Skip to main content
Zwei Männer in Business Kleidung schütteln sich die Hände Vertrauensdienste

Trust services provide the foundation for secure, legally valid, and traceable digital transactions. For businesses, public administration, the public sector, or education, this is not just about electronic signatures. Trust services also include seals, timestamps, certificates, registered delivery services, identification, and preservation services.

This is precisely why they are a central building block for digital processes: They help make the identity, integrity, and origin of electronic documents verifiable – within a common European trust framework. Practical applications range from contract processes and official notices to secure digital evidence.

Trust services are electronic services that establish trust and security in digital processes. The legal foundation is provided by the eIDAS Regulation of the European Union. It regulates how electronic identities, signatures, seals, and other trust services are recognized in the European single market.

In Switzerland, the Federal Act on Certification Services in the Field of Electronic Signatures (ZertES) forms the national basis for trust services. It regulates the requirements for providers, certificates, and the legal recognition of electronic signatures and seals – similar to the eIDAS Regulation in the EU.

Importantly, trust services and electronic signatures are not the same. The signature is just one of several types of trust services. While an electronic signature represents the declaration of intent of a natural person, an electronic seal, for example, can confirm the origin of a document from a company or authority.

What types of trust services are there?

The most important trust services include:

– Electronic signatures, including the qualified electronic signature (QES)
– Electronic seals for companies, organizations, and authorities
– Electronic timestamps to document a point in time in an evidentiary manner
– Certificates for signatures, seals, or website authentication
– Electronic registered delivery services for secure communication
– Preservation services, such as for the long-term retention of qualified signatures and seals

In practice, this means: Trust services not only secure contracts but also notices, applications, evidence, test protocols, approvals, and other business-critical documents. Depending on the application, the focus is either on identity, integrity, delivery, timing, or long-term evidence.

In Switzerland, the requirements for these services are defined in ZertES. The qualified electronic signature (QES) under ZertES is legally equivalent to a handwritten signature and is recognized for official and business transactions.

Benefits of Trust Services for Businesses and Public Administration

Trust services add value especially where digital processes require high traceability, security, and legal reliability. For businesses, authorities, and educational institutions, this results in several practical benefits:

Legal certainty: Qualified trust services under eIDAS provide a robust foundation for electronic signatures, seals, timestamps, and digital evidence.
Seamless processes: Documents no longer need to be printed, manually signed, scanned, or sent by mail.
Enhanced security: The identity, integrity, and origin of documents can be secured technically and organizationally.
Better traceability: Timestamps, certificates, and verification mechanisms make digital transactions auditable and verifiable.
EU-wide and pan-European recognition: Thanks to the eIDAS Regulation, qualified trust services can be used across borders in the European single market. By complying with ZertES, these services can also be extended to Switzerland.
Efficiency in specialized processes: Trust services can be integrated into applications for contract management, HR, procurement, administrative procedures, or customer onboarding.
Stronger trust: A qualified trust service provider (TSP) ensures that digital communication and electronic documents are based on a verified trust infrastructure.

For decision-makers, this means: Trust services are not just a compliance issue. They are an enabler for scalable, secure, and user-friendly digitalization – especially where signatures, seals, identity verification, or evidentiary delivery were previously paper-based.

Qualified Trust Services and TSPs

A qualified trust service meets particularly high requirements of the eIDAS Regulation. It is provided by a qualified trust service provider, also known as a QTSP. The abbreviation TSP (Trust Service Provider) is often used in this context.

A TSP must demonstrate technical, organizational, and legal requirements. These include, among others, requirements for security, availability, identity verification, key management, and traceability. Qualified trust service providers are subject to regular audits and are supervised by a competent authority.

In Germany, the Federal Network Agency plays a central role as the supervisory authority for trust service providers. Additionally, technical guidelines, regulations, and requirements for security and information technology are relevant, such as those in the environment of the BSI. The national Trust Services Act specifies certain aspects of the European regulation.

In Switzerland, this role is taken by the Federal Office of Communications (BAKOM). Qualified trust service providers under ZertES must meet strict requirements, including regular audits by accredited bodies and registration in the Swiss provider directory.

Role of Certification Authorities and Trust Lists

Certification authorities issue certificates and verify the identity of applicants beforehand. These certificates form the technical and legal basis for providing trust in signatures, seals, or website authentication.

Whether a trust service provider is qualified can be checked via the European Trusted List. Each EU member state maintains such a trusted list, which includes qualified providers and services with qualification status from the respective country.

In Switzerland, verification is done through the BAKOM provider directory, which lists qualified certification service providers under ZertES. Companies and authorities can check the recognition and status of Swiss trust service providers there.

This verification is important for companies and authorities: Only if the respective TSP is qualified for the specific service can the desired legal effect and security be reliably achieved.

Application in Public Administration and Businesses

In public administration, trust services are used wherever paper processes are to be replaced by digital ones: for applications, notices, tenders, approvals, personnel files, or internal communication. Electronic seals can confirm that a document actually originates from an authority. Timestamps additionally enhance security by making the time of creation, submission, or approval verifiable.

In Switzerland, trust services under ZertES are particularly relevant for official procedures, public tenders, land registry offices, and the healthcare sector. Electronic signatures and seals under ZertES enable, for example, the legally valid submission of tax returns, building applications, or medical documents.

For businesses, this means: Trust services can be integrated into existing processes – such as contract management, procurement, HR, compliance, operations, or customer onboarding. Key factors are interfaces, role models, identification procedures, archiving, signature verification, and integration into specialized applications.

A typical application is digital contract signing: The identity of the signing person is verified, the document is electronically signed, a timestamp secures the time, and subsequent verification ensures that the content has remained unchanged. This creates digital processes that are user-friendly, efficient, and legally secure.

Trust services can also play an important role in the Digital Product Passport (DPP): A qualified electronic seal can help companies assign product data, registrations, and regulatory evidence to an organization in a trustworthy manner and secure their integrity.

Why Security is Central to Trust Services

Trust services are more than just technical auxiliary services. They form a trust infrastructure on which business-critical and official processes are built. Security here means not only encryption or access protection. It also involves reliable identities, tamper-proof documents, verifiable certificates, and traceable transactions.

In Switzerland, the requirements of ZertES, the Code of Obligations (CO), and industry-specific regulations (e.g., in the financial or healthcare sector) must additionally be considered. Choosing a qualified provider under ZertES ensures that digital processes in Switzerland are legally secure and compliant.

For CISOs, compliance officers, and management, it is therefore crucial which TSP is used, how the application is integrated into existing systems, and whether the requirements from eIDAS, internal policies, and industry-specific regulations are met.

Frequently Asked Questions about Trust Services

What is the eIDAS Regulation?

The eIDAS Regulation is an EU law that regulates electronic identification and trust services in the European single market. The goal is to create a uniform legal framework for secure digital transactions.

What is ZertES?

ZertES is the Swiss Federal Act on Certification Services in the field of electronic signatures. It regulates the requirements for electronic signatures, seals, timestamps, and certification service providers, ensuring that qualified electronic signatures (QES) are legally recognized in Switzerland and equivalent to handwritten signatures. ZertES thus provides the foundation for secure, legally valid digital transactions in Switzerland.

What is a qualified trust service provider?

A qualified trust service provider is a provider authorized to offer qualified services under eIDAS. Such a TSP is subject to strict requirements, regular audits, and governmental supervision.

What is a certification service provider?

A certification service provider (CSP) is a natural or legal person that issues, manages, and verifies digital certificates. In Switzerland, CSPs under ZertES must meet specific technical, organizational, and legal requirements to be allowed to issue qualified certificates for electronic signatures, seals, or timestamps. CSPs are responsible for the security and trustworthiness of digital identities and documents and are supervised in Switzerland by the Federal Office of Communications (BAKOM).

Are electronic signatures always qualified?

No. There are simple, advanced, and qualified electronic signatures. Only the QES is legally equivalent to a handwritten signature in many cases.

Where can you verify qualified providers?

Qualified trust service providers under eIDAS can be verified via the European Trusted List. In Switzerland, verification is done through the BAKOM provider directory, which lists qualified certification service providers under ZertES.

Why are timestamps important?

Timestamps prove that certain data or documents existed at a specific point in time and have not been altered since. This strengthens integrity, security, and traceability.

What are certification services?

Certification services include the issuance, management, and verification of digital certificates. They enable electronic signatures, seals, and other trust services to be uniquely assigned to a person, organization, or technical identity.

Conclusion

Trust services are a fundamental component of modern digital infrastructure. They create trust in identities, documents, communication, and transactions – and make digital processes in businesses and public administration robust, efficient, and compliant with eIDAS or ZertES.

The key is the appropriate application: Not every process requires the same trust service, the same signature level, or the same TSP. Those who consider security, user-friendliness, and regulatory requirements together create a solid foundation for digital transformation.

SIGN8 supports organizations in the field of trust infrastructure, digital identities, electronic signatures, seals, and EUDI wallet readiness by translating regulatory requirements into secure and user-friendly processes.