Qualified certificate
A qualified certificate is the eIDAS PKI certificate underpinning a QES, giving electronic signatures and seals the highest level of legal assurance.
A qualified certificate is a PKI certificate issued by a QTSP that meets the eIDAS annexes (I for signatures, III for seals, IV for website authentication) and underpins a qualified electronic signature (QES) or seal. It binds a verified identity to a public key and states that it is qualified. Certificates for signatures are issued only to natural persons; those for seals are issued to legal persons, while a website authentication certificate can go to either: Annex IV covers a natural person (name or a clearly marked pseudonym) as well as a legal person, even if in practice organisations are the usual holders. The identity is established through identity verification.
Qualified certificates for signatures underpin a QES together with a QSCD that holds the signing key; those for seals underpin qualified seals. Their issuance, management and revocation follow ETSI EN 319 411 policies; status is checked via CRL or OCSP. A certificate only counts as qualified if its issuing QTSP appears on the EU Trusted List.