Signature creation data (SCD)
Signature creation data (SCD) is the private key used to sign; eIDAS requires sole control and, for qualified signing, a certified QSCD.
Signature creation data (SCD) - also called electronic signature creation data, the full eIDAS term - is the unique data, in practice the private cryptographic key, that a signatory uses to create an electronic signature. Its counterpart, the signature validation data (the public key in the certificate), lets anyone verify the result. Do not confuse the data (SCD) with the signature creation device that holds it, such as a QSCD. Legal persons use the equivalent electronic seal creation data to create an electronic seal.
For simple electronic signatures, this key may sit in ordinary software. Advanced electronic signatures already require that the data be used under the signatory's sole control. For qualified signatures, eIDAS raises the bar further: the data must reside in a certified QSCD, whose confidentiality is guaranteed by certified means. Where the QSCD is managed remotely, as with remote signing, Article 29a allows a QTSP to generate and manage the data on the signatory's behalf, typically in an HSM configuration itself certified as a QSCD under EN 419241-2.
By December 2026, the EUDI Wallet must also be able to create qualified signatures, under eIDAS Article 5a(g), with the signature creation data held in a WSCD (wallet secure cryptographic device) rather than at a QTSP; a WSCD can itself be a local secure element in the device or a remote instance, such as an HSM hosted by the wallet provider.