Time-stamping authority (TSA)

A TSA (Time-Stamping Authority) issues electronic timestamps binding a document hash to a moment in time, under eIDAS and RFC 3161 standards.

A TSA (Time-Stamping Authority) is the service, operated by a trust service provider, that issues electronic timestamps: it receives a hash of a document or data set and returns a signed token binding that hash to a specific point in time, without ever seeing the underlying content. The protocol is standardised in IETF RFC 3161 and further profiled by ETSI EN 319 421 and EN 319 422, with Commission Implementing Regulation (EU) 2025/1929 of 29 September 2025 laying down binding rules under eIDAS for binding date and time to data; the TSA relies on a time source traceable to UTC and signs each timestamp token with a key generally protected in a Hardware Security Module (HSM).

A TSA operated by a QTSP can issue qualified electronic timestamps under eIDAS: these carry a legal presumption of accuracy for the date and time they indicate, and the QTSP's own certificate is listed on the EU Trusted List. TSAs matter well beyond signing: repeated timestamping is the mechanism behind long-term validation, keeping signatures and seals verifiable even after certificates expire or cryptographic algorithms weaken.

Frequently asked questions

Back to glossary