Digital Certification
In recent decades, we have witnessed constant technological developments, influencing the various spheres of society, namely our way of communicating, working, learning or thinking.
Nowadays, organizations seek to accelerate their digital transformation through disruptive technologies that offer various competitive advantages, as well as presenting themselves as solutions that reduce the environmental impact of various economic activities.
Despite being fundamental to the evolution of any organization, digital transformation brings new challenges — the inevitable increase in cyber-risk. It is in this context that we explore the role of the EIDAS Regulation in mitigating this risk. Although the diploma has been in force for some years, there is still a great lack of knowledge about the instruments it has introduced. But let's start at the beginning...
Regulation No 910/2014 of the European Parliament and of the Council of 23 July 2014 is commonly known as the EIDAS Regulation. It has entered into force to create a common legal framework for the entire European Union and to strengthen confidence in electronic transactions in the internal market through the mutual recognition of facilitating technologies. As Decree-Law No 12/2021, which implements eIDAS in the internal legal order, "the adoption of the Regulation aimed to increase the confidence and security of online transactions in the European Union". This regulatory clarity — and demanding technical standards for electronic communications in the single market — It's essential for cyber-risk mitigation.
The eIDAS Regulation established the assumptions for issuing qualified electronic signatures and stamps, standardising them throughout the European Union. Therefore, a qualified signature issued in one Member State must be recognised in all others, with effect equivalent to a handwritten signature (Article 25(3)). The same applies to qualified electronic seals (Article 35(3)).
It is therefore concluded that a qualified signature is valid only if it complies with the requirements of eIDAS. Therefore, it is essential to have tools to confirm this validity. As the technology of these signatures is different, their verification also differs from that of a handwritten signature.
For this reason, eIDAS created — Article 33 — the qualified service for the validation of qualified electronic signatures and seals. This service makes it possible to verify that a signature has been issued in accordance with the requirements of the Regulation in accordance with Article 32.
DigitalSign, as Qualified Trust Service Provider, has created the DS Verify, – a qualified electronic signature validation service qualifies or qualified electronic seals – which, as mentioned above above, makes it possible to verify that a particular qualified electronic signature actually complies with the requirements for the validity of qualified electronic signatures.
The combination of these three elements of the eIDAS Regulation is essential to mitigate cyber-risk. Qualified Trust Service Providers act as third-party trust by issuing qualified electronic signatures and seals to market agents. In addition, they provide qualified subscription validation services qualified electronics. Thus, those agents may verify the authenticity of an electronic document by validating the signatures affixed to it.
In short, it is established that the dematerialization of physical processes allows organizations to operate in a faster, more agile, economic and sustainable way.
However, it is crucial that digital transformation be carried out efficiently and, above all, safely. As made clear in this exhibition, the use of the tools provided for in the EIDAS Regulation allows the establishment of management controls of all types of electronic documents received by a particular organisation, in particular by defining which types of electronic signatures should be used/accepted in each dematerialised process.
In addition, the use of qualified validation services makes it possible to assess whether an electronic signature attached to a given electronic document is or is not qualified, which in turn enables organisations to ensure the authenticity of the electronic documents they receive, and this is an essential process for all organisations with regard to Cybersecurity.
Continue reading
Explore the DS Verify qualified service: