Regulatory framework and compliance

SK ID Solutions AS provides electronic identification and trust services that form part of the digital infrastructure used by individuals, businesses and public authorities. Because these services enable legally significant electronic identification, signing and sealing, their security, reliability and continuity are subject to European Union and Estonian legislation, independent conformity assessment and recognised technical standards.

The regulatory requirements applicable to SK depend on the role and service concerned. SK operates electronic identification solutions, is a qualified trust service provider, and, for services defined by Estonian law, acts as a provider of a vital service. SK is also subject to cybersecurity, data-protection and business-continuity requirements.

ELECTRONIC IDENTIFICATION AND TRUST SERVICES

The principal European legal framework is Regulation (EU) No 910/2014 on electronic identification and trust services for electronic transactions in the internal market (eIDAS), as amended by Regulation (EU) 2024/1183 establishing the European Digital Identity Framework, commonly referred to as eIDAS 2.0.

The eIDAS framework establishes requirements for electronic identification and for trust services used in electronic transactions across the European Union. The amended Regulation also extends the European trust-services framework to new services and strengthens requirements relating to security, supervision and electronic identity.

Electronic identity provider

SK provides electronic identification solutions that enable users to authenticate securely and reliably when accessing digital services.

SK’s electronic identification services are designed and operated within the European eIDAS framework and in accordance with the applicable national electronic identification requirements in Estonia, Latvia and Lithuania. While eIDAS establishes the common European framework for electronic identification and levels of assurance, each country maintains its own national eID scheme, governance arrangements and supervisory requirements. SK therefore ensures that its electronic identification solutions meet both the common European requirements and the specific national requirements applicable in each country where the service is recognised or used as part of a national electronic identification scheme.

This includes requirements relating to identity proofing and enrolment, authentication security, lifecycle management, security and risk management, service availability and supervision. Where an SK electronic identification solution forms part of a notified or nationally recognised eID scheme, its assurance level and use are determined in accordance with the applicable national framework and the eIDAS requirements.

Qualified trust service provider

SK provides several services falling within the eIDAS trust-services framework. These include the issuance and lifecycle management of qualified certificates for electronic signatures, the issuance of qualified certificates for electronic sealsqualified electronic time stamps, and the qualified management of remote qualified electronic signature creation devices (rQSCDs). SK also provides other certification and electronic-identity-related services according to the applicable service and legal framework.

A trust service may be described as qualified only where the requirements of the eIDAS Regulation are fulfilled and the qualified status of the provider and the particular service is reflected in the applicable national Trusted List. Qualified trust service providers and their qualified services are subject to regular independent conformity assessment by an accredited conformity assessment body and supervision by the competent supervisory authority. SK’s currently certified qualified services and conformity-assessment documentation are published on SK’s Compliance Audit page.

The official EU Trusted Lists provide the authoritative electronic evidence of the qualified status of trust service providers and their qualified trust services. Customers and relying parties can therefore use the Trusted List to verify the current regulatory status of an SK qualified trust service.

In Estonia, the eIDAS Regulation is supplemented by the Electronic Identification and Trust Services for Electronic Transactions Act. The Act establishes national requirements and procedures in areas left to Member States by eIDAS, including the organisation of supervision, authorisation of qualified trust service providers and maintenance of the Estonian Trusted List.

The Identity Documents Act is also relevant to SK’s activities. Among other matters, it regulates certificates associated with Estonian identity documents and permits duties relating to the issuance of certificates contained in identity documents to be entrusted to a qualified trust service provider.

CYBERSECURITY AND RESILIENCE

Security and resilience are fundamental regulatory requirements for electronic identification and trust services.

SK is subject to the applicable requirements of the Estonian Cybersecurity Act, which implements the European cybersecurity framework established by the NIS2 Directive (EU) 2022/2555. The Cybersecurity Act requires regulated service providers to implement appropriate and proportionate technical, operational and organisational measures for managing cybersecurity risks, preventing and minimising incidents and ensuring effective incident response.

Trust service providers are additionally covered by Commission Implementing Regulation (EU) 2024/2690, which specifies technical and methodological cybersecurity risk-management requirements and criteria for determining significant incidents under the NIS2 framework. The Regulation expressly covers trust service providers and draws on recognised standards including ISO/IEC 27001 and ETSI EN 319 401.

SK maintains an information security management system certified according to ISO/IEC 27001:2022. The valid ISO/IEC 27001 certificate and SK’s current eIDAS conformity certificates are available on, SK’s Compliance Audit page.

SK AS A VITAL SERVICE PROVIDER

Digital identification and digital signing are designated as a vital service under Estonian law.

Under the Emergency Act and the Identity Documents Act, the certification service provider ensuring the availability of certificate-validity information required for digital identification and digital signing with identity documents issued by the Republic of Estonia is a provider of a vital service.

SK’s vital-service obligations therefore concern the legally defined vital service and should not be understood as meaning that every product or service provided by SK is itself classified as a vital service.

The detailed continuity requirements are established by the regulation “The description and requirements for ensuring the continuity of digital identification and digital signing as a vital service.” These requirements address, among other matters, service availability, continuity risk analysis, resilience measures, restoration of service and reporting of significant disruptions.

These requirements complement SK’s obligations arising from eIDAS and cybersecurity legislation and form part of the broader framework through which the continuity and resilience of critical electronic identification and signing infrastructure are managed.

DATA PROTECTION

SK processes personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Estonian data-protection legislation, including the Personal Data Protection Act.

The principles governing SK’s processing of personal data, including information about purposes of processing, categories of data, retention and data-subject rights, are described separately in SK’s Data Protection information.

APPLICABLE STANDARDS FOR QUALIFIED TRUST SERVICES

Legislation establishes the regulatory requirements applicable to SK, while European and international standards provide detailed technical, security and operational requirements used in implementing and assessing those requirements.

SK’s trust services are designed and assessed against applicable ETSI and other recognised standards. Depending on the service, these include standards such as ETSI EN 319 401 for general requirements applicable to trust service providers, ETSI EN 319 411-1 and EN 319 411-2 for certificate services, ETSI EN 319 421 for electronic time-stamping services and ETSI TS 119 431-1 for trust services operating and managing remote signature-creation devices.

The standards applicable to an individual SK service are identified more precisely in the relevant certificate policy, practice statement and conformity-assessment documentation. The regulatory and technical requirements therefore form a layered assurance framework rather than a single certification or legal requirement.

POLICIES, PRACTISE STATEMENTS AND EVIDENCE OF COMPLIANCE

SK publishes the principal documents describing how its trust services are operated.

The SK Trust Services Practice Statement describes the common practices and principles applicable to SK’s trust services and public-key infrastructure, including the shared information-security management framework, processes, infrastructure and controls.

Service-specific Certificate Policies and Certification Practice Statements define requirements and operating practices for individual certificate services. SK also publishes the applicable policies and practice statements for its qualified electronic time-stamping and remote QSCD management services. Current service documentation is available in the Resources section of this website.

For customers, relying parties, auditors and other interested parties, the principal sources for verifying SK’s regulatory and assurance status are the EU Trusted List, SK’s Compliance Audit page containing current conformity certificates and assessment information, the applicable service policies and practice statements, and SK’s ISO/IEC 27001 certificate.

These sources should be used for the current status and scope of a particular service, as legislation, technical standards and individual service certifications may evolve over time.