Renew or activate signature

Electronic signature activation

How to activate NEW
Certum's electronic signature?

Activate a Signature

Electronic signature renewal

Renewal of Certum's e-signature
step by step

Renew a Signature

2026-09-24

How do trust services support cybersecurity and NIS2 compliance?

From this article, you will learn:

  • What are trust services? Learn about the main types of qualified trust services and their importance for an organization’s digital security.
  • NIS2 – a new approach to cybersecurity. Find out what risk management and security requirements NIS2 places on essential and important entities.
  • How do trust services support NIS2 compliance? See how electronic signatures, seals, time stamps, and validation and preservation services support data security, accountability and audit readiness.
  • Why is it worth deploying qualified trust services? Discover the main benefits of using qualified trust services in an organization.

Trust Services and NIS2 – How to Support Cybersecurity and Regulatory Compliance

As public and business services move online, trust in digital identity and the security of ICT systems are becoming central to the way organizations operate. The two most important European legal acts in this area are the eIDAS Regulation (together with eIDAS 2.0), which governs trust services, and the NIS2 Directive, which aims to raise the level of cybersecurity among essential and important entities. In Poland, the requirements of NIS2 are implemented through the Act on the National Cybersecurity System (KSC).

Although the two acts differ in scope, they complement each other – trust services ensure the trustworthiness of electronic transactions, while NIS2 focuses on infrastructure resilience and cybersecurity risk management.

The NIS2 Directive introduces new cybersecurity requirements for thousands of organizations across Europe. Companies covered by the Directive must put appropriate risk management measures in place, secure their communications, control access to their systems, and be able to demonstrate during audits and inspections what measures they have taken.

What are trust services?

Qualified trust services compliant with eIDAS play an important role in meeting these requirements. Trust services include solutions for securely confirming identity and the integrity of electronic documents. Importantly, the NIS2 Directive explicitly recognizes the role of qualified trust services in strengthening cybersecurity. Under Article 24 of the NIS2 Directive, Member States should encourage essential and important entities to use qualified trust services, which support compliance with requirements relating to identification, data integrity, accountability and secure communication.

Qualified trust services compliant with eIDAS include, among others:

  • qualified electronic signature,
  • qualified electronic seal,
  • qualified time stamp,
  • qualified validation and qualified preservation services for electronic signatures and seals.

These services are provided by qualified trust service providers, who are subject to supervision and must meet the requirements laid down in trust services legislation. In Poland, the national trust infrastructure is supervised by the Minister of Digital Affairs. The register of qualified trust service providers is published by the National Certification Centre (NCCert).

NIS2 – a new approach to cybersecurity

The NIS2 Directive considerably expands the obligations of organizations classified as essential and important entities. The main requirements include:

  • implementing an information security management system,
  • managing cybersecurity risk,
  • securing the supply chain,
  • managing incidents,
  • ensuring business continuity,
  • providing regular staff training and management oversight of security.

The aim of NIS2 is to make organizations more resilient to cyberattacks and limit the impact of security incidents.

How do trust services support NIS2 compliance?

Trust services are one of the foundations for meeting NIS2 requirements. In practice, they support organizations in the following areas:

Verifying user identity

Qualified certificates make it possible to unambiguously identify the individuals and organizations carrying out activities in a company’s systems. This helps reduce the risk of unauthorized access and improves accountability for operations.

Protecting the integrity of documents and data

Electronic signatures and seals make it possible to demonstrate that a document has not been altered since it was signed. This is an important element of protecting information and implementing the security policies required by NIS2.

Secure communication and information exchange

Trust services support electronic document workflows and the exchange of information between organizations, partners and public authorities while maintaining a high level of security and trustworthiness.

Evidence for audits and inspections

Time stamps, signatures and seals create a reliable audit trail, making it possible to demonstrate when, by whom and on what basis particular actions were taken.

For example, an electronic signature provides clear confirmation of who authored a document, a time stamp confirms when it was signed, and a qualified electronic seal makes it possible to reliably verify documents generated by the organization.

Qualified validation and preservation services for electronic signatures and seals play a particularly important role in ensuring the long-term trustworthiness of digital documents. A qualified validation service makes it possible to reliably confirm the validity of an electronic signature or seal, both when it is affixed and at a later date. A qualified preservation service for electronic signatures and seals, in turn, preserves their evidentiary value for many years, even after the certificates used have expired or the underlying technology has changed.

Why is it worth deploying qualified trust services?

Deploying qualified trust services helps organizations meet NIS2 requirements more effectively while also providing a range of business and organizational benefits, such as:

  • stronger cybersecurity across the organization,
  • a lower risk of unauthorized changes to documents,
  • confirmation of the identity of users and organizations,
  • support for compliance with NIS2 and KSC requirements
  • legal recognition throughout the European Union,
  • easier preparation for audits and inspections.

Summary

NIS2 and trust services share a common goal: building a secure digital environment. NIS2 sets out how organizations should manage the security of their systems, while trust services provide the tools needed to ensure the trustworthiness and integrity of electronic transactions and documents. In practice, effective compliance with NIS2 requirements will in many cases rely on the use of qualified trust services. Certum offers a comprehensive range of qualified trust services designed to support secure digital processes. These services enable an organization not only to accelerate the digitalization of its processes, but also to strengthen its security, regulatory compliance and readiness to meet NIS2 requirements.