Qualified electronic timestamp: definition, legal effect, and eIDAS Articles 41 and 42

A qualified electronic timestamp is a cryptographic record that binds a date and time to data, issued by a qualified trust service provider listed on an EU trusted list. Under Article 41 of the eIDAS Regulation it carries a legal presumption that the date and time are accurate and the data unaltered.

Reference material on Regulation (EU) No 910/2014. Last reviewed .

Key points

  • A qualified electronic timestamp is issued by a qualified trust service provider listed on an EU trusted list.
  • Article 41(2) gives it a presumption of the accuracy of the date and time, and of the integrity of the data bound to them.
  • The presumption shifts the burden of proof to whoever disputes the timestamp. It is rebuttable, not absolute.
  • Article 42(1) sets three requirements: detectable alteration, a UTC-linked time source, and an advanced signature or seal of the provider.
  • Recognition is automatic across EU member states under Article 41(3), and extends to the EEA states through the trusted list framework.
  • A qualified timestamp establishes existence and integrity at a point in time. It does not establish authorship, ownership, or who submitted the data.
On this page
  1. What is a qualified electronic timestamp under eIDAS?
  2. What does eIDAS Article 41 say about qualified electronic timestamps?
  3. What is the Article 41 presumption of accuracy?
  4. What are the Article 42 requirements for a qualified electronic timestamp?
  5. How is a qualified electronic timestamp different from an ordinary timestamp?
  6. Where is a qualified electronic timestamp legally recognised?
  7. What is an electronic time stamp?
  8. What is an eIDAS certificate?
  9. How do I add a qualified timestamp to a PDF signature?
  10. How long does a qualified electronic timestamp remain valid?
  11. What did eIDAS 2 change for qualified timestamps?
  12. How a qualified electronic timestamp is produced
  13. How to check that a provider is qualified
  14. What a qualified electronic timestamp does not establish

What is a qualified electronic timestamp under eIDAS?

A qualified electronic timestamp is an electronic timestamp that meets the requirements of Article 42 of the eIDAS Regulation and is issued by a qualified trust service provider listed on an EU trusted list. It binds a date and time to data in a way that makes later alteration detectable.

The qualification is what separates it from an ordinary timestamp. A date recorded by a computer, an email header or a version control system may be useful, but only a qualified electronic timestamp carries the legal presumption set out in Article 41.

What does eIDAS Article 41 say about qualified electronic timestamps?

Article 41 has three paragraphs. Article 41(1): “An electronic time stamp shall not be denied legal effect and admissibility as evidence in legal proceedings solely on the grounds that it is in an electronic form or that it does not meet the requirements of the qualified electronic time stamp.”

Article 41(2): “A qualified electronic time stamp shall enjoy the presumption of the accuracy of the date and the time it indicates and the integrity of the data to which the date and time are bound.”

Article 41(3): “A qualified electronic time stamp issued in one Member State shall be recognised as a qualified electronic time stamp in all Member States.”

What is the Article 41 presumption of accuracy?

It is a shift in the burden of proof. A party relying on a qualified electronic timestamp does not have to prove that the date and time are correct, or that the data has not changed since. Those things are presumed.

A party disputing the timestamp must prove otherwise. That is a substantially harder position to be in, and it is the practical value of qualification.

The presumption is rebuttable. It shifts who must prove what; it does not make a timestamp incapable of being challenged.

What are the Article 42 requirements for a qualified electronic timestamp?

Article 42(1) sets three requirements. A qualified electronic timestamp must bind the date and time to data in such a manner as to reasonably preclude the possibility of the data being changed undetectably; it must be based on an accurate time source linked to Coordinated Universal Time; and it must be signed using an advanced electronic signature or sealed with an advanced electronic seal of the qualified trust service provider, or by some equivalent method.

Three, not four. Being issued by a qualified trust service provider is not a fourth requirement of Article 42(1) — it follows from the definition of a qualified trust service.

Article 42(2) is separate. It allows the Commission to establish reference numbers of standards for binding date and time to data and for accurate time sources, and provides that compliance with Article 42(1) is presumed where those standards are met.

How is a qualified electronic timestamp different from an ordinary timestamp?

An ordinary electronic timestamp records a date and time. A qualified electronic timestamp does the same, but is issued by a provider that has been assessed and listed as qualified, and meets the Article 42 requirements.

The difference is legal rather than technical. Article 41(1) makes clear that an ordinary electronic timestamp is not denied legal effect or admissibility merely for being electronic or unqualified. It simply does not carry the Article 41(2) presumption, so its accuracy has to be established rather than assumed.

Where is a qualified electronic timestamp legally recognised?

Within the European Union, Article 41(3) provides that a qualified electronic timestamp issued in one Member State is recognised as such in all Member States. The Regulation applies directly and requires no national implementation.

The trusted list framework also extends to the EEA states. Norway, Iceland and Liechtenstein each publish a national trusted list referenced from the European Commission’s List of Trusted Lists, with recognition arising through the EEA Agreement rather than the Regulation itself.

The United Kingdom retains an equivalent domestic framework, including the presumption. Since departure from the EU, however, UK and EU qualified timestamps are no longer mutually recognised as qualified between the two regimes, which matters where evidence may be used on both sides.

The United States has no equivalent statutory presumption. A qualified timestamp is assessed under ordinary rules of evidence, where it remains strong technical proof but carries no automatic shift in the burden of proof.

What is an electronic time stamp?

The eIDAS Regulation defines an electronic timestamp as data in electronic form which binds other data in electronic form to a particular time, establishing evidence that the latter data existed at that time.

That definition covers both qualified and unqualified timestamps. The qualified variety is the subset meeting the Article 42 requirements and issued by a listed provider.

What is an eIDAS certificate?

There is no single thing called an eIDAS certificate. The Regulation defines several distinct qualified certificates: qualified certificates for electronic signatures, for electronic seals, and for website authentication. Each supports a different trust service and carries different requirements.

A qualified electronic timestamp involves a certificate too — the one used by the trust service provider to sign the timestamp token — but it is the provider’s certificate, not one issued to the person requesting the timestamp.

How do I add a qualified timestamp to a PDF signature?

Most signing applications allow a timestamp server to be configured. The application is given the address of a timestamp authority, and thereafter submits the hash of each signature to that authority and embeds the returned token in the document.

For the resulting timestamp to be qualified, the authority must be a qualified trust service provider listed on an EU trusted list for the qualified timestamping service. Configuring an arbitrary public timestamp server produces a valid timestamp, but not a qualified one.

How long does a qualified electronic timestamp remain valid?

There is no fixed period set by the Regulation. A qualified electronic timestamp remains verifiable for as long as the cryptographic algorithms it relies on remain sound and sufficient validation data has been preserved to check the signing certificate and its status.

Figures such as “valid for twenty years” are sometimes quoted. They reflect particular provider practices or certificate lifetimes rather than anything in eIDAS, and should not be treated as a property of qualification itself.

For long-term preservation, the recognised approach is re-timestamping before the existing cryptographic protection weakens, together with retention of the validation material, as addressed in ETSI EN 319 421.

What did eIDAS 2 change for qualified timestamps?

Regulation (EU) 2024/1183 amended the eIDAS Regulation; the consolidated text is dated 18 October 2024. Articles 41 and 42 remain substantively as originally drafted, so the presumption and the requirements are unchanged.

The broader amendment introduces the European Digital Identity Wallet and further trust services, and moves the applicable technical standards from a voluntary footing toward binding effect through implementing acts.

How a qualified electronic timestamp is produced

The data is first reduced to a cryptographic hash, commonly SHA-256. That hash alone is sent to the provider’s timestamping authority under the RFC 3161 protocol. The document itself is never transmitted, so the provider learns nothing about its contents.

The authority records the hash against a time drawn from a source linked to Coordinated Universal Time, signs the two together, and returns a timestamp token. Anyone holding the original data and the token can verify the pairing independently, without contacting the provider.

The relevant technical standards are RFC 3161 for the protocol itself, with ETSI EN 319 421 and EN 319 422 covering the policy requirements for providers issuing timestamps and the profile of the tokens they issue.

How to check that a provider is qualified

Each member state publishes a national trusted list of its qualified trust service providers. The European Commission publishes a List of Trusted Lists pointing to all of them. A provider must appear on the relevant list specifically for the qualified timestamping service; being listed for another service is not sufficient.

Status can be granted, suspended or withdrawn over time, and the lists record when each status took effect. The question that matters when assessing a timestamp is what the status was at the moment of stamping, not what it is today. A service withdrawn later does not retroactively unqualify the timestamps it issued while granted, and a service granted later does not retroactively qualify those issued before.

What a qualified electronic timestamp does not establish

A qualified electronic timestamp proves that specific data existed in a specific form at a specific moment, and that it has not changed since. That is the whole of what it proves.

It does not establish who created the data, who owns it, or who submitted it for stamping. It says nothing about the meaning of the content, and nothing about whether the data is an original or a copy. Establishing authorship requires separate evidence, such as a qualified electronic signature or documentary record.

Further reading

The Regulation is published on EUR-Lex, and the amending Regulation (EU) 2024/1183 on EUR-Lex. Provlyn applies qualified eIDAS timestamps as an optional layer on individual deposits — see how eIDAS works on Provlyn or the eIDAS section of the FAQ.

For how a qualified timestamp compares with anchoring a hash to a public blockchain, see blockchain timestamp or qualified timestamp.

This page is reference material about the eIDAS Regulation. It is not legal advice, and Provlyn is not a qualified validation service within the meaning of Article 33.