CEN TS 18170 - Policy and functional requirements for the electronic archiving service
CEN TS 18170 specifies provisions (requirements, recommendations, permissions, possibilities and capabilities) for an Electronic Archiving Trust Service (EATS).
The Regulation (EU) 2024/1183 of the European Parliament and of the Council of 11 April 2024 (eIDAS 2) amending Regulation (EU) No 910/2014 (eIDAS) as regards establishing the European Digital Identity Framework establishes a legal framework of requirements for electronic signatures and trust services. This regulation introduces the (qualified) electronic archiving service. It requires standards for services, processes, systems and products related to trust services as well as guidance for conformity assessment of such services, processes, systems and products.
The main objective of CEN TS 18170 is to define requirements and recommendations for an electronic archiving trust service which may use procedures and technologies capable of ensuring the durability and legibility of electronic data and electronic documents beyond the technological validity period and at least throughout the legal or contractual preservation period, while maintaining their integrity and the accuracy of their origin.
It is assumed that the Electronic Archiving Trust Service Provider (EATSP) which provides electronic archiving trust services operates the trustworthy system in an environment with a security policy which incorporates general physical, procedural and documentation security requirements for TSP providing electronic archiving trust services.
CENN TS 18170 specifies requirements for implementing electronic archiving trust services with specific regard to:
- Functional requirements for electronic archiving to ensure the receipt, storage, retrieval and deletion of electronic data and electronic documents in order to ensure their durability and legibility as well as to preserve their integrity, confidentiality and proof of origin throughout the preservation period.
- Requirements for qualified electronic archiving trust services, aiming to fulfil the provisions outlined in Article 45j of the eIDAS Regulation
- Procedures and technologies capable of ensuring the durability and legibility of electronic data and electronic documents beyond the technological validity period and at least throughout the legal or contractual preservation period, while maintaining their integrity and the accuracy of their origin.
- Procedures and technologies to ensure that those electronic data and those electronic documents are preserved in such a way that they are safeguarded against loss and alteration, except for changes concerning their medium or electronic format.
- Procedures and technologies that allow authorized relying parties to receive a report in an automated manner that confirms that electronic data and electronic documents retrieved from a QEATS qualified electronic archive trust service enjoy the presumption of integrity of the data from the beginning of the preservation period to the moment of retrieval.
QUick look to CEN TS 18170 summary
Différences entre la certification nationale marque NF461 et la certification européenne eIDAS2


