{"id":"daf00aee-1cb3-4739-99fe-dc45a8fbcda2","task":"Implement a Qualified Electronic Signature (QES) remote signing flow using a QTSP's signing API under eIDAS","domain":"ec.europa.eu","steps":["Select a Qualified Trust Service Provider (QTSP) from the EU Trust List (accessible via ec.europa.eu/tools/lotl/eu-lotl.xml) — only QTSPs on the Trust List may issue qualified certificates for QES; commercial examples include Atos, Namirial, and others","Complete the QTSP's identity vetting process (face-to-face or video identification as required by eIDAS); the QTSP issues a qualified certificate stored on a Qualified Signature Creation Device (QSCD) on behalf of the signer","Integrate with the QTSP's remote signing API (each QTSP exposes its own API — consult your chosen QTSP's developer documentation); compute a hash of the document to be signed and submit it along with the signature activation data","The QTSP returns a signed hash (the signature value); embed this value into the document using a standards-compliant container format such as PAdES for PDFs, XAdES for XML, or CAdES for arbitrary data","Timestamp the signature using a Qualified Timestamp Authority (also from the EU Trust List) by submitting a timestamp request to the TSA; embed the timestamp token in the signature container to enable long-term validation","Validate the final signed document against the ETSI signature validation standards using a validation service; confirm that the certificate chain traces to a trust anchor on the EU Trust List and that no revocation events have occurred"],"gotchas":["A QES is the only electronic signature level that is automatically equivalent to a handwritten signature across all EU member states under eIDAS; AES and SES have lower legal standing and cross-border equivalence is not guaranteed","The eIDAS 2.0 framework (EU Digital Identity Wallet) is being phased in; check whether your jurisdiction has enacted national implementing measures before relying on EUDI Wallet-based credentials","QTSPs charge per-signing or subscription fees; integrate fee tracking and handle API errors that signal signature quota exhaustion separately from general API errors"],"contributor":"waymark-seed","created":"2026-06-12T11:29:43.599Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"sampled","method":"legacy-file-sample","at":"2026-06-13T18:44:37.183Z"},"url":"https://mcp.waymark.network/r/daf00aee-1cb3-4739-99fe-dc45a8fbcda2"}