Signatures the Registry expects on the declaration: the Commission institutional seal plus the organisation's countersignature or counterseal
A QSeal is not a certificate you download: the application chain includes a step that must happen in person
QSeal applications stall at the same point for most manufacturers, and it is not the paperwork: it is the identity verification that has to be completed before a qualified certificate can be issued. Under eIDAS (Regulation (EU) No 910/2014), an electronic seal only carries qualified status when a qualified trust service provider (QTSP) that appears on the EU Trusted List (EUTL) issues it, and Article 24 of that regulation excludes email and SMS identification from the ways an applicant may be identified. For a company registering with the EU Digital Product Passport (DPP) Registry this decides the shape of the whole process: the legal entity needs a QSeal to countersign the Commission-sealed declaration, the certificate's organisation name, identifier and country of registration must match the submitted data character for character, and a mismatch is rejected automatically. What follows separates the two places a QSeal is needed, compares five application paths, sets out the two verification routes and the three-layer material list, lists the specific reasons validation fails, and covers the long-term validation settings that have to be chosen at issuance rather than at archiving.
Date the DPP Registry became operational, with economic operator onboarding open
Date from which every EV battery, LMT battery and industrial battery above 2 kWh needs a battery passport
Largest declaration file the Registry accepts; PDF only, filename up to 100 characters
Date the Hague Apostille Convention entered into force for China, replacing consular legalisation in most cases
A QSeal appears at two points in the DPP process, and each point asks for something different
Separating the two touchpoints before applying keeps the certificate requirements clear instead of buying one seal to cover two unrelated jobs.
Operator registration verification. The organisation downloads the Commission-sealed PDF declaration, adds its own QSeal, and uploads a file that contains exactly two signatures. This happens once per legal entity and repeats at certificate renewal. Sole traders use a qualified electronic signature (QES) instead, and the two are not interchangeable.
Signing DPP content files. Product data generated as XML or JSON needs a qualified signature at archival level. Volume tracks export volume rather than the number of legal entities, so the cost behaves like a metered service.
Registration verification asks whether the seal can represent this legal entity, so the work is organisation data consistency and a documented chain of authority. Content signing asks whether the signature will still validate at the end of the retention period, so the work is signature format level and timestamp configuration.
Article 24 lists four identification routes, and none of them is an emailed verification code
Article 24(1) of eIDAS sets out the only ways a QTSP may identify an applicant before issuing a qualified certificate, which is why the application cannot be completed as a self-service download.
Physical presence (Article 24(1)(a))
The applicant attends in person. This is the route a QTSP will usually propose to a company based outside the Union, because it produces a verifiable record without depending on another country's identity infrastructure.
Remote identification through a notified electronic identification means (Article 24(1)(b))
Remote identification is permitted only where the electronic identification means was issued under a scheme notified under Article 9 and reaches a substantial or high level of assurance under Article 8.
Presentation of a qualified certificate (Article 24(1)(c))
An existing qualified electronic signature or qualified electronic seal certificate can serve as the basis for issuing another qualified certificate.
A method recognised at national level (Article 24(1)(d))
Member States may accept other identification methods, but the method has to be confirmed by a conformity assessment body. Email addresses and SMS codes fall into none of these four categories.
What the registration authority records on site
Because a QTSP generally cannot verify a Chinese company's legal existence directly, it authorises a local registration authority (RA) to carry out verification and forward an encrypted record. Three facts are established: the identity documents are originals, the person presenting them is the person named in them, and the application is made at the applicant's own initiative. The verification record is archived as audit evidence.
Who is allowed to act for the company
Either the legal representative attends in person, or the attending person holds a power of attorney that has been notarised and legalised. The language, the notary and the legalisation route each carry their own requirements, so the document is prepared before the verification appointment rather than at it.
Five application paths differ less in what they deliver than in whether the seal keeps representing the legal entity after it is issued
The first three paths answer the question whether a qualified seal can be obtained. The fourth and fifth answer whether that seal will still represent the legal entity at renewal and at scale.
| 1. Domestic CA certificate | 2. Single overseas reseller | 3. Direct QTSP remote verification | 4. RA verification with normalised organisation data | 5. Seal wired into the signing workflow | |
|---|---|---|---|---|---|
| Seal qualification | Not issued by a QTSP | Depends on the reseller's channel | QTSP-issued | QTSP-issued | QTSP-issued |
| Identity verification | Online real-name check | Delegated to an intermediary | Video verification in English | In person at a registration authority | In person, plus an authorisation register |
| Organisation data alignment | Not applicable | Checked case by case | Checked case by case | Normalised before the application | Mapped to signing-system fields |
| Renewal handling | Not applicable | New engagement each cycle | Full re-verification each cycle | Batched re-verification before expiry | Expiry alerts routed into the workflow |
| Signing DPP content files | Not supported | Not supported | Purchased separately | Purchased separately | API-connected, metered signing |
| Long-term verifiability | Not covered | Not covered | Depends on the chosen format | Depends on the chosen format | Archival-grade format with qualified timestamps |
In-person verification at a registration authority
- The applicant brings original identity documents to the verification point, where an agent captures and compares them.
- Missing items can be corrected during the visit instead of being resubmitted by courier.
- Communication runs in Chinese, which shortens the round trip on translation questions.
- The practical choice when the power of attorney or the sworn translation is not yet finalised.
Remote video verification
- The applicant presents documents over an international video channel and completes a face comparison.
- The session runs in English, so the applicant needs working English.
- Time-zone coordination is required, and verification hours are billed separately.
- The practical choice when the file is complete and the applicant can communicate in English.
The application chain has six steps, and three of them run on timelines the company does not control
Translation, notarisation, legalisation and field alignment sit outside internal scheduling, which is why they start first.
Confirm the applying entity and the authority to represent it
Decide whether the legal representative attends personally or whether a notarised and legalised power of attorney is used. This determines what has to be prepared before any appointment is booked.
Normalise the organisation data
Fix the English legal name, the identifier and the country of registration as they will appear in the certificate. The same strings have to hold across the business register, the sworn translation, the seal certificate and the Registry form.
Complete identity verification
Attend in person at a registration authority, or complete remote video verification. The verification record is archived either way.
Submit for issuance to a QTSP on the EU Trusted List
The issuing provider must be listed on the EUTL. Confirm the delivery method at this point as well: a QSCD in the form of a smart card or USB token, or a qualified remote signing service operated by the QTSP.
Configure long-term validation
Set the signature format level and the qualified timestamp before the first signature is produced. Changing the format afterwards means re-signing the documents that are already archived.
Countersign the Registry declaration
Download the Commission-sealed PDF, add only your own QSeal, and upload. The result must contain exactly two signatures. Adding a third seal invalidates the declaration, and the original PDF has to be downloaded again.
The material list has three layers, and the third one causes most rejections
The first two layers are administrative. The third layer is a data problem that no amount of paperwork resolves after the fact.
Layer 1: entity identity documents
The business licence in original or a stamped copy, plus the original second-generation ID card and passport of the legal representative or authorised agent. The person attends in person; originals are returned after verification and compliant copies are archived.
Layer 2: language and legalisation documents
The business licence translated into English with a sworn translation. China has applied the Hague Apostille Convention since 7 November 2023, so an Apostille covers most cases and consular legalisation is no longer required; where the receiving jurisdiction is not a party to the Convention, the legalisation route is confirmed separately.
Layer 3: organisation information sheet
English legal name, registered address, official email address and telephone number. This layer is the most underestimated, because the seal certificate has to match the declaration character for character and the Registry reports one error per mismatched field.
Choosing the identifier
A legal person's first choice is the National Trade Register identifier (NTR). Non-EU operators may use a Legal Entity Identifier (LEI, ISO 17442). A VAT number can be supplied as a supplement but is not mandatory. The identifier is capped at 50 characters and must match the corresponding certificate attribute in full, not partially.
Registry validation reports one error per mismatched field, so failures cluster in five places
Validation is automatic and the report can list several failures at once. Correct them and the declaration can be resubmitted.
Signature count mismatch
The uploaded PDF must contain exactly two signatures: the Commission institutional seal and the organisation's countersignature or counterseal. Adding a third seal removes the declaration's validity, and the original PDF has to be downloaded again.
Data mismatch
The organisation name, identifier or country recorded in the seal certificate differs from the value entered on the form. A single submission can return several errors here because every field is checked separately.
Insufficient seal level
A seal that was not issued by a QTSP, or a signing tool without qualified status, is rejected. Holding a qualified certificate is not enough on its own: a software certificate in .p12 or .pfx form only produces an advanced signature. Creation has to go through a QSCD, meaning a smart card or a USB token, or through a QTSP's qualified remote signing service.
Wrong signature format
The Registry expects PAdES Baseline B, T, LT or LTA. Adobe Acrobat's default signing format has to be changed to CAdES-Equivalent before signing, otherwise the file is rejected.
Format and file constraints
Only PDF is accepted, up to 1 GB, with a filename of no more than 100 characters. Batch upload is available, but it is not atomic: errors are reported per DPP, including its unique product identifier, and can be exported as CSV.
Long-term validation is configured at issuance, because a baseline signature stops validating once the certificate expires
DPP data has to stay accessible, understandable and verifiable for the whole retention period, including after an operator ceases trading.
Why the format level is a decision, not a setting
A baseline signature relies on the certificate being valid at the moment of verification. Once the certificate expires, the signature chain can no longer be completed, which is why the format level is chosen when the seal is issued rather than when the archive is built.
What archival level adds
A long-term archival signature embeds the validation chain and appends archive timestamps, so the signature stays verifiable after the original certificate expires. Under eIDAS, qualified electronic timestamps bind a date and time to data using a UTC time source and are signed or sealed by a QTSP (Article 42).
Retention expectations
The Batteries Regulation requires manufacturers to keep technical documentation and the EU declaration of conformity available to national authorities for 10 years after the battery is placed on the market (Article 38(4)), and ESPR requires the data in a digital product passport to be accurate, complete and up to date (Article 9(1)). Signature validity has to span that window, not just the signing event.
Renewal and expiry
A successful validation report includes the expiry date of the signature or seal. That date is the renewal trigger, and renewal involves re-verification rather than an automatic extension.
Common questions about QSeal applications
Not through a self-service download. Article 24(1) of eIDAS allows identification in person, remotely through a notified electronic identification means at substantial or high assurance level, through an existing qualified certificate, or through a method recognised at national level. Remote video verification is available to Chinese applicants, but the session runs in English and verification hours are billed separately.
Where eSign.AI sits in the application chain, and where the company's own responsibility stays
The split matters because a trust service can be delegated and product data accountability cannot.
Registration authority services
eSign.AI supports the verification stage through registration authority services that coordinate document collection, identity verification appointments and comparison of certificate attributes against the data that will be declared. Issuance itself is performed by the connected QTSP.
Signing after issuance
Three capabilities run after the seal exists: document signing in PAdES for declarations and document-based approvals; structured data signing in XAdES and JAdES at archival level for the XML and JSON used in DPP content files; and long-term validation support with qualified timestamps and retained evidence. Organisations with low signing volume can raise and confirm documents in the SaaS interface, while system-triggered signing connects through SDK or API and keeps per-record status and evidence.
What a cross-border group actually runs
Winner Medical, a medical device manufacturer whose products reach more than 110 countries with production sites in North America and Southeast Asia, runs domestic operations on e签宝 and its overseas entities on eSign.AI. Board resolutions, corporate announcements and internal letters previously moved as files and offline countersignature rounds, which left confirmation order and progress untracked. The overseas entities now initiate those documents from a SaaS interface, and global participants confirm and sign online with automatic archiving. What transfers to a QSeal application is not the seal itself but the handling of organisation identity and authority: when more than one entity signs for a group and regional authority boundaries differ, the certificate data and the authorisation record have to line up the same way they do for a Registry declaration.
Sources and review status
Primary sources: eIDAS, Regulation (EU) No 910/2014, Articles 3(27), 3(32), 24, 35, 36, 38 and 42, and Annex III, as published on EUR-Lex; Regulation (EU) 2024/1781 (ESPR), Articles 9 and 13; Regulation (EU) 2023/1542 (Batteries Regulation), Articles 38(4) and 77; Commission Implementing Regulation (EU) 2026/1778 of 16 July 2026, in force from 6 August 2026; and the European Commission's DPP Registry User Guide for Economic Operators, version 1.03, last published 16 September 2026. Registry access is at registry.product-passport.ec.europa.eu and requires an EU Login account; a test environment is available. This article summarises published requirements and is not legal advice. Requirements for a specific entity, product group or destination market are confirmed with the relevant authority or an adviser qualified in that market. Last reviewed: 19 September 2026.








