EUTL | |
|---|---|---|
| Signature status shown | Valid, qualified (where applicable) with automatic trust | Valid from a technical standpoint, but 'trust not established' warning |
| Cross-border treatment | Recognised in all EU/EEA member states by regulation | Depends on the receiving party manually deciding to trust the issuer |
| Evidence weight | Qualified presumption: strong legal default under eIDAS | Ordinary evidentiary weight, must be argued from the audit trail |
| Typical use | QES, qualified e-seals, qualified timestamps for regulated workflows | Advanced or simple signatures for general B2B contracting |
| How to fix a warning | Usually just update the validator's trusted-list cache | Manually add the issuer to the trust store — a one-off, not a policy |
What changes with eIDAS 2.0
The trusted-list architecture survives and extends.
Wallet services join the register
As the EU Digital Identity Wallet (EUDI) ecosystem deploys through 2026 and beyond, trust services that support wallet-based signing and identity attestations appear in the trusted lists alongside classic QES and seal services. The register is the natural place for enterprises to watch who is officially wallet-ready.
Verification becomes a product requirement
eIDAS 2.0 obliges relying parties in certain scenarios to verify qualified attestations — and the trusted list is the mechanism that verification uses. If your business receives signed documents or wallet-presented attributes from the EU, your validation stack will touch the EUTL whether you planned to or not.
Non-EU providers and trust lists
Other jurisdictions maintain analogous lists — national trusted lists exist across Asia and the Americas, and Adobe consumes several of them by region. A non-EU provider being absent from the EUTL is not a defect; it may simply be certified under a different regime, which matters for cross-border contracts choosing which trust route to use.
Common questions
The European Commission publishes the list of qualified trust service providers, and most national supervisory bodies offer searchable versions. For the practical walkthrough including where each country's list lives, see our guide to qualified trust service providers on the EU trusted list.







