Industries0 / 9 modules
Learn
0%
Build
0%
Back to DashboardIndustriesPhase 5 · Pilots & Migrationintermediate60 min

Trust Services & Long-Term Signatures

Qualified signatures, timestamping and proof of existence, long-term validation and re-timestamping, trust service provider conformity, and the ETSI cryptographic suites that just gained post-quantum modes.

Why this matters: A qualified signature made today may need to be evaluated in 2050 — outliving the certificate, the revocation data, and very probably the algorithm underneath it. That is a migration problem no amount of new-signature planning solves, because the work is proportional to the archive you already have.

Practice in the Simulation

Under eIDAS, an advanced electronic signature is uniquely linked to its signatory and detects later changes to the data. A qualified signature adds two things: it is created with a qualified signature creation device, and it rests on a certificate issued by a qualified trust service provider. Only the qualified form carries automatic legal equivalence to a handwritten signature across the Union.

That legal equivalence is why this module exists. Once a signature has legal weight, the question stops being “is this cryptographically valid today” and becomes “can a court establish that it was valid when it was made” — potentially decades later.

Scope note. Wallet activation, PID issuance and the eIDAS 2.0 wallet flows are covered in Digital ID; CMS and S/MIME signing mechanics in Email & Document Signing; certificate chain fundamentals in PKI. This module deliberately does not repeat them — it covers what happens to a signature over time, which none of them cover.

Check off all sections and mark this reading done.

Learning module content can be inaccurate. Please double-check its information. Report inaccuracies in PQC Today GitHub Discussions.