Choose the experimental features you want to try

This document is an excerpt from the EUR-Lex website

Document 32025D2164

Izvedbeni sklep Komisije (EU) 2025/2164 z dne 27. oktobra 2025 o spremembi Izvedbenega sklepa (EU) 2015/1505 glede različice standarda, na kateri temelji skupna predloga za zanesljive sezname

C/2025/7179

UL L, 2025/2164, 28.10.2025, ELI: http://data.europa.eu/eli/dec_impl/2025/2164/oj (BG, ES, CS, DA, DE, ET, EL, EN, FR, GA, HR, IT, LV, LT, HU, MT, NL, PL, PT, RO, SK, SL, FI, SV)

Legal status of the document In force

ELI: http://data.europa.eu/eli/dec_impl/2025/2164/oj

European flag

Uradni list
Evropske unije

SL

Serija L


2025/2164

28.10.2025

IZVEDBENI SKLEP KOMISIJE (EU) 2025/2164

z dne 27. oktobra 2025

o spremembi Izvedbenega sklepa (EU) 2015/1505 glede različice standarda, na kateri temelji skupna predloga za zanesljive sezname

EVROPSKA KOMISIJA JE –

ob upoštevanju Pogodbe o delovanju Evropske unije,

ob upoštevanju Uredbe (EU) št. 910/2014 Evropskega parlamenta in Sveta z dne 23. julija 2014 o elektronski identifikaciji in storitvah zaupanja za elektronske transakcije na notranjem trgu in o razveljavitvi Direktive 1999/93/ES (1) ter zlasti člena 22(5) Uredbe,

ob upoštevanju naslednjega:

(1)

Zanesljivi seznami iz člena 22(1) Uredbe (EU) št. 910/2014 so bistveni za krepitev zaupanja med udeleženci na trgu, saj omogočajo potrjevanje kvalificiranega statusa ponudnikov storitev zaupanja in storitev zaupanja, ki jih zagotavljajo. Zato ponudniki kvalificiranih storitev zaupanja začnejo zagotavljati kvalificirano storitev zaupanja šele po tem, ko se kvalificirani status navede na zanesljivih seznamih.

(2)

Izvedbeni sklep Komisije (EU) 2015/1505 (2) določa tehnične specifikacije in formate v zvezi z zanesljivimi seznami. Te specifikacije in formati temeljijo na specifikacijah in zahtevah iz standarda ETSI TS 119 612, različica 2.1.1.

(3)

Z Uredbo (EU) 2024/1183 Evropskega parlamenta in Sveta (3) se je spremenila Uredba (EU) št. 910/2014 z uvedbo novih kvalificiranih storitev zaupanja, in sicer upravljanja naprav za ustvarjanje kvalificiranega elektronskega podpisa na daljavo, upravljanja naprav za ustvarjanje kvalificiranega elektronskega žiga na daljavo, izdajanja kvalificiranih elektronskih potrdil o atributih, zagotavljanja kvalificiranih storitev elektronskega arhiviranja ter beleženja elektronskih podatkov v kvalificirani elektronski evidenci. Standard ETSI TS 119 612 je bil posodobljen na različico 2.4.1 in zdaj vsebuje specifikacije, ki omogočajo, da zanesljivi seznami vključujejo in navajajo statuse teh novih kvalificiranih storitev zaupanja. S posodobljeno različico 2.4.1 so bile spremenjene tudi specifikacije za format podpisov ali žigov, ki jih države članice uporabljajo za podpisovanje ali žigosanje svojih nacionalnih zanesljivih seznamov.

(4)

Zato bi bilo treba Izvedbeni sklep Komisije (EU) 2015/1505 spremeniti, da se sklic na standard ETSI TS 119 612 posodobi na njegovo novejšo različico 2.4.1. Zaradi te spremembe so potrebne tudi nekatere dodatne spremembe navedenega izvedbenega sklepa. Prvič, pojasniti bi bilo treba informacije, ki se morajo navesti na zanesljivih seznamih, v zvezi z razlago vsebine takih seznamov, da se zanašajočim se strankam omogoči razlaga informacij na zanesljivih seznamih. Drugič, specifikacije v zvezi z ustvarjanjem elektronskih podpisov ali žigov, ki se uporabljajo za zanesljive sezname, bi bilo treba prilagoditi, da se preprečijo nekatere znane in sporočene ranljivosti.

(5)

Za zagotovitev, da bodo imele zanašajoče se stranke dovolj časa za prilagoditev specifikacijam iz Priloge, bi bilo treba začetek uporabe tega sklepa odložiti.

(6)

Uredba (EU) 2016/679 Evropskega parlamenta in Sveta (4) in, kadar je ustrezno, Direktiva 2002/58/ES Evropskega parlamenta in Sveta (5) se uporabljata za vse dejavnosti obdelave osebnih podatkov na podlagi tega sklepa.

(7)

V skladu s členom 42(1) Uredbe (EU) 2018/1725 Evropskega parlamenta in Sveta (6) je bilo opravljeno posvetovanje z Evropskim nadzornikom za varstvo podatkov, ki je mnenje podal 8. avgusta 2025 (7).

(8)

Ukrepi iz tega sklepa so v skladu z mnenjem odbora, ustanovljenega na podlagi člena 48 Uredbe (EU) št. 910/2014 –

SPREJELA NASLEDNJI SKLEP:

Člen 1

Priloga I k Izvedbenemu sklepu (EU) 2015/1505 se spremeni, kot je določeno v Prilogi k temu sklepu.

Člen 2

Ta sklep začne veljati dvajseti dan po objavi v Uradnem listu Evropske unije.

Ta izvedbeni sklep se uporablja od 29. aprila 2026.

V Bruslju, 27. oktobra 2025

Za Komisijo

predsednica

Ursula VON DER LEYEN


(1)   UL L 257, 28.8.2014, str. 73, ELI: http://data.europa.eu/eli/reg/2014/910/oj.

(2)  Izvedbeni sklep Komisije (EU) 2015/1505 z dne 8. septembra 2015 o določitvi tehničnih specifikacij in formatov v zvezi z zanesljivimi seznami v skladu s členom 22(5) Uredbe (EU) št. 910/2014 Evropskega parlamenta in Sveta o elektronski identifikaciji in storitvah zaupanja za elektronske transakcije na notranjem trgu (UL L 235, 9.9.2015, str. 26, ELI: http://data.europa.eu/eli/dec_impl/2015/1505/oj).

(3)  Uredba (EU) 2024/1183 Evropskega parlamenta in Sveta z dne 11. aprila 2024 o spremembi Uredbe (EU) št. 910/2014 v zvezi z vzpostavitvijo evropskega okvira za digitalno identiteto (UL L, 2024/1183, 30.4.2024, ELI: http://data.europa.eu/eli/reg/2024/1183/oj).

(4)  Uredba (EU) 2016/679 Evropskega parlamenta in Sveta z dne 27. aprila 2016 o varstvu posameznikov pri obdelavi osebnih podatkov in o prostem pretoku takih podatkov ter o razveljavitvi Direktive 95/46/ES (Splošna uredba o varstvu podatkov) (UL L 119, 4.5.2016, str. 1, ELI: http://data.europa.eu/eli/reg/2016/679/oj).

(5)  Direktiva 2002/58/ES Evropskega parlamenta in Sveta z dne 12. julija 2002 o obdelavi osebnih podatkov in varstvu zasebnosti na področju elektronskih komunikacij (Direktiva o zasebnosti in elektronskih komunikacijah) (UL L 201, 31.7.2002, str. 37, ELI: http://data.europa.eu/eli/dir/2002/58/oj).

(6)  Uredba (EU) 2018/1725 Evropskega parlamenta in Sveta z dne 23. oktobra 2018 o varstvu posameznikov pri obdelavi osebnih podatkov v institucijah, organih, uradih in agencijah Unije in o prostem pretoku takih podatkov ter o razveljavitvi Uredbe (ES) št. 45/2001 in Sklepa št. 1247/2002/ES (UL L 295, 21.11.2018, str. 39, ELI: http://data.europa.eu/eli/reg/2018/1725/oj).

(7)   Uradne pripombe ENVP o osnutku glede različice standarda, na kateri temelji skupna predloga za zanesljive sezname | Evropski nadzornik za varstvo podatkov.


PRILOGA

Priloga I k Izvedbenemu sklepu (EU) 2015/1505 se spremeni:

(1)

v poglavju II se prvi odstavek nadomesti z naslednjim:

„Te specifikacije temeljijo na specifikacijah in zahtevah iz ETSI TS 119 612 v2.4.1 (v nadaljnjem besedilu: ETSI TS 119 612).“;

(2)

v poglavju II se oddelek pod naslovom „Vrsta sheme/skupnost/pravila (razdelek 5.3.9)“ nadomesti z naslednjim:

Vrsta sheme/skupnost/pravila (razdelek 5.3.9)

To polje je obvezno in v skladu s specifikacijami iz razdelka 5.3.9 ETSI TS 119 612.

To polje vključuje izključno URI v britanski angleščini.

To polje vključuje najmanj dva URI:

(1)

URI, ki je skupen vsem zanesljivim seznamom držav članic, z napotilom na opisno besedilo, ki velja za vse zanesljive sezname, in sicer:

URI: http://uri.etsi.org/TrstSvc/TrustedList/schemerules/EUcommon

Opisno besedilo:

‚A.    Participation in a scheme

Each Member State must create a trusted list including information related to the qualified trust service providers that are under supervision, together with information related to the qualified trust services they provide, in accordance with the relevant provisions laid down in Regulation (EU) No 910/2014.

The present implementation of such trusted lists is also to be referred to in the list of links (pointers) towards each Member State’s trusted list, compiled by the European Commission.

B.    Policy/rules for the assessment of the listed services

Member States must supervise qualified trust service providers established in the territory of the designating Member State as laid down in Chapter III of Regulation (EU) No 910/2014 to ensure that those qualified trust service providers and the qualified trust services they provide meet the requirements laid down in that Regulation.

The trusted lists of Member States include, as a minimum, information specified in Articles 1 and 2 of Implementing Decision (EU) 2015/1505.

The trusted lists include both current and historical information about the status of listed trust services.

Each Member State’s trusted list must provide information on the national supervisory scheme and, where applicable, national approval, including through accreditation scheme(s) under which the trust service providers and the trust services they provide are listed.

C.    Interpretation of the trusted list

The general user guidelines for applications, services or products relying on a trusted list published in accordance with Regulation (EU) No 910/2014 are as follows:

C.1    Qualified status of a trust service

The qualified status of a trust service is indicated by the combination of:

the “Service type identifier” (“Sti”) value in a service entry;

where applicable, the presence of one of the following values in all the fields “additionalServiceInformation extension” in the service entry:

" http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSignatures ": further specifying the "Sti" identified service as being provided for electronic signatures;

" http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForeSeals ": further specifying the "Sti" identified service as being provided for electronic seals; or

" http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/ForWebSiteAuthentication ": further specifying the "Sti" identified service as being provided for website authentication; and

the status according to the “Service current status” field value as from the date indicated in the “Current status starting date and time”.

Historical information about such a qualified status is similarly provided when applicable.

C.1.1    Service status under Regulation (EU) No 910/2014

Including and after 1 July 2016 (UTC+2), the value of the “Service current status” field used by the Supervisory Body designated in a Member State to indicate that a trust service entry is representing a qualified trust service is the URI “ http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/granted ”.

C.1.2    Service status under Directive 1999/93/EC

Strictly before 1st July 2016 (UTC+2), the value of the “Service current status” field used by the Supervisory Body designated in a Member State to indicate that a trust service entry is representing a certification-service-provider issuing qualified certificates is one of the following URIs:

http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/undersupervision ”;

http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/supervisionincessation ”; or

http://uri.etsi.org/TrstSvc/TrustedList/Svcstatus/accredited ”.

C.2    Qualified status of a certificate

Regarding qualified trust service providers issuing qualified certificates for electronic signatures, for electronic seals and/or for website authentication, a “CA/QC” “Service type identifier” (“Sti”) entry indicates that any end-entity certificate issued by or under the CA represented by the CA’s public key and CA’s name (both CA data to be considered as trust anchor input) present in the “Service digital identifier” (“Sdi”), is or was a qualified certificate (QC) at a certain date and time provided that the trust service entry indicates a granted qualified status (see clause C.1) and that the below requirements are met with reference to that date and time.

C.2.1    Default rules

C.2.1.1   Certificate status standardised rule

The end-entity certificate contains the ETSI standardised QcStatements extension as specified in standard ETSI EN 319412-5 with the following requirements:

the id-etsi-qcs-QcCompliance (urn:oid:0.4.0.1862.1.1) QcStatement is present; and

where present, the id-etsi-qcs-QcType (urn:oid:0.4.0.1862.1.6) QcStatement contains exactly one of the following values:

the id-etsi-qct-esign (urn:oid:0.4.0.1862.6.1) ETSI defined QC type identifier;

the id-etsi-qct-eseal (urn:oid:0.4.0.1862.6.2) ETSI defined QC type identifier; or

the id-etsi-qct-web (urn:oid:0.4.0.1862.6.3) ETSI defined QC type identifier.

Optionally, the id-etsi-qct-QcSSCD (urn:oid:0.4.0.1862.4) QcStatement may be present.

C.2.1.2   Certificate status under Directive 1999/93/EC

Restricted to the context of Directive 1999/93/EC and as a legacy alternative to the above standardised rule, the end-entity certificate contains:

the ETSI standardised QcStatements extension (as specified in ETSI EN 319412-5) with the id-etsi-qcs-QcCompliance (urn:oid:0.4.0.1862.1.1) QcStatement being present;

the legacy QCP+ (urn:oid:0.4.0.1456.1.1) ETSI defined certificate policy OID; or

the legacy QCP (urn:oid:0.4.0.1456.1.2) ETSI defined certificate policy OID.

C.2.2    Additional rules: Presence of Qualifications Extension

If “Sie” “Qualifications Extension” information as specified in clause 5.5.9.2 of standard ETSI TS 119 612 is present, then in addition to the above default rules, those certificates that are identified through the use of “Sie” “Qualifications Extension” information must be considered according to the associated qualifiers. Those qualifiers are used when necessary to compensate for a lack of standardised machine processable information in the corresponding certificate content. They are not to be used to compensate for a lack of machine processable information in certificates issued after 1 July 2016 where that lack would result in a non-compliance with Annex I, III or IV of Regulation (EU) No 910/2014. However, they can be used to provide further machine processable information when the information provided in the certificate, while compliant with the Regulation, does not align with the above default interpretation rules. Where used, they provide additional information regarding:

their qualified status:

“QCStatement” (" http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCStatement ") meaning the identified certificates are qualified under Directive 1999/93/EC or under Regulation (EU) No 910/2014; or

“NotQualified” (" http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/NotQualified ") meaning the identified certificates are not to be considered as qualified.

the nature of their qualification:

“QCForESig” (" http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForESig ") meaning the identified certificates, when claimed or stated as qualified, are qualified certificates for electronic signature under Regulation (EU) No 910/2014;

“QCForESeal” (" http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForESeal ") meaning the identified certificates, when claimed or stated as qualified, are qualified certificates for electronic seal under Regulation (EU) No 910/2014; or

“QCForWSA” (" http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForWSA ") meaning the identified certificates, when claimed or stated as qualified, are qualified certificates for website authentication under Regulation (EU) No 910/2014.

whether or not the private key resides in a qualified signature or qualified seal creation device (QSCD) and the nature thereof:

“QCWithQSCD” (" http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithQSCD ") meaning the identified certificates, when claimed or stated as qualified, have their private key residing in a QSCD;

“QCNoQSCD” (" http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCNoQSCD ") meaning the identified certificates, when claimed or stated as qualified, have not their private key residing in a QSCD;

“QCQSCDStatusAsInCert” (" http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCQSCDStatusAsInCert ") meaning the identified certificates, when claimed or stated as qualified, do contain proper machine processable information about whether or not their private key is residing in a QSCD; or

“QCQSCDManagedOnBehalf” (" http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCQSCDManagedOnBehalf ") meaning the identified certificates, when they are claimed or stated as qualified, have their private key is residing in a QSCD for which the generation and management of that private key is done by a qualified TSP on behalf of the entity whose identity is certified in the certificate;

Restricted to the context of certificates issued under Directive 1999/93/EC, the following qualifiers are defined and provide additional information regarding:

whether or not the private key resides in a secure signature creation device (SSCD):

“QCWithSSCD” (" http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCWithSSCD ") meaning the identified certificates, when claimed or stated as qualified, have their private key residing in an SSCD;

“QCNoSSCD” (" http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCNoSSCD ") meaning the identified certificates, when claimed or stated as qualified, do not have their private key residing in an SSCD; or

“QCSSCDStatusAsInCert” (" http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCSSCDStatusAsInCert ") meaning the identified certificates, when claimed or stated as qualified, do contain proper machine processable information about whether or not their private key is residing in an SSCD.

the issuance to a Legal Person:

“QCForLegalPerson” (" http://uri.etsi.org/TrstSvc/TrustedList/SvcInfoExt/QCForLegalPerson ") meaning the identified certificates, when claimed or stated as qualified, are issued to a Legal Person under Directive 1999/93/EC.

Note:

The information provided in the trusted list is to be considered as accurate meaning that the certificate is not to be considered as qualified if the end-entity certificate does not follow any of the default rules defined above, and:

if no “Sie” “Qualifications Extension” information is present for the trust anchor CA/QC corresponding service entry to qualify the certificate with a “QCStatement” qualifier, or

a “Sie” “Qualifications Extension” information is present for the trust anchor CA/QC corresponding service entry to qualify the certificate with a “NotQualified” qualifier.

C.3    Trust anchors

“Service digital identifiers” are to be used as Trust Anchors in the context of validating electronic signatures or seals for which signer’s or seal creator’s certificate is to be validated against information in the trusted list, hence only the public key and the associated subject name are needed as Trust Anchor information. When more than one certificate represents the public key identifying the service, they are to be considered as Trust Anchor certificates conveying identical information with regard to the information strictly required as Trust Anchor information.

C.4    General rule for the interpretation of trust service entries

The general rule for interpretation of any “Sti” type entry, possibly further specified through a “Sie” “additionalServiceInformation”, not corresponding to qualified trust services is that, for that “Sti” identified service type, and possibly in combination with a “Sie” “additionalServiceInformation” URI, the listed service named according to the “Service name” field value and uniquely identified by the “Service digital identity” field value has the current approval status according to the “Service current status” field value as from the date indicated in the “Current status starting date and time”.

Specific interpretation rules for any additional information with regard to a listed service (e.g. “Service information extensions” field) may be found, when applicable, in the Member State specific URI as part of the present “Scheme type/community/rules” field.

Please refer to the implementing acts adopted pursuant to Article 22(5) of Regulation (EU) No 910/2014 for further details on the specifications of the fields of the Member States’ trusted lists.’;

(2)

URI, ki je specifičen za zanesljivi seznam vsake države članice, z napotilom na opisno besedilo, ki velja za zanesljivi seznam te države članice:

(a)

http://uri.etsi.org/TrstSvc/TrustedList/schemerules/CC, pri čemer je CC koda države ISO 3166-1 alpha-2, ki se uporablja v polju ‚Država sheme‘ (razdelek 5.3.10),

podatki o tem, kje lahko uporabniki najdejo posebne politike/pravila za zadevno državo članico, v skladu s katerimi se storitve zaupanja v zanesljivem seznamu ocenjujejo v skladu s sistemom nadzora države članice in, kadar je to primerno, shemo potrjevanja,

podatki o tem, kje lahko uporabniki najdejo posebni opis za zadevno državo članico glede načina uporabe in razlage vsebine zanesljivega seznama v zvezi z navedenimi nekvalificiranimi storitvami zaupanja in/ali nacionalno opredeljenimi storitvami zaupanja. Ta opis se lahko uporabi za navedbo morebitne razdrobljenosti v nacionalnih sistemih potrjevanja v zvezi s ponudniki storitev certificiranja / ponudniki storitev zaupanja, ki ne izdajajo kvalificiranih potrdil, in kako se v ta namen uporabljata polji ‚URI za opredelitev storitev sheme‘ (razdelek 5.5.6) in ‚Razširitve informacij o storitvah‘ (razdelek 5.5.9).

(b)

Države članice lahko razširijo naveden poseben URI za državo članico, tako da opredelijo in uporabijo dodatne URI (tj. URI, opredeljene na podlagi tega hierarhičnega posebnega URI).“;

(3)

v poglavju II se za oddelkom z naslovom „Trenutni status storitve (razdelek 5.5.4)“ doda naslednji oddelek:

Element podpis (razdelek B.1), Splošno (razdelek B.1.0)

Ta razdelek je obvezen in v skladu s specifikacijami iz razdelka B.1.0 TS 119 612, kjer se točka 2 nadomesti z naslednjim:

‚2)

Njegov element ds:SignedInfo vsebuje element ds:Reference z atributom URI, nastavljenim na prazen niz (tj. URI="", tako da se nanaša na cel dokument. Navedeni element ds:Reference izpolnjuje naslednji zahtevi:

(a)

vsebuje samo en element ds:Transforms;

(b)

navedeni element ds:Transforms vsebuje dva elementa ds:Transform. Prvi je tisti, katerega atribut Algorithm označuje ovito (enveloped) transformacijo z vrednostjo: "http://www.w3.org/2000/09/xmldsig#enveloped-signature". Drugi je tisti, katerega atribut Algorithm nalaga izvedbo ekskluzivne kanonikalizacije "http://www.w3.org/2001/10/xml-exc-c14n#".‘.“.


ELI: http://data.europa.eu/eli/dec_impl/2025/2164/oj

ISSN 1977-0804 (electronic edition)


Top