in force 2024-05-20 MODIFIED+1,188 −181§
Amended by Regulation (EU) 2024/1183 32024R1183
applies from: unknown (the text changed beyond its dates, so no date that moved can be read as the application date)
dates added to the text: 2025-05-21
The text now specifies that compliance with the Annex IV requirements for qualified certificates for website authentication is evaluated according to standards, specifications and procedures referred to in paragraph 2, rather than relying solely on Annex IV.
Two new paragraphs, 1a and 1b, were added: one requiring providers of web-browsers to recognise such qualified certificates, display identity data and additional attested attributes in a user-friendly manner, and ensure support and interoperability (with an exception for microenterprises and small enterprises during their first five years of operation), and the other stating that such certificates shall not be subject to mandatory requirements other than those in paragraph 1.
Paragraph 2 was changed from allowing the Commission to establish reference numbers of standards, to requiring the Commission, by 21 May 2025, to establish a list of reference standards and, where necessary, specifications and procedures.
Cited: Art. 45, v2 · Art. 45, v1
text before / after
texts differ too much for an inline diff; shown separately
before (32014R0910)
Article 45 Requirements for qualified certificates for website authentication 1. Qualified certificates for website authentication shall meet the requirements laid down in Annex IV. 2. The Commission may, by means of implementing acts, establish reference numbers of standards for qualified certificates for website authentication. Compliance with the requirements laid down in Annex IV shall be presumed where a qualified certificate for website authentication meets those standards. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
after (02014R0910-20240520)
Article 45 Requirements for qualified certificates for website authentication 1. Qualified certificates for website authentication shall meet the requirements laid down in Annex IV. The evaluation of compliance with those requirements shall be carried out in accordance with the standards, specifications and procedures referred to in paragraph 2 of this Article. 1a. Qualified certificates for website authentication issued in accordance with paragraph 1 of this Article shall be recognised by providers of web-browsers. Providers of web-browsers shall ensure that the identity data attested in the certificate and additional attested attributes are displayed in a user-friendly manner. Providers of web-browsers shall ensure support and interoperability with qualified certificates for website authentication referred to in paragraph 1 of this Article, with the exception of microenterprises or small enterprises as defined in Article 2 of the Annex to Recommendation 2003/361/EC during the first five years of operating as providers of web-browsing services. 1b. Qualified certificates for website authentication shall not be subject to any mandatory requirements other than the requirements laid down in paragraph 1. 2. By 21 May 2025, the Commission shall, by means of implementing acts, establish a list of reference standards and, where necessary, establish specifications and procedures for qualified certificates for website authentication, referred to in paragraph 1 of this Article. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).