Service Finder
Certification service provider - voluntary accreditation
Service Description
Certification service providers can apply for accreditation from the competent authority if they can prove that they meet the requirements of the Signature Act and the Signature Ordinance.
Accredited certification service providers receive a quality mark from the competent authority. They may call themselves accredited certification service providers and refer to the proven security in legal and business transactions.
Note: The application for voluntary accreditation is also considered to be notification of the operation of a certification service if the requirements specified in the Signature Act and the Signature Ordinance are met.
Process flow
Contact a testing and confirmation body at an early stage. They can advise you in advance on any questions you may have. Have them check and confirm that the requirements have been met. You can freely select the testing and confirmation body from the above list on the website of the Federal Network Agency.
After the fulfillment of the requirements has been checked and confirmed by a testing and confirmation body, you must submit the application for accreditation in writing to the competent body. It must be signed by hand or submitted using a document with a qualified electronic signature. It must contain the name and address of the certification service provider and the names of the legal representatives.
Who should I contact?
Contact the Federal Network Agency.
Which documents are required?
In addition to the application for accreditation, you must submit the following documents:
- For proof of personal reliability:
- If you have your place of residence in Germany, you will need:
- Certificates of good conduct for submission to an authority in accordance with Section 30 (5) of the Federal Central Register Act for the certification service provider (e.g. head of the certification service provider's operations and his representatives) and for the legal representatives of the certification service provider.
- If you are resident in another EU country or in a contracting state of the Agreement on the European Economic Area, you will need documents from your home country that have an equivalent function or that prove that the requirement for personal reliability to perform the desired service is met.
- If you have your place of residence in Germany, you will need:
- For proof of entrepreneurial legal form:
- If you have your company headquarters in Germany, you will require:
- In the case of registered companies: Excerpt from the commercial register; in other cases, if applicable, a copy of the articles of association (e.g., in the case of a civil-law partnership (GbR)) or other evidence.
- If you have your company's registered office in another EU country or in a contracting state to the Agreement on the European Economic Area, you will need comparable documents from the country in which you have your registered office proving the legal form.
- If you have your company headquarters in Germany, you will require:
- Documents proving the required technical, administrative and legal expertise
- Security concept with the following points:
- Description of all required technical, structural and organizational security measures and their suitability
- Overview of the products used for qualified electronic signatures with corresponding confirmations in accordance with the Signature Act
- Overview of the structural and procedural organization as well as certification activities
- Precautions and measures for securing and maintaining operations, especially in the event of emergencies
- Procedures for assessing and ensuring the reliability of the personnel deployed
- Assessment and evaluation of remaining safety risks
- Proof of coverage (e.g., liability insurance or comparable indemnification/warranty obligation of an insurance company/credit institution authorized to do business in the area of application of the German Signature Act, in another member state of the European Union, or in another state party to the Agreement on the European Economic Area) that meets the requirements of § 12 of the German Signature Act and § 9 of the Signature Ordinance
- If applicable, proof of the transfer of tasks under the Signature Act and the Signature Ordinance to third parties (e.g. contracts)
- Test and confirmation report of the testing and confirmation body including confirmation for the implementation of security concepts
If you wish to delegate tasks under the Signature Act and the Signature Ordinance to third parties, they must be included in your security concept accordingly.
When checking your personal reliability, the authorizing authority may, in individual cases, request further documents in addition to those listed that are suitable for making a statement about your personal reliability as an applicant.
What are the fees?
The competent body charges fees and expenses for processing the application for accreditation, the amount of which depends on the time spent. Ask the competent body about the possible costs.
Legal basis
What else should I know?
Accredited certification service providers must have a testing and confirmation body check and confirm at least every three years that the requirements of the Signature Act and the Signature Ordinance continue to be met in full. In addition, the verification and confirmation must be repeated after security-relevant changes.
You must submit the verification and confirmation report and the confirmation to the competent authority without being asked to do so.
Accredited certification service providers
- must use tested and confirmed products for qualified electronic signatures for their certification activities,
- may only issue qualified certificates to persons who have demonstrably tested and confirmed signature creation devices, and
- must inform the signature key holder about tested and confirmed signature application components.
Tip: More detailed information on confirmed products for qualified electronic signatures can be found on the Federal Network Agency's website in the "Publications" section under "Products for qualified electronic signatures", subsection "Confirmations".
For further requirements or obligations of a certification service provider that are not described in detail in this brief list (e.g., identity verification, documentation, revocation, obligation to provide information, maintenance of a certificate directory), please refer to the Signature Act and the Signature Ordinance.
Author
The text was automatically translated based on the German content per DeepL.
Source: Zuständigkeitsfinder Thüringen (Linie6PLus)
No competent authority found
Please enter your location.