European flag

Az Európai Unió
Hivatalos Lapja

HU

L sorozat


2025/2164

2025.10.28.

A BIZOTTSÁG (EU) 2025/2164 VÉGREHAJTÁSI HATÁROZATA

(2025. október 27.)

az (EU) 2015/1505 végrehajtási határozatnak a bizalmi listák egységes sablonjának alapjául szolgáló szabvány verziója tekintetében történő módosításáról

AZ EURÓPAI BIZOTTSÁG,

tekintettel az Európai Unió működéséről szóló szerződésre,

tekintettel a belső piacon történő elektronikus tranzakciókhoz kapcsolódó elektronikus azonosításról és bizalmi szolgáltatásokról, valamint az 1999/93/EK irányelv hatályon kívül helyezéséről szóló, 2014. július 23-i 910/2014/EU európai parlamenti és tanácsi rendeletre (1) és különösen annak 22. cikke (5) bekezdésére,

mivel:

(1)

A 910/2014/EU rendelet 22. cikkének (1) bekezdésében előírt bizalmi listák elengedhetetlenek a piaci szereplők bizalmának megteremtéséhez, mivel lehetővé teszik a bizalmi szolgáltatók és az általuk nyújtott bizalmi szolgáltatások minősített státuszának érvényesítését. Ezért a minősített bizalmi szolgáltatók csak azt követően indíthatják el a minősített bizalmi szolgáltatást, hogy a minősített státuszt feltüntették a bizalmi listákon.

(2)

Az (EU) 2015/1505 bizottsági végrehajtási határozat (2) meghatározza a bizalmi listákhoz kapcsolódó technikai specifikációkat és formátumokat. Az említett specifikációk és formátumok az ETSI TS 119 612 szabvány 2.1.1. verziójában meghatározott specifikációkon és követelményeken alapulnak.

(3)

Az (EU) 2024/1183 európai parlamenti és tanácsi rendelet (3) módosította a 910/2014/EU rendeletet azáltal, hogy új minősített bizalmi szolgáltatásokat vezetett be, így például a távoli minősített elektronikus aláírást létrehozó eszközök kezelését, a távoli minősített elektronikus bélyegzőt létrehozó eszközök kezelését, a minősített elektronikus attribútumtanúsítványok kibocsátását, a minősített elektronikus archiválási szolgáltatások nyújtását és az elektronikus adatok minősített elektronikus főkönyvbe történő rögzítését. Az ETSI TS 119 612 szabványt a 2.4.1. verzióra frissítették, így az már olyan specifikációkat tartalmaz, amelyek lehetővé teszik, hogy a bizalmi listák magukban foglalják és feltüntessék az említett új minősített bizalmi szolgáltatások státuszát. Az aktualizált, 2.4.1. verzió módosította a tagállamok által a nemzeti bizalmi listáik aláírással vagy bélyegzővel való ellátásához használandó aláírások vagy bélyegzők formátumára vonatkozó specifikációkat is.

(4)

Ezért az (EU) 2015/1505 bizottsági végrehajtási határozatot az ETSI TS 119 612 szabványra való hivatkozásnak a szabvány új, 2.4.1. verziójára való frissítése érdekében módosítani kell. A szóban forgó módosítás következtében az említett végrehajtási határozatban bizonyos további módosításokra is szükség van. Először is – a bizalmi listák tartalmának értelmezése tekintetében – pontosítani kell az említett listákban feltüntetendő információkat, hogy az igénybe vevő felek megfelelően értelmezhessék őket. Másodszor, a bizalmi listák tekintetében alkalmazandó elektronikus aláírások vagy bélyegzők létrehozására vonatkozó specifikációkat ki kell igazítani annak érdekében, hogy megelőzhetők legyenek bizonyos ismert és bejelentett sebezhetőségek.

(5)

Annak érdekében, hogy az igénybe vevő felek számára elegendő idő álljon rendelkezésre a mellékletben meghatározott specifikációkhoz való alkalmazkodásra, e határozat alkalmazását el kell halasztani.

(6)

Az (EU) 2016/679 európai parlamenti és tanácsi rendelet (4) és adott esetben a 2002/58/EK európai parlamenti és tanácsi irányelv (5) az e határozat szerinti valamennyi személyesadat-kezelési tevékenységre alkalmazandó.

(7)

Az európai adatvédelmi biztossal az (EU) 2018/1725 európai parlamenti és tanácsi rendelet (6) 42. cikkének (1) bekezdésével összhangban konzultációra került sor, és a biztos 2025. augusztus 8-án véleményt nyilvánított (7).

(8)

Az e határozatban előírt intézkedések összhangban vannak a 910/2014/EU rendelet 48. cikkében említett bizottság véleményével,

ELFOGADTA EZT A HATÁROZATOT:

1. cikk

Az (EU) 2015/1505 végrehajtási határozat I. melléklete az e határozat mellékletében foglaltak szerint módosul.

2. cikk

Ez a határozat az Európai Unió Hivatalos Lapjában való kihirdetését követő huszadik napon lép hatályba.

Ezt a végrehajtási határozatot 2026. április 29-től kell alkalmazni.

Kelt Brüsszelben, 2025. október 27-én.

a Bizottság részéről

az elnök

Ursula VON DER LEYEN


(1)   HL L 257., 2014.8.28., 73. o., ELI: http://data.europa.eu/eli/reg/2014/910/oj.

(2)  A Bizottság (EU) 2015/1505 végrehajtási határozata (2015. szeptember 8.) a belső piacon történő elektronikus tranzakciókhoz kapcsolódó elektronikus azonosításról és bizalmi szolgáltatásokról szóló 910/2014/EU európai parlamenti és tanácsi rendelet 22. cikkének (5) bekezdése szerinti bizalmi listákhoz kapcsolódó technikai specifikációk és formátumok meghatározásáról (HL L 235., 2015.9.9., 26. o., ELI: http://data.europa.eu/eli/dec_impl/2015/1505/oj).

(3)  Az Európai Parlament és a Tanács (EU) 2024/1183 rendelete (2024. április 11.) a 910/2014/EU rendeletnek az európai digitális személyazonossági keret létrehozása tekintetében történő módosításáról (HL L, 2024/1183, 2024.4.30., ELI: http://data.europa.eu/eli/reg/2024/1183/oj).

(4)  Az Európai Parlament és a Tanács (EU) 2016/679 rendelete (2016. április 27.) a természetes személyeknek a személyes adatok kezelése tekintetében történő védelméről és az ilyen adatok szabad áramlásáról, valamint a 95/46/EK irányelv hatályon kívül helyezéséről (általános adatvédelmi rendelet) (HL L 119., 2016.5.4., 1. o., ELI: http://data.europa.eu/eli/reg/2016/679/oj).

(5)  Az Európai Parlament és a Tanács 2002/58/EK irányelve (2002. július 12.) az elektronikus hírközlési ágazatban a személyes adatok kezeléséről, feldolgozásáról és a magánélet védelméről (Elektronikus hírközlési adatvédelmi irányelv) (HL L 201., 2002.7.31., 37. o., ELI: http://data.europa.eu/eli/dir/2002/58/oj).

(6)  Az Európai Parlament és a Tanács (EU) 2018/1725 rendelete (2018. október 23.) a természetes személyeknek a személyes adatok uniós intézmények, szervek, hivatalok és ügynökségek általi kezelése tekintetében való védelméről és az ilyen adatok szabad áramlásáról, valamint a 45/2001/EK rendelet és az 1247/2002/EK határozat hatályon kívül helyezéséről (HL L 295., 2018.11.21., 39. o., ELI: http://data.europa.eu/eli/reg/2018/1725/oj).

(7)   Az európai adatvédelmi biztos hivatalos észrevételei a bizalmi listák egységes sablonjának alapjául szolgáló szabvány verziójáról szóló tervezetről | Európai adatvédelmi biztos.


MELLÉKLET

Az (EU) 2015/1505 végrehajtási határozat I. melléklete a következőképpen módosul:

1.

A II. fejezet első bekezdésének helyébe a következő szöveg lép:

„Ez a specifikáció az ETSI TS 119 612 szabvány 2.4.1. verziójában (a továbbiakban: ETSI TS 119 612 szabvány) szereplő specifikációkon és követelményeken alapul.”

2.

A II. fejezetben a „Scheme type/community/rules (Rendszertípus, közösség, szabályok) (5.3.9. pont)” cím alatti szakasz helyébe a következő szöveg lép:

Scheme type/community/rules (Rendszertípus, közösség, szabályok) (5.3.9. pont)

Ennek a mezőnek szerepelnie kell és meg kell felelnie az ETSI TS 119 612 szabvány 5.3.9. pontjában meghatározott követelményeknek.

Ez a mező csak brit angol URI-kat tartalmazhat.

A mező legalább a következő két URI-t tartalmazza:

1.

A bizalmi szolgáltatók valamennyi tagállami listája tekintetében azonos URI, amely olyan leíró szövegre mutat, amelynek a bizalmi szolgáltatók összes listájára vonatkozik, az alábbiak szerint:

URI: http://uri.etsi.org/TrstSvc/TrustedList/schemerules/EUcommon

Leíró szöveg:

„A.    Participation in a scheme

Each Member State must create a trusted list including information related to the qualified trust service providers that are under supervision, together with information related to the qualified trust services they provide, in accordance with the relevant provisions laid down in Regulation (EU) No 910/2014.

The present implementation of such trusted lists is also to be referred to in the list of links (pointers) towards each Member State’s trusted list, compiled by the European Commission.

B.    Policy/rules for the assessment of the listed services

Member States must supervise qualified trust service providers established in the territory of the designating Member State as laid down in Chapter III of Regulation (EU) No 910/2014 to ensure that those qualified trust service providers and the qualified trust services they provide meet the requirements laid down in that Regulation.

The trusted lists of Member States include, as a minimum, information specified in Articles 1 and 2 of Implementing Decision (EU) 2015/1505.

The trusted lists include both current and historical information about the status of listed trust services.

Each Member State’s trusted list must provide information on the national supervisory scheme and, where applicable, national approval, including through accreditation scheme(s) under which the trust service providers and the trust services they provide are listed.

C.    Interpretation of the trusted list

The general user guidelines for applications, services or products relying on a trusted list published in accordance with Regulation (EU) No 910/2014 are as follows:

C.1    Qualified status of a trust service

The qualified status of a trust service is indicated by the combination of:

the »Service type identifier« (»Sti«) value in a service entry;

where applicable, the presence of one of the following values in all the fields »additionalServiceInformation extension« in the service entry:

» http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures «: further specifying the »Sti« identified service as being provided for electronic signatures;

» http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSeals «: further specifying the »Sti« identified service as being provided for electronic seals; or

» http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForWebSiteAuthentication «: further specifying the »Sti« identified service as being provided for website authentication; and

the status according to the »Service current status« field value as from the date indicated in the »Current status starting date and time«.

Historical information about such a qualified status is similarly provided when applicable.

C.1.1    Service status under Regulation (EU) No 910/2014

Including and after 1 July 2016 (UTC+2), the value of the »Service current status« field used by the Supervisory Body designated in a Member State to indicate that a trust service entry is representing a qualified trust service is the URI » http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted «.

C.1.2    Service status under Directive 1999/93/EC

Strictly before 1st July 2016 (UTC+2), the value of the »Service current status« field used by the Supervisory Body designated in a Member State to indicate that a trust service entry is representing a certification-service-provider issuing qualified certificates is one of the following URIs:

» http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision «;

» http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/supervisionincessation «; or

» http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited «.

C.2    Qualified status of a certificate

Regarding qualified trust service providers issuing qualified certificates for electronic signatures, for electronic seals and/or for website authentication, a »CA/QC« »Service type identifier« (»Sti«) entry indicates that any end-entity certificate issued by or under the CA represented by the CA’s public key and CA’s name (both CA data to be considered as trust anchor input) present in the »Service digital identifier« (»Sdi«), is or was a qualified certificate (QC) at a certain date and time provided that the trust service entry indicates a granted qualified status (see clause C.1) and that the below requirements are met with reference to that date and time.

C.2.1    Default rules

C.2.1.1   Certificate status standardised rule

The end-entity certificate contains the ETSI standardised QcStatements extension as specified in standard ETSI EN 319 412-5 with the following requirements:

the id-etsi-qcs-QcCompliance (urn:oid:0.4.0.1862.1.1.) QcStatement is present; and

where present, the id-etsi-qcs-QcType (urn:oid:0.4.0.1862.1.6.) QcStatement contains exactly one of the following values:

the id-etsi-qct-esign (urn:oid:0.4.0.1862.6.1.) ETSI defined QC type identifier;

the id-etsi-qct-eseal (urn:oid:0.4.0.1862.6.2.) ETSI defined QC type identifier; or

the id-etsi-qct-web (urn:oid:0.4.0.1862.6.3.) ETSI defined QC type identifier.

Optionally, the id-etsi-qct-QcSSCD (urn:oid:0.4.0.1862.4) QcStatement may be present.

C.2.1.2   Certificate status under Directive 1999/93/EC

Restricted to the context of Directive 1999/93/EC and as a legacy alternative to the above standardised rule, the end-entity certificate contains:

the ETSI standardised QcStatements extension (as specified in ETSI EN 319 412-5) with the id-etsi-qcs-QcCompliance (urn:oid:0.4.0.1862.1.1.) QcStatement being present;

the legacy QCP+ (urn:oid:0.4.0.1456.1.1.) ETSI defined certificate policy OID; or

the legacy QCP (urn:oid:0.4.0.1456.1.2.) ETSI defined certificate policy OID.

C.2.2    Additional rules: Presence of Qualifications Extension

If »Sie« »Qualifications Extension« information as specified in clause 5.5.9.2 of standard ETSI TS 119 612 is present, then in addition to the above default rules, those certificates that are identified through the use of »Sie« »Qualifications Extension« information must be considered according to the associated qualifiers. Those qualifiers are used when necessary to compensate for a lack of standardised machine processable information in the corresponding certificate content. They are not to be used to compensate for a lack of machine processable information in certificates issued after 1 July 2016 where that lack would result in a non-compliance with Annex I, III or IV of Regulation (EU) No 910/2014. However, they can be used to provide further machine processable information when the information provided in the certificate, while compliant with the Regulation, does not align with the above default interpretation rules. Where used, they provide additional information regarding:

their qualified status:

»QCStatement« (» http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCStatement «) meaning the identified certificates are qualified under Directive 1999/93/EC or under Regulation (EU) No 910/2014; or

»NotQualified« (» http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/NotQualified «) meaning the identified certificates are not to be considered as qualified.

the nature of their qualification:

»QCForESig« (» http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForESig «) meaning the identified certificates, when claimed or stated as qualified, are qualified certificates for electronic signature under Regulation (EU) No 910/2014;

»QCForESeal« (» http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForESeal «) meaning the identified certificates, when claimed or stated as qualified, are qualified certificates for electronic seal under Regulation (EU) No 910/2014; or

»QCForWSA« (» http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForWSA «) meaning the identified certificates, when claimed or stated as qualified, are qualified certificates for website authentication under Regulation (EU) No 910/2014.

whether or not the private key resides in a qualified signature or qualified seal creation device (QSCD) and the nature thereof:

»QCWithQSCD« (» http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithQSCD «) meaning the identified certificates, when claimed or stated as qualified, have their private key residing in a QSCD;

»QCNoQSCD« (» http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCNoQSCD «) meaning the identified certificates, when claimed or stated as qualified, have not their private key residing in a QSCD;

»QCQSCDStatusAsInCert« (» http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCQSCDStatusAsInCert «) meaning the identified certificates, when claimed or stated as qualified, do contain proper machine processable information about whether or not their private key is residing in a QSCD; or

»QCQSCDManagedOnBehalf« (» http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCQSCDManagedOnBehalf «) meaning the identified certificates, when they are claimed or stated as qualified, have their private key is residing in a QSCD for which the generation and management of that private key is done by a qualified TSP on behalf of the entity whose identity is certified in the certificate;

Restricted to the context of certificates issued under Directive 1999/93/EC, the following qualifiers are defined and provide additional information regarding:

whether or not the private key resides in a secure signature creation device (SSCD):

»QCWithSSCD« (» http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithSSCD «) meaning the identified certificates, when claimed or stated as qualified, have their private key residing in an SSCD;

»QCNoSSCD« (» http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCNoSSCD «) meaning the identified certificates, when claimed or stated as qualified, do not have their private key residing in an SSCD; or

»QCSSCDStatusAsInCert« (» http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCSSCDStatusAsInCert «) meaning the identified certificates, when claimed or stated as qualified, do contain proper machine processable information about whether or not their private key is residing in an SSCD.

the issuance to a Legal Person:

»QCForLegalPerson« (» http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForLegalPerson «) meaning the identified certificates, when claimed or stated as qualified, are issued to a Legal Person under Directive 1999/93/EC.

Note:

The information provided in the trusted list is to be considered as accurate meaning that the certificate is not to be considered as qualified if the end-entity certificate does not follow any of the default rules defined above, and:

if no »Sie« »Qualifications Extension« information is present for the trust anchor CA/QC corresponding service entry to qualify the certificate with a »QCStatement« qualifier, or

a »Sie« »Qualifications Extension« information is present for the trust anchor CA/QC corresponding service entry to qualify the certificate with a »NotQualified« qualifier.

C.3    Trust anchors

»Service digital identifiers« are to be used as Trust Anchors in the context of validating electronic signatures or seals for which signer’s or seal creator’s certificate is to be validated against information in the trusted list, hence only the public key and the associated subject name are needed as Trust Anchor information. When more than one certificate represents the public key identifying the service, they are to be considered as Trust Anchor certificates conveying identical information with regard to the information strictly required as Trust Anchor information.

C.4    General rule for the interpretation of trust service entries

The general rule for interpretation of any »Sti« type entry, possibly further specified through a »Sie« »additionalServiceInformation«, not corresponding to qualified trust services is that, for that »Sti« identified service type, and possibly in combination with a »Sie« »additionalServiceInformation« URI, the listed service named according to the »Service name« field value and uniquely identified by the »Service digital identity« field value has the current approval status according to the »Service current status« field value as from the date indicated in the »Current status starting date and time«.

Specific interpretation rules for any additional information with regard to a listed service (e.g. »Service information extensions« field) may be found, when applicable, in the Member State specific URI as part of the present »Scheme type/community/rules« field.

Please refer to the implementing acts adopted pursuant to Article 22(5) of Regulation (EU) No 910/2014 for further details on the specifications of the fields of the Member States’ trusted lists.”

2.

Az egyes tagállamok bizalmi listáinak egyedi URI-ja, amely az adott tagállam bizalmi listájára alkalmazandó leíró szövegre mutat:

a)

http://uri.etsi.org/TrstSvc/TrustedList/schemerules/CC, ahol CC = a „Scheme territory” (Rendszer területi hatálya) mezőben (5.3.10. pont) használt ISO 3166-1 (1) alpha-2 országkód

ahol a felhasználók elérhetik az adott tagállam azon egyedi szabályzatait/szabályait, amelyek alapján a listán szereplő szolgáltatásokat értékelik a tagállam felügyeleti rendszerének és – adott esetben – jóváhagyási rendszerének megfelelően

ahol a felhasználók elérhetik az adott tagállamra vonatkozó külön leírásokat arról, hogy miként kell a bizalmi lista tartalmát értelmezni a listán szereplő nem minősített bizalmi szolgáltatásokkal és/vagy nemzeti szinten meghatározott bizalmi szolgáltatásokkal kapcsolatban. Ezzel jelezni lehet a minősített tanúsítványok kiadásával nem foglalkozó hitelesítésszolgáltatók vagy bizalmi szolgáltatók nemzeti jóváhagyási rendszerének potenciális granularitását és azt, hogy a „Scheme service definition URI” (Rendszer szolgáltatásai meghatározásának URI-ja) (5.5.6. pont) és a „Service information extension” (Szolgáltatásadat-bővítmény) (5.5.9. pont) mezőket miként használják erre a célra

b)

A tagállamoknak lehetőségük van a fenti tagállam-specifikus URI-t kibővítő további URI-kat (azaz ebből a hierarchikus specifikus URI-ból meghatározott URI-kat) meghatározni és használni.”

3.

A II. fejezet a „Service current status (Szolgáltatás aktuális státusa) (5.5.4. pont)” cím alatti szakasz után a következő szakasszal egészül ki:

The Signature element (Az Aláírás elem) (B.1. pont), General (Általános rész) (B.1.0. pont)

Ennek a pontnak szerepelnie kell és meg kell felelnie az ETSI TS 119 612 szabvány B.1.0. pontjában meghatározott követelményeknek, ahol a 2) pont helyébe a következő szöveg lép:

»2)

A ds:SignedInfo elemének tartalmaznia kell egy ds:Reference elemet, amelynek URI attribútuma üres karakterláncot tartalmaz (azaz URI=""), hogy az egész dokumentumra vonatkozzon. A szóban forgó ds:Reference elemnek a következő követelményeknek kell megfelelnie:

a)

csak egy ds:Transforms elemet tartalmazhat;

b)

ez a ds:Transforms elem két ds:Transform elemet tartalmaz. Az első Algorithm attribútuma a következő értékkel adja meg a borítékolt aláírássá történő átalakítást: ’http://www.w3.org/2000/09/xmldsig#enveloped-signature’. A másodiknak az Algorithm attribútuma pedig a ’http://www.w3.org/2001/10/xml-exc-c14n#’ értékű kizárólagos kanonizáció elvégzésére ad utasítást.«”


(1)  ISO 3166-1:2006: „Országok és igazgatási egységeik nevének kódjai – 1. rész: Országkódok”.


ELI: http://data.europa.eu/eli/dec_impl/2025/2164/oj

ISSN 1977-0731 (electronic edition)