Trust Service Provider Conformity
Accredited conformity assessment of Trust Service Providers under ETSI EN 319 403 and the applicable eIDAS trust service standards.
Who needs this — and why
Operating as a Trust Service Provider — or preparing to become one — means demonstrating through conformity assessment that the organisation itself meets the Regulation's requirements.
Unlike individual trust services, ETSI EN 319 403 defines the conformity assessment framework for the provider itself. It establishes how accredited Conformity Assessment Bodies evaluate the governance, operation and trust services delivered by a Trust Service Provider.
Because every provider offers a different combination of qualified and non-qualified trust services, the assessment is tailored to the services included within the agreed scope.
Every assessment therefore begins by defining the appropriate scope before conformity activities start.
Assessing the entire provider
Trust Service Provider conformity extends beyond individual trust services. Our auditors combine accredited assessment with practical security expertise to evaluate governance, operational processes and technical controls as one integrated trust environment.
What the certification covers
Our assessment covers the complete operational framework of a Trust Service Provider, including governance, security management and certification practices and the trust services delivered within the agreed scope. We examine how the provider manages risk, protects trust assets and demonstrates conformity across its organisational and technical environment.
The assessment also includes the wider governance and security framework, including operational procedures, incident handling, personnel, supplier relationships, facilities and change management. Rather than reviewing individual controls in isolation, we evaluate how the organisation functions as a whole and whether objective evidence demonstrates that it consistently operates in conformity with the applicable requirements.
Standards & articles
Trust Service Providers are assessed against the applicable requirements of ETSI EN 319 403 together with the relevant eIDAS and ETSI trust service standards.
This may include:
- ETSI EN 319 403
- ETSI EN 319 401
- Regulation (EU) No 910/2014
- Service-specific ETSI standards applicable to the assessed trust services
The exact assessment scope depends on the trust services operated by the provider and is agreed with you during scoping, before the assessment begins.
Where we've done it
Our experience includes accredited assessments involving organisations such as those below — the full list is on our references page:
-
Incode
-
MISA
-
monobank
-
Scrive
More broadly, TAYLLORCOX has certified more than 30 trust services across 11 countries.
Our references include Trust Service Providers operating national and international trust services across Europe and beyond.
Explore the full eIDAS scope
We assess every trust service and identity scheme the Regulation defines — not only the one on this page.
Request an assessment
If you are establishing a new Trust Service Provider, preparing for supervisory assessment or reviewing an existing conformity assessment, we can help define the assessment scope and explain what evidence will be required before the conformity assessment begins.
Your first conversation will be with an experienced eIDAS auditor who will discuss your trust services, organisational scope and the most appropriate assessment path.