Time-stamping authority (TSA)

A TSA (Time-Stamping Authority) issues electronic timestamps binding a document hash to a moment in time, under eIDAS and RFC 3161 standards.

A TSA (Time-Stamping Authority) is the service, operated by a trust service provider, that issues electronic timestamps: it receives a hash of a document or data set and returns a signed token binding that hash to a specific point in time, without ever seeing the underlying content. The protocol is standardised in IETF RFC 3161 and further profiled by ETSI EN 319 421 and EN 319 422; the TSA relies on a time source traceable to UTC and signs each timestamp token with a key generally protected in a Hardware Security Module (HSM).

A TSA operated by a QTSP can issue qualified electronic timestamps under eIDAS: these carry a legal presumption of accuracy for the date and time they indicate, and the QTSP's own certificate is listed on the EU Trusted List. TSAs matter well beyond signing: repeated timestamping is the mechanism behind long-term validation, keeping signatures and seals verifiable even after certificates expire or cryptographic algorithms weaken.

Frequently asked questions

Back to glossary