Fourthline is a Qualified Trust Service Provider (QTSP)

Fourthline is a Qualified Trust Service Provider (QTSP)

Fourthline Trust Services AB, part of Fourthline, is a Qualified Trust Service Provider under eIDAS. Supervised by the Swedish Post and Telecom Authority and listed on the EU Trusted List, it issues qualified certificates for electronic signatures. 

Fourthline Trust Services AB, part of Fourthline, is a Qualified Trust Service Provider under eIDAS. Supervised by the Swedish Post and Telecom Authority and listed on the EU Trusted List, it issues qualified certificates for electronic signatures. 

What our QTSP status covers and what it means for you 

What our QTSP status covers and what it means for you 

Qualified status is granted per service.

Here's exactly what we hold: 

Qualified status is granted per service. Here's exactly what we hold: 

Fourthline Trust Services AB

Qualified Service

Granted

Qualified certificates for electronic signature (QCert for ESig)

21 August 2026

Supervisory body: Swedish Post and Telecom Authority

How do these work in a QES flow?

How do these work in a QES flow?

A customer proves their identity. On the strength of that check, we issue them a qualified certificate. They sign. A qualified time stamp fixes the moment. 

A customer proves their identity. On the strength of that check, we issue them a qualified certificate. They sign. A qualified time stamp fixes the moment. 

The certificate makes the signature theirs. It binds the verified identity to the cryptographic key used to sign, so the signature can't be separated from the person who made it. That’s what gives the signature the same legal standing as a handwritten one, in all 27 member states.

The certificate makes the signature theirs. It binds the verified identity to the cryptographic key used to sign, so the signature can't be separated from the person who made it. That’s what gives the signature the same legal standing as a handwritten one, in all 27 member states.

A customer completes identity verification. Fourthline Trust Services AB issues a qualified certificate linking the verified identity to the signature validation data. The signature is created using a qualified signature creation device. Together, these elements form a Qualified Electronic Signature, which has the equivalent legal effect of a handwritten signature across the EU. The signing flow also includes timestamping to provide evidence of when the signature was created and to support validation of the signed data. 

A customer completes identity verification. Fourthline Trust Services AB issues a qualified certificate linking the verified identity to the signature validation data. The signature is created using a qualified signature creation device. Together, these elements form a Qualified Electronic Signature, which has the equivalent legal effect of a handwritten signature across the EU. The signing flow also includes timestamping to provide evidence of when the signature was created and to support validation of the signed data. 

New eIDAS requirements for QTSPs, explained 

New eIDAS requirements for QTSPs, explained 

eIDAS 2.0 expanded what counts as a qualified service and tightened how providers are supervised. Two of those changes directly affect who can issue qualified certificates. The first tightened the technical rules for remote signing systems: the signing devices, how signers are authenticated, and what must be recorded. The second rewrote how providers check identity before issuing a qualified certificate. It defines two levels of identity proofing: 

eIDAS 2.0 expanded what counts as a qualified service and tightened how providers are supervised. Two of those changes directly affect who can issue qualified certificates. The first tightened the technical rules for remote signing systems: the signing devices, how signers are authenticated, and what must be recorded. The second rewrote how providers check identity before issuing a qualified certificate. It defines two levels of identity proofing: 

ETSI TS 119 461 defines Baseline and Extended levels of identity proofing. Under the new requirements, identity verification used for issuing qualified certificates must meet Extended LoIP. Extended LoIP may be achieved through approved in-person, electronic identification, qualified-certificate, hybrid or fully automated digital-document methods, depending on the evidence and controls used. 

ETSI TS 119 461 defines Baseline and Extended levels of identity proofing. Under the new requirements, identity verification used for issuing qualified certificates must meet Extended LoIP. Extended LoIP may be achieved through approved in-person, electronic identification, qualified-certificate, hybrid or fully automated digital-document methods, depending on the evidence and controls used. 

Qualified certificates require Extended. The standard also sets minimum performance levels for biometric checks, and defences against fake presentations and injected video.

Qualified certificates require Extended. The standard also sets minimum performance levels for biometric checks, and defences against fake presentations and injected video.

THE DATES THAT MATTER

Date

What changes

10 July 2027

The EU Anti-Money Laundering Regulation (AMLR) applies

19 August 2027

The new eiD identity verification requirements for issuing qualified certificates apply

Why a Qualified Signature reaches customers a national eID and EUDI wallet can't 

Why a Qualified Signature reaches customers a national eID and EUDI wallet can't 

From July 2027, AMLR sets how regulated institutions verify customers across the EU. It allows two broad approaches: data necessary for identity verification are obtained through either submission of government-issued identity documents, or electronic identification means and relevant trust services under eIDAS (the eIDAS toolkit).

From July 2027, AMLR sets how regulated institutions verify customers across the EU. It allows two broad approaches: data necessary for identity verification are obtained through either submission of government-issued identity documents, or electronic identification means and relevant trust services under eIDAS (the eIDAS toolkit).

The eIDAS toolkit contains two different things, which often get mixed up: 

The eIDAS toolkit contains two different things, which often get mixed up: 

Electronic identification

Electronic identification

A national eID, or the EUDI Wallet

A national eID, or the EUDI Wallet

Qualified Trust Services

Qualified Trust Services

A qualified electronic signature

A qualified electronic signature

The difference matters commercially. Electronic identification only works if your customer has a national credential and uses it. A qualified signature doesn't need one. That distinction decides how much of your customer base each route actually reaches. 


eID adoption varies dramatically across the EU. In Denmark, Finland, the Netherlands it’s above 90%, whereas in Germany, Slovakia, Bulgaria and Romania, it's 15% or less. Electronic identification is voluntary, your customer can simply decline. And even when they don't, an eID or EUDI wallet won't always return every data point a regulated onboarding needs. 


A qualified electronic signature is the qualified trust service route. AMLR allows identity verification using documents and reliable independent sources, or through certain eIDAS electronic-identification and relevant qualified trust-service mechanisms. QES can support the eIDAS route, but it does not automatically satisfy every CDD requirement or every institution’s risk-based policy. Unlike national eID and EUDI Wallet routes, a QES flow does not require the customer to already hold or actively use a national electronic identity. This can allow regulated businesses to serve a broader customer population through a consistent cross-border flow, subject to supported identity documents, markets and risk controls. 

The difference matters commercially. Electronic identification only works if your customer has a national credential and uses it. A qualified signature doesn't need one. That distinction decides how much of your customer base each route actually reaches. 


eID adoption varies dramatically across the EU. In Denmark, Finland, the Netherlands it’s above 90%, whereas in Germany, Slovakia, Bulgaria and Romania, it's 15% or less. Electronic identification is voluntary, your customer can simply decline. And even when they don't, an eID or EUDI wallet won't always return every data point a regulated onboarding needs. 


A qualified electronic signature is the qualified trust service route. AMLR allows identity verification using documents and reliable independent sources, or through certain eIDAS electronic-identification and relevant qualified trust-service mechanisms. QES can support the eIDAS route, but it does not automatically satisfy every CDD requirement or every institution’s risk-based policy. Unlike national eID and EUDI Wallet routes, a QES flow does not require the customer to already hold or actively use a national electronic identity. This can allow regulated businesses to serve a broader customer population through a consistent cross-border flow, subject to supported identity documents, markets and risk controls. 

The strongest identity and signing flows are those where accountability is clear from end to end. By becoming a QTSP, Fourthline can combine identity verification and qualified-certificate issuance in one integrated flow, under our own qualification and audit framework. National eIDs and the EUDI Wallet will be important channels, while QES provides an additional route that does not depend on customers already using a national electronic identity.

The strongest identity and signing flows are those where accountability is clear from end to end. By becoming a QTSP, Fourthline can combine identity verification and qualified-certificate issuance in one integrated flow, under our own qualification and audit framework. National eIDs and the EUDI Wallet will be important channels, while QES provides an additional route that does not depend on customers already using a national electronic identity.

Mustafa Kucukaytekin

Mustafa Kucukaytekin

VP of Security & Infrastructure at Fourthline

VP of Security & Infrastructure at Fourthline

No SMS code at signing, here's why we don't need one 

No SMS code at signing, here's why we don't need one 

Most QES flows end with an SMS code. Not because it adds security, but because the company issuing the certificate usually isn't the one that verified the identity, so a code has to connect the two. 


Fourthline does both. We verify the customer and we issue the certificate, so the signature is tied directly to the identity check. No code to send, no code to wait for, and that matters for conversion. An SMS that arrives late or goes to an old number costs you a customer you already paid to acquire. Every signature still comes with full proof: the qualified certificate, the identity check behind it, a qualified timestamp, and an evidence file on request.

Most QES flows end with an SMS code. Not because it adds security, but because the company issuing the certificate usually isn't the one that verified the identity, so a code has to connect the two. 


Fourthline does both. We verify the customer and we issue the certificate, so the signature is tied directly to the identity check. No code to send, no code to wait for, and that matters for conversion. An SMS that arrives late or goes to an old number costs you a customer you already paid to acquire. Every signature still comes with full proof: the qualified certificate, the identity check behind it, a qualified timestamp, and an evidence file on request.

Trust, certified at every step 

Trust, certified at every step 

A qualified signature depends on three things: the identity check, the certificate issued from it, and the service that creates the signature. Each has its own European standard, and each is audited by an accredited body. We hold all of them. 

A qualified signature depends on three things: the identity check, the certificate issued from it, and the service that creates the signature. Each has its own European standard, and each is audited by an accredited body. We hold all of them. 

Identity proofing

Proving the person is real, and who they claim to be

Proving the person is real, and who they claim to be

Signing service

Creating and protecting the signature itself

Creating and protecting the signature itself

Certificate issuance

Issuing the qualified certificate that gives the signature legal force 

Issuing the qualified certificate that gives the signature legal force 

Security and controls

Protecting the systems and data behind all three 

Protecting the systems and data behind all three 

See what changes for your onboarding 

See what changes for your onboarding 

Tell us which markets you operate in and how you verify customers today. We'll show you where a qualified signature fits, where a national eID or the wallet genuinely performs, and what to build first. 

Tell us which markets you operate in and how you verify customers today. We'll show you where a qualified signature fits, where a national eID or the wallet genuinely performs, and what to build first. 

FREQUENTLY ASKED QUESTIONS

Is Fourthline a Qualified Trust Service Provider (QTSP), or does it use one?

Why is the qualification held by a Swedish entity?

What is the difference between QTSP and Qualified Electronic Signature (QES)?

Do I need a QTSP to comply with AMLR?

How often is a QTSP audited?

Can I verify Fourthline's qualified status independently?

Worth reading

Worth reading

Learn more about qualified trust services, AMLR compliance, and the future of digital identity. 

Learn more about qualified trust services, AMLR compliance, and the future of digital identity. 

Fourthline Trust Services AB, Östermalmstorg 1 114 42 Stockholm / Sweden 559555-2505

Fourthline Trust Services AB

Östermalmstorg 1 114 42 Stockholm / Sweden

559555-2505

Copyright © 2026 - Fourthline B.V. - All rights reserved.