emendrix

Art. 32a

Electronic Identification and Trust Services Regulation · 32014R0910 · every event for this act · on EUR-Lex

Requirements for the validation of advanced electronic signatures based on qualified certificates

1 change recorded across 1 event, newest first.

in force 2024-05-20 INSERTED+1,929 −0

Amended by Regulation (EU) 2024/1183 32024R1183

applies from: unknown (an inserted provision states its own application date only in prose)

This is an entirely new article setting out conditions that must be confirmed for the validation of an advanced electronic signature based on a qualified certificate, including matters such as the certificate's qualification status at signing time, correspondence of validation data, correct provision of signatory data, indication of pseudonym use, integrity of signed data, and compliance with Article 26 requirements.

It also adds a requirement that the validation system provide the relying party with the correct validation result and allow detection of security relevant issues, and it directs the Commission to establish, by 21 May 2025, a list of reference standards and, where necessary, specifications and procedures via implementing acts, with compliance with those standards giving rise to a presumption of conformity with the listed requirements.

Cited: Art. 32a, v2

text before / after

inserted text (02014R0910-20240520)

Article 32a
Requirements for the validation of advanced electronic signatures based on qualified certificates
1. The process for the validation of an advanced electronic signature based on a qualified certificate shall confirm the validity of an advanced electronic signature based on a qualified certificate, provided that:
(a) the certificate that supports the signature was, at the time of signing, a qualified certificate for electronic signature complying with Annex I;
(b) the qualified certificate was issued by a qualified trust service provider and was valid at the time of signing;
(c) the signature validation data corresponds to the data provided to the relying party;
(d) the unique set of data representing the signatory in the certificate is correctly provided to the relying party;
(e) the use of any pseudonym is clearly indicated to the relying party if a pseudonym was used at the time of signing;
(f) the integrity of the signed data has not been compromised;
(g) the requirements provided for in Article 26 were met at the time of signing.
2. The system used for validating the advanced electronic signature based on qualified certificate shall provide to the relying party the correct result of the validation process and shall allow the relying party to detect any security relevant issues.
3. By 21 May 2025, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for the validation of advanced electronic signatures based on qualified certificates. Compliance with the requirements laid down in paragraph 1 of this Article shall be presumed where the validation of advanced electronic signature based on qualified certificates complies with those standards, specifications and procedures. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).