Who is eIDAS Certification for Qualified Electronic Ledgers Aimed At?
This certification is designed for organizations providing or operating a distributed ledger service in environments requiring a high level of proof, trust, and long-term preservation. Becoming a Qualified Trust Service Provider (QTSP) within this scope is a strategic asset for:
- Blockchain and DLT Providers / Web3 Ecosystem Players: Teams operating shared ledgers who wish to transform their decentralized technological solutions into a legally recognized trusted third party at the European level.
- Supply Chain and Logistics Operators: Industries requiring flawless and legally enforceable traceability (e.g., Digital Product Passport (DPP), raw materials tracking).
- The Financial and Banking Sector: Institutions managing transactions, digital assets, or smart contracts that demand indisputable proof of priority and sequential order.
- Public and State Authorities: Agencies responsible for managing administrative, land, or legal public registries.
- Critical Infrastructure and Energy Operators: Entities handling the certification of origin for green energy, carbon credits, or grid transactions.
What are the Stakes of eIDAS Certification for Ledger Operators?
For tech and industrial players, the eIDAS v2 qualification of an electronic ledger addresses 4 major strategic challenges:
- The Legal Presumption of Integrity (Automatic Legal Effect): In accordance with the eIDAS v2 Regulation, data recorded in a qualified electronic ledger enjoys a unique presumption of the accuracy of the date, time, and sequential order of the recording. In the event of litigation, the burden of proof is reversed: it is up to the opposing party to prove any hypothetical alteration of the ledger.
- Automatic Cross-Border Recognition: Qualification guarantees the legal and technical interoperability of the ledger across all 27 EU Member States. A recording certified in France is natively enforceable before any European administration or court of law.
- A Passport to Regulated and Public Markets: Listing on the European Trusted List (EUTL) removes entry barriers when contracting with the public sector, finance, healthcare, or heavy industry, where eIDAS v2 compliance is becoming a prerequisite for procurement tenders.
- Technological Immunity and Evidence Permanence: By validating the consensus architecture and cryptographic protections against strict ISO standards, certification protects the operator against immutability flaws and guarantees the independent verification of long-term evidence, even if the underlying infrastructure undergoes technical evolution.
eIDAS v2 Framework for Qualified Electronic Ledgers
The eIDAS v2 framework defines strict requirements to guarantee the reliability and continuity of the service. The provider must demonstrate:
- Controlled governance of the service (processes, responsibilities, supervision);
- Robust security covering the distributed infrastructure and cryptographic mechanisms;
- Full traceability of the operations recorded in the ledger;
- Mechanisms guaranteeing immutability and proof of data integrity;
- Clear methods ensuring long-term preservation and independent verification of evidence.
The service is assessed based on European and international standards for Trust Service Providers (TSPs):
| Reference | Status | Subject | Role in the assessment | |||
| ETSI EN 319 401 | European standard | General requirements | Governance framework, organization, security, and internal control of the provider. | |||
| ISO 23257:2022 | International Standard | Blockchain Reference Architecture | Defines the expected properties of the DLT infrastructure: immutability, chaining of records, tampering prevention. |
|||
| ISO 23635:2022 | International Standard | DLT Service Guidelines | Direct baseline for the technical and cryptographic certification audit of the ledger. | |||
| Implementing Regulation (EU) 2025/2531 | European Implementing Act |
Technical Requirements for Ledgers |
Legally binding rule mandating the use of these standards for inclusion on the European Trusted List (EUTL). |
The service is assessed based on European and international standards for Trust Service Providers (TSPs):The technical ISO (23257 / 23635) and eIDAS v2 frameworks notably mandate:
- Consensus mechanisms preventing retroactive modification (absolute immutability).
- Secure time-stamping of blocks (typically backed by an ETSI EN 319 422 qualified time stamp).
- Traceable and publicly verifiable logging.
- Mathematically provable integrity without depending on an unmanaged centralized third party.
- High-level protection of the cryptographic keys used for transactions.
Note: Certification attests to compliance with technical standards. Qualification is subsequently granted by the national supervisory authority (such as ANSSI in France), enabling official entry into the European Trusted List (EUTL).
Governance and DLT Architectures: Public or Private Blockchains?
Consequently, while the underlying technology can rely on public, hybrid, or consortium architectures, the service operator must prove absolute control over the validation nodes, cryptographic keys, and governance mechanisms.
Your Questions about the eIDAS Service: Qualified Electronic Ledgers
-
What is a Qualified Electronic Ledger under eIDAS v2?
A Qualified Electronic Ledger under eIDAS v2 is a new trust service (Article 3, No. 16-n) that leverages distributed ledger technologies (such as blockchain) to record data. Its "qualified" status means it has been thoroughly audited by an independent body and legally guarantees the immutability, authenticity, and chronological traceability of the information recorded within it across the entire European Union. -
What technical standards must be met to certify a qualified electronic ledger?
To certify a qualified electronic ledger, a provider must comply with the general organizational standard ETSI EN 319 401, and crucially with the international standards ISO 23257:2022 and ISO 23635:2022. These technical standards are officially mandated by the European Commission through Implementing Regulation (EU) 2025/2531. -
What is the legal value of data recorded in a qualified electronic ledger?
The legal value of data recorded in a qualified electronic ledger is exceptionally strong: the eIDAS v2 Regulation grants it a presumption of integrity and accuracy regarding the date, time, and sequential order of the recording. In the event of litigation before a European court, the burden of proof is reversed: it is up to the party contesting the recording to provide evidence of its falsification (reversal of the burden of proof). -
What security mechanisms are audited during the certification of a DLT/Blockchain ledger?
During the certification of a DLT (Distributed Ledger Technology) ledger, the audited security mechanisms include the robustness of the cryptographic algorithms used, the reliability of block time-stamping, consensus processes preventing retroactive modification (immutability), and the protection of the private keys used to record transactions in the electronic ledger. -
Can a public (permissionless) blockchain be certified as a qualified electronic ledger?
Directly certifying a completely decentralized public blockchain (such as the Bitcoin or Ethereum mainnets) is extremely complex under eIDAS v2 because the standard requires a legal entity (the QTSP) to be held liable for governance, security breaches, and financial compensation in case of an issue. On the other hand, many providers use consortium (permissioned) networks or develop secondary layers (Layer-2) with strict access control to ensure the legal and cryptographic control required by the audit. -
How does the audit process with LSTI work to qualify an electronic ledger service?
The audit process with LSTI to qualify an electronic ledger service generally takes place in two steps: a documentary audit phase to validate the security policy and the ledger's architecture (according to ISO 23257 and 23635 standards), followed by an on-site audit to verify the practical implementation of technical and organizational measures. A Conformity Assessment Report (CAR) is then delivered to support the qualification application filed with the national supervisory authority (ANSSI).
Why Choose LSTI?

Recognized expertise
With more than twenty years of experience, LSTI supports more than 300 organizations in France and across Europe as a certification body and leading assessment center, operating in the fields of cybersecurity, digital trust, and information security.

Specialized Auditors
Our audit teams are composed of experienced professionals who are well-versed in ANSSI’s cybersecurity standards, information security management practices, and European digital trust frameworks. Their approach ensures rigorous, balanced assessments that are tailored to each organization’s operational context.

Independent Third Party and Dedicated Support
Accredited by ANSSI, LSTI ensures impartiality, transparency, and consistency throughout the entire process: preparation, audits, monitoring, and renewals. A dedicated point of contact ensures continuity and clarity throughout the certification process.




