emendrix

Art. 32

Electronic Identification and Trust Services Regulation · 32014R0910 · every event for this act · on EUR-Lex

Requirements for the validation of qualified electronic signatures

1 change recorded across 1 event, newest first.

in force 2024-05-20 MODIFIED+342 −171

Amended by Regulation (EU) 2024/1183 32024R1183

applies from: unknown (the text changed beyond its dates, so no date that moved can be read as the application date)

dates added to the text: 2025-05-21

A new sentence was added at the end of paragraph 1 stating that compliance with the requirements of that paragraph's first subparagraph is presumed where validation of qualified electronic signatures complies with the standards, specifications and procedures referred to in paragraph 3.

Paragraph 3 was changed from describing the Commission's establishing of reference numbers of standards, with a presumption-of-compliance clause tied to paragraph 1, to describing the Commission's establishing of a list of reference standards and, where necessary, specifications and procedures, with a deadline of 21 May 2025 and without that presumption clause, which was moved to paragraph 1.

Cited: Art. 32, v2 · Art. 32, v1

text before / after

32014R091002014R0910-20240520

Article 32 Requirements for the validation of qualified electronic signatures 1. The process for the validation of a qualified electronic signature shall confirm the validity of a qualified electronic signature provided that: (a) the certificate that supports the signature was, at the time of signing, a qualified certificate for electronic signature complying with Annex I; (b) the qualified certificate was issued by a qualified trust service provider and was valid at the time of signing; (c) the signature validation data corresponds to the data provided to the relying party; (d) the unique set of data representing the signatory in the certificate is correctly provided to the relying party; (e) the use of any pseudonym is clearly indicated to the relying party if a pseudonym was used at the time of signing; (f) the electronic signature was created by a qualified electronic signature creation device; (g) the integrity of the signed data has not been compromised; (h) the requirements provided for in Article 26 were met at the time of signing. Compliance with the requirements laid down in the first subparagraph of this paragraph shall be presumed where the validation of qualified electronic signatures complies with the standards, specifications and procedures referred to in paragraph 3. 2. The system used for validating the qualified electronic signature shall provide to the relying party the correct result of the validation process and shall allow the relying party to detect any security relevant issues. 3. The By 21 May 2025, the Commission may, shall, by means of implementing acts, establish a list of reference numbers of standards and, where necessary, establish specifications and procedures for the validation of qualified electronic signatures. Compliance with the requirements laid down in paragraph 1 shall be presumed where the validation of qualified electronic signatures meets those standards. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).