Commission Implementing Regulation (EU) 2025/2162 of 27 October 2025 laying down rules for the application of Regulation (EU) No 910/2014
as it stood on 2025-10-28, permalink: /eu-eurlex/32025r2162/2025-10-28
2 versions · click any mark to read the law as it stood that day · ▌ the one you are reading
Outline, 10 provisions
Article 1 Article 2 Article 3 Article 4 Article 5 Article 6 Article 7 Article 8 Article 9 Article 10
For the purpose of this Regulation, the following definitions shall apply:
(1) ‘scheme owner’ means an entity or a group of entities which is responsible for developing and maintaining a conformity assessment scheme;
(2) ‘certification decision’ means a certification decision, which follows a conformity assessment conducted by a conformity assessment body where that body positively or negatively confirms the conformity of a specific qualified trust service provider and the qualified trust service it provides with the requirements laid down in Regulation (EU) No 910/2014 and with Article 21 of Directive (EU) 2022/2555;
(3) ‘certificate of conformity’ means a document by which a conformity assessment body attests a certification decision that positively confirms that a specific qualified trust service provider and the qualified trust service it provides comply with the requirements laid down in Regulation (EU) No 910/2014 and with Article 21 of Directive (EU) 2022/2555;
(4) ‘conformity assessment scheme’ means a set of rules and procedures to be used by conformity assessment bodies for the purpose of the assessment of the conformity of qualified trust service providers and the qualified trust services that they provide with the requirements laid down in Regulation (EU) No 910/2014 and with Article 21 of Directive (EU) 2022/2555;
(5) ‘conformity assessment report’ means a document that provides detailed information, where applicable supplementary to that contained in a certification decision and associated certificate of conformity, on the method used to carry out, in accordance with a conformity assessment scheme, a conformity assessment of the compliance of a specific qualified trust service provider and the qualified trust service it provides with the requirements of Regulation (EU) No 910/2014 and of Article 21 of Directive (EU) 2022/2555 and on the results of the conformity assessment;
(6) ‘accreditation’ means an accreditation, as defined in Article 2, point 10 of Regulation (EC) No 765/2008;
(7) ‘flexible scope accreditation’ means an accreditation where the specific conformity assessment activities for which accreditation is sought, or has been granted, are expressed to allow conformity assessment bodies to make changes in methodology and other parameters which fall within the competence of the conformity assessment body as confirmed by the national accreditation body;
(8) ‘national accreditation body’ means a national accreditation body as defined in Article 2, point 11, of Regulation (EC) No 765/2008.
1. For the purposes of making certification decisions in accordance with a specific conformity assessment scheme, conformity assessment bodies shall be accredited in accordance with standard EN ISO/IEC 17065:2012 supplemented by standard ETSI EN 319 403 -1 v2.3.1.
2. The accreditation of conformity assessment bodies referred to in paragraph 1 shall be performed by a national accreditation body in compliance with standard EN ISO/IEC 17011:2017.
1. National accreditation bodies shall ensure that the accreditation certificates they issue to conformity assessment bodies contain at least the following information:(a) the unique accreditation certificate identity code;(b) the issuance date of the accreditation certificate;(c) the name and country, as stated in the national official records, of the national accreditation body issuing the accreditation certificate;(d) the name and, where applicable, registration number as stated in the national official records, of the accredited conformity assessment body;(e) the scope of accreditation, with regard to one or more of the following qualified trust services:— the issuance of qualified certificates for electronic signatures;— the issuance of qualified certificates for electronic seals;— the issuance of qualified certificates for website authentication;— the qualified validation service for qualified electronic signatures;— the qualified validation service for qualified electronic seals,— the qualified preservation service for qualified electronic signatures;— the qualified preservation service for qualified electronic seals;— the creation of qualified electronic timestamps;— the provision of qualified electronic registered delivery services;— the qualified service for the management of remote qualified electronic signature creation devices;— the qualified service for the management of remote qualified electronic seal creation devices;— the provision of qualified electronic archiving services;— the issuance of qualified electronic attestations of attributes;— the recording of electronic data in a qualified electronic ledger.(f) the identification, including, where relevant, the specific version, of the conformity assessment scheme for which the conformity assessment body has been accredited;(g) the indication of the use of the flexible scope accreditation, where relevant;(h) the identification, where relevant, of the document outlining the design and implementation process of the flexible scope accreditation.
2. National accreditation bodies shall ensure that the start date, and where applicable, the end date of the accreditation of the conformity assessment body for conducting the conformity assessment of the qualified trust services as referred to in paragraph 1, point (e), including specific dates for each qualified trust service as applicable, are part of the accreditation details referred to in Article 20(1b) of Regulation (EU) No 910/2014.
3. National accreditation bodies shall ensure that any relevant changes made in relation to the information provided in accordance with paragraph 1 shall be clearly reflected in the accreditation certificate.
4. The accreditation certificate shall clearly describe the scope of the accreditation of the conformity assessment body, in accordance with Article 2(1).
1. The scheme owner shall implement procedures to monitor any changes in the standards referred to in Article 2(1) or in Article 6(3), or to a conformity assessment scheme owned by it and on the basis of which a conformity assessment body has been accredited in accordance with Article 2.
2. The scheme owner shall notify the national accreditation body of the changes identified as a result of the procedures referred to in paragraph 1, in a timely manner.
3. Where the national accreditation body did not apply flexible scope accreditation to accredited conformity assessment bodies, the national accreditation body shall determine whether the changes, identified as a result of the procedures referred to in paragraph 1, are likely to materially affect the ability of accredited conformity assessment bodies to conduct conformity assessments pursuant to schemes for which they have been accredited.
4. Where the national accreditation body determines, pursuant to paragraph 3, that changes do affect the ability of conformity assessment bodies to conduct conformity assessments, it shall request the conformity assessment body to take appropriate measures within a reasonable prescribed period.
5. If the conformity assessment body is unable or unwilling to take the measures referred to in paragraph 4 within the period prescribed, the national accreditation body shall immediately withdraw or suspend the accreditation.
6. Where the national accreditation body determines, pursuant to paragraph 3, that changes do not affect the ability of conformity assessment bodies to conduct conformity assessments, it may, where appropriate, extend the validity and scope of the accreditation of the assessed conformity assessment body.
7. Where appropriate, the national accreditation body shall update the accreditation certificate in a timely manner to reflect the outcome of the reconsideration of the accreditation pursuant to this Article.
8. Where a conformity assessment body receives a request pursuant to paragraph 4, it shall, in a timely manner, inform any qualified trust service providers that it has previously assessed under the relevant conformity assessment scheme of any impacts that the reconsideration of the conformity assessment body’s accreditation may have on those qualified trust service providers, including with respect to future certification decisions made by the conformity assessment body under that scheme.
1. Conformity assessment bodies shall make the certificates of conformity they issue available in a public repository maintained by that conformity assessment body for that purpose.
2. Any subcontracting by the conformity assessment body of the performance of conformity assessment activities shall duly consider the nature of the activity to be performed. The conformity assessment body shall ensure that the subcontractor complies with the standards set out in Annex I for the specific activity being subcontracted.
3. Conformity assessment bodies shall ensure, upon issuing a certification decision, that the qualified trust services provider to whom the decision relates, is able to submit the complete conformity assessment reports corresponding to that decision to the supervisory bodies.
1. Each conformity assessment scheme shall identify a scheme owner.
2. A conformity assessment scheme shall comply with scheme type 6 of standard EN ISO/IEC 17067:2013 and with the requirements laid down in this Article.
3. Scheme owners shall ensure that their conformity assessment schemes include at least the standards, as applicable, set out in Annex II by indicating the year and version number of these standards.
4. Scheme owners shall ensure that where a flexible scope accreditation is applicable, this is indicated in the conformity assessment scheme.
5. Scheme owners shall ensure that their conformity assessment schemes establish processes and procedures, regarding at least the following:(a) receiving and handling complaints to the scheme owner on the implementation of the conformity assessment scheme;(b) notifications by the conformity assessment body to the supervisory body designated in accordance with Article 46b(1) of Regulation (EU) No 910/2014 on the issuance of certificates of conformity and any changes thereto;(c) where applicable, subcontracting the performance of conformity assessment activities by the conformity assessment body;(d) the performance of yearly surveillance activities on the basis of the applicable requirements of clause 7.9 of standard ISO/IEC 17065:2012;(e) the management and notification by the qualified trust service provider to the conformity assessment body and to the competent supervisory body of any change impacting the operation of qualified trust service providers or the qualified trust services they provide;(f) the verification of evidence demonstrating that the conformity assessment body:— has sufficient knowledge and expertise in the application of specific standards related to the qualified trust service provided by the qualified trust service provider, as referred to in paragraph 3;— has professional experience in conformity assessment in at least three assessments of trust service providers or three assessments of information security management systems; and— can ensure the availability of a team of no fewer than two qualified persons possessing the necessary expertise to carry out such conformity assessment.
6. Scheme owners shall ensure that their conformity assessment schemes require the qualified trust service providers to have processes, procedures and work instructions in place to notify the conformity assessment body at least one month before the qualified trust service providers implement any significant change in the provision of the qualified trust services certified under that scheme and at least three months ►C1 before they intend** ◄ ** to cease the provision of the services or parts thereof.
7. Scheme owners shall ensure that their conformity assessment schemes do not allow positive certification decisions, or any certificate of conformity, to be issued where the conformity assessment leads to the identification of non-conformity of the assessed qualified trust service providers and the qualified trust service they provide with the requirements of Regulation (EU) No 910/2014 and of Article 21 of Directive (EU) 2022/2555.
8. Scheme owners shall ensure that their conformity assessment schemes set out the procedure for the attestation of a certificate of conformity. They shall require, in particular, that the qualified trust service providers immediately inform the competent supervisory body of any change to a certificate of conformity. They shall also require that qualified trust services providers refrain from providing the qualified trust services concerned or from advertising any reference thereto until the competent supervisory body reconfirms the qualified status. This procedure shall comply with the requirements set out in clause 7.11 of standard ISO/IEC 17065:2012.
9. Scheme owners shall ensure that their conformity assessment schemes set out the conformity assessment process to be conducted over a sufficient number of person-days and shall ensure that sufficient resources and time are allocated for the conformity assessment, taking into account the scope and the complexity of the assessment.
10. Scheme owners shall make a summary of the conformity assessment scheme publicly available for download. The summary shall contain a description of the set of rules and procedures followed for the assessment of the conformity of qualified trust service providers and the qualified trust services they provide with the requirements of Regulation (EU) No 910/2014 and of Article 21 of Directive (EU) 2022/2555.
11. Scheme owners shall ensure that their conformity assessment schemes require that at least one surveillance conformity assessment is conducted annually for every evaluated qualified trust service.
1. The conformity assessment report referred to in Article 20(1) of Regulation (EU) No 910/2014, shall comply with the specifications set out in Annex III.
2. The conformity assessment report shall be considered a part of the certification documentation specified in clause 7.7 of standard ETSI EN 319 403 -1.
1. Any interested party can request, free of charge, current and past information about the scope, start date and, where applicable, end date of the accreditation of conformity assessment bodies, for each type of qualified trust service that the conformity assessment body is or has been accredited to assess. This information shall be made available by national accreditation bodies.
2. Current and past information, as referred to in paragraph 1, should be made available for at least a period of 6 years after the accreditation of the conformity assessment body.
Conformity assessment bodies that have, before 17 November 2025, been accredited with reference to standard ETSI EN 319 403 version 2.2.2, or earlier version, for the purposes of the assessment of conformity with Regulation (EU) No 910/2014 of qualified trust service providers and the qualified trust services they provide shall have their accreditation be considered to meet the requirements of Article 2(1) until 17 May 2027.
This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
Provenance and validity dates, identifier, hash
| as of | 2025-10-28 → this version applied |
| valid | 2025-10-28 → open publisher-asserted |
| type | REG_IMPL Commission Implementing Regulation (EU) 2025/2162 of 27 October 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and the Council as regards the accreditation of conformity assessment bodies performing the assessment of qualified trust service providers and the qualified trust services they provide, the conformity assessment report and the conformity assessment scheme |
| language | en |
| published | 2025-10-28 |
| lex_id | eu-eurlex:32025r2162:2025-10-28 |
| record sha256 | 7709459e3e42c0bb3333682c401285292a9440f2e810213fe9758513ab75dd3f |
New here? What am I looking at?
This is a consolidated text: the original law with every later amendment merged in, as the official publisher produced it for a given date. Laws are amended constantly, so “the law” has no single text, only a text per date. That date is the banner above.
It has no legal force. Only the version published in the official gazette (Mémorial / Official Journal) is authentic, the publishers say so themselves, and so do we. Lex reproduces their text without altering a byte, and links the source on every page. This is legal information, never legal advice: it reports what the text said, never what it means for your situation.
“Valid from → to” = the window in which this text applied. “Open” = still current as far as the publisher has consolidated. Each article carries its own hash so you can prove it was not tampered with , here is how.
← previous version (2025-10-27) what changed? timeline next version (2025-10-28) →
| tier | A, publisher-supplied validity dates |
| history begins | publisher |
| index built | 2026-08-07T19:46:23Z · corpus 8d5e859 |
| stamp signature | valid (ECDSA-P256) |