eSign.AIeSign.AI

Glossary

CA, TSP and QTSP: The Trust-Service Ecosystem

Certificate Authorities, Trust Service Providers, and Qualified TSPs form the trust infrastructure for digital signatures.

eSign.AI Digital Trust Research Team5 min read

The trust-service ecosystem

Digital signatures rely on a layered ecosystem of trusted organisations. Certificate Authorities (CAs) issue certificates. Trust Service Providers (TSPs) offer signature-related services. Qualified TSPs (QTSPs) are accredited to issue qualified certificates that carry the highest legal weight under eIDAS.

CA vs TSP vs QTSP

RoleKey function
CAIssues digital certificatesIdentity verification and certificate lifecycle
TSPProvides trust servicesSignatures, timestamps, seals, registered delivery
QTSPQualified TSP (accredited)Same as TSP plus qualified certificates with legal presumption

What each role does in practice

The roles often overlap — a single organisation may be a CA, TSP, and QTSP.

01

A CA verifies identity and issues digital certificates. Responsible for identity proofing, certificate issuance, key management, and revocation handling.

02

A TSP provides electronic trust services: signature creation, validation, timestamping, registered delivery, and certificate management. Many CAs are also TSPs.

03

A QTSP is a TSP accredited by a national supervisory body under eIDAS. Only QTSPs can issue qualified certificates that enable QES and QSeal with legal presumption.

Examples across jurisdictions

Different countries have different trust service ecosystems.

EU trust list

The European Commission maintains the EU Trusted List — a public registry of all accredited QTSPs in member states. Check this list to verify whether a TSP is qualified under eIDAS.

China CA system

China's CA system is regulated by MIIT and SCA. Licensed CAs include eSign, BJCA, and others. Under T/CQAE 11034-2025, CAs must directly handle identity verification and key management.

Singapore IMDA

IMDA accredits CAs under the ETA. Netrust is a prominent licensed CA. IMDA oversees the trust framework for digital signatures in Singapore.

Cross-border recognition

eIDAS allows EU member states to recognise QTSPs from third countries if they meet equivalent standards. Most APAC CAs are not eIDAS-accredited.

Trust service provider selection: EU Trusted List and APAC equivalents

Practical data for evaluating and selecting TSPs.

EU Trusted List statistics (2026)

The EU Trusted Lists are the authoritative source for checking whether a provider and a specific trust service hold qualified status. Counts change as services are added, suspended, withdrawn, or renewed, so procurement teams should verify the live list rather than rely on a static total.

APAC TSP equivalents

APAC markets use their own legal and supervisory models. Singapore maintains a voluntary accreditation framework for certification authorities under the ETA; Hong Kong recognises certification authorities and certificates under the ETO; Malaysia licenses certification authorities under the Digital Signature Act; China regulates electronic certification services and commercial cryptography; and Indonesia maintains a registered PSrE framework. These local statuses are not the same as qualified status under eIDAS and must be checked with the relevant regulator.

Common questions

A TSP provides services related to electronic signatures and trust — certificate issuance, timestamping, signature validation, and registered delivery. Under eIDAS, TSPs can be qualified (accredited) or non-qualified.

How eSign.AI applies this in practice

eSign.AI supports certificate-backed digital-signature workflows and confirmed local integrations including Singpass in Singapore, iAM Smart in Hong Kong, Trustgate in Malaysia, VNPT in Vietnam, and Vinotek in Indonesia. Each integration must still be described using the local legal framework and certificate status; APAC recognition is not eIDAS-qualified status.

Team discussing the right eSignature approach for a business

Explore the right eSignature approach for your business

Talk to our team about eSignature requirements, compliance considerations, and document workflows across your target markets.