The updated eIDAS regulation (eIDAS 2.0), particularly Commission Implementing Regulation (CIR) 2025/2160, fundamentally changes the legal status of digitally sealed data. For Digital Product Passport implementations, this creates a new compliance paradigm.
Understanding Qualified Electronic Seals
A Qualified Electronic Seal (QES) is a cryptographic mechanism that provides legal presumption of data integrity and authentic origin. Unlike ordinary digital signatures, a QES creates an irrebuttable presumption of integrity in legal proceedings—the data is presumed unaltered unless proven otherwise.
Why This Matters for DPP
When sustainability data is sealed with a QES, market surveillance authorities can rely on that data without requiring extensive manual verification. This dramatically reduces the compliance burden on both manufacturers and regulators.
Technical Requirements
To achieve QES status, seals must be created using a qualified certificate issued by a Qualified Trust Service Provider (QTSP). The cryptographic keys must be stored in a Qualified Seal Creation Device (QSCD), typically a hardware security module (HSM) that meets FIPS 140-2 Level 3 or Common Criteria EAL 4+ standards.
Implementation Considerations
Many manufacturers assume that QES requirements necessitate expensive infrastructure investments. However, seal-as-a-service offerings from QTSPs can provide compliant sealing capabilities without capital expenditure on HSMs.
Cryptar's Approach
Our protocol integrates with multiple European QTSPs, allowing manufacturers to obtain qualified seals for their DPP data through simple API calls. The resulting evidence files contain both the sealed data and the complete validation chain, ensuring long-term verifiability even if the original QTSP ceases operations.
As eIDAS 2.0 provisions take full effect, manufacturers with QES-backed DPP implementations will have a significant advantage in demonstrating compliance and building trust with regulators and customers alike.
