Conformity assessment report
A conformity assessment report is the audit evidence a CAB issues to prove a trust service provider still meets eIDAS requirements.
A conformity assessment report is the formal document a conformity assessment body (CAB) produces after auditing a trust service provider against the eIDAS requirements and the relevant ETSI standards (chiefly EN 319 401 and the service-specific policy requirements). It is the evidence that turns a provider's own claim of compliance into something a supervisory body can check and rely on. Commission Implementing Regulation (EU) 2025/2162 of 27 October 2025, adopted under Article 20(4) and Article 21(4) of eIDAS, lays down the report format in its Annex III and requires the CAB itself to be accredited against ETSI EN 319 403-1.
Two eIDAS provisions call for it. A provider seeking qualified status for the first time submits one together with its notification, under Article 21; the report must confirm that the provider fulfils both the eIDAS requirements and the cybersecurity risk-management requirements of Article 21 of the NIS2 Directive. A provider that already holds qualified status must be re-audited at least every 24 months under Article 20, and must forward the resulting report to its supervisory body within three working days of receiving it; that report likewise confirms compliance with both eIDAS and NIS2 Article 21. In the Netherlands that supervisory body is the Rijksinspectie Digitale Infrastructuur, which uses the report to decide whether to grant, maintain or withdraw qualified status and to update the EU Trusted List entry accordingly.