Agent · eidas-910-2014-30
eIDAS 2.0 artikel 30: Certification of qualified electronic signature creation devices
Structural tree: the article's own paragraphs, verbatim.
CELEX 32014R0910 · 2026-08-26 · Weight 80 · minimal-risk
ExtendedOperational weight but lower priority. Metered by volume, not per call, once metering is switched on.
- What this page is
- Agent, eIDAS 2.0 artikel 30
- Checked against the official source
- 2026-08-26Current
- Responsible publisher
- ExploreWorld Legal, editorial deskLiability position
Short answer
What does eIDAS 2.0 Article 30 require, and what outcome does the rule tree give?
eIDAS 2.0 Article 30 is tested here by a deterministic rule tree of 8 rules, built from the article's own conditions. The tree reads your facts and names the outcome that applies, starting with Paragraph 1 applies, carrying paragraph citation, content hash and read date 2026-08-26 against CELEX 32014R0910. The outcome is a machine classification, not a compliance decision.
eIDAS 2.0 Article 30Checked against the publisher 2026-08-26Official text
- Paragraph 1 applies. a security evaluation process carried out in accordance with one of the standards for the security assessment of information technology products included in the list established in accordance with the second subparagraph; or
- Paragraph 2 applies. a process other than the process referred to in point (a), provided that it uses comparable security levels and provided that the public or private body referred to in paragraph 1 notifies that process to the Commission. That process may be used only in the absence of standards referred to in point (a) or when a security evaluation process referred to in point (a) is ongoing.
- Paragraph 3 applies. The Commission shall, by means of implementing acts, establish a list of standards for the security assessment of information technology products referred to in point (a). Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
A source reference, not legal advice.
Jurisdiction
The same agent, read through one country's lens.
Inputs
- in_scopeThe article applies to the situationboolean
- punktParagraph of the articleenum (1 | 2 | 3 | 4 | 5 | 6 | 7 | 8)
Rule tree
If: alla(in_scope = true, punkt = 1)
Paragraph 1 applies
a security evaluation process carried out in accordance with one of the standards for the security assessment of information technology products included in the list established in accordance with the second subparagraph; or
Paragraph 1
If: alla(in_scope = true, punkt = 2)
Paragraph 2 applies
a process other than the process referred to in point (a), provided that it uses comparable security levels and provided that the public or private body referred to in paragraph 1 notifies that process to the Commission. That process may be used only in the absence of standards referred to in point (a) or when a security evaluation process referred to in point (a) is ongoing.
Paragraph 2
If: alla(in_scope = true, punkt = 3)
Paragraph 3 applies
The Commission shall, by means of implementing acts, establish a list of standards for the security assessment of information technology products referred to in point (a). Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
Paragraph 3
If: alla(in_scope = true, punkt = 4)
Paragraph 4 applies
1. Conformity of qualified electronic signature creation devices with the requirements laid down in Annex II shall be certified by appropriate public or private bodies designated by Member States.
Paragraph 4
If: alla(in_scope = true, punkt = 5)
Paragraph 5 applies
2. Member States shall notify to the Commission the names and addresses of the public or private body referred to in paragraph 1. The Commission shall make that information available to Member States.
Paragraph 5
If: alla(in_scope = true, punkt = 6)
Paragraph 6 applies
3. The certification referred to in paragraph 1 shall be based on one of the following: (a) a security evaluation process carried out in accordance with one of the standards for the security assessment of information technology products included in the list established in accordance with the second subparagraph; or
Paragraph 6
If: alla(in_scope = true, punkt = 7)
Paragraph 7 applies
3a The validity of a certification referred to in paragraph 1 shall not exceed five years, provided that vulnerabilities assessments are carried out every two years. Where vulnerabilities are identified and not remedied, the certification shall be cancelled.
Paragraph 7
If: alla(in_scope = true, punkt = 8)
Paragraph 8 applies
4. The Commission shall be empowered to adopt delegated acts in accordance with Article 47 concerning the establishment of specific criteria to be met by the designated bodies referred to in paragraph 1 of this Article.
Paragraph 8
If no rule matches: The article is not stated to apply, or no paragraph is selected. The agent abstains rather than guesses.
The article text as read
- 1a security evaluation process carried out in accordance with one of the standards for the security assessment of information technology products included in the list established in accordance with the second subparagraph; or
- 2a process other than the process referred to in point (a), provided that it uses comparable security levels and provided that the public or private body referred to in paragraph 1 notifies that process to the Commission. That process may be used only in the absence of standards referred to in point (a) or when a security evaluation process referred to in point (a) is ongoing.
- 3The Commission shall, by means of implementing acts, establish a list of standards for the security assessment of information technology products referred to in point (a). Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
- 41. Conformity of qualified electronic signature creation devices with the requirements laid down in Annex II shall be certified by appropriate public or private bodies designated by Member States.
- 52. Member States shall notify to the Commission the names and addresses of the public or private body referred to in paragraph 1. The Commission shall make that information available to Member States.
- 63. The certification referred to in paragraph 1 shall be based on one of the following: (a) a security evaluation process carried out in accordance with one of the standards for the security assessment of information technology products included in the list established in accordance with the second subparagraph; or
- 73a The validity of a certification referred to in paragraph 1 shall not exceed five years, provided that vulnerabilities assessments are carried out every two years. Where vulnerabilities are identified and not remedied, the certification shall be cancelled.
- 84. The Commission shall be empowered to adopt delegated acts in accordance with Article 47 concerning the establishment of specific criteria to be met by the designated bodies referred to in paragraph 1 of this Article.
Lineage
Interface
Hashes
Artefacts
No legal advice. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.
Citation: 32014R0910 art. 30, Certification of qualified electronic signature creation devices. ExploreWorld Legal, https://legal.exploreworldai.com/agent/eidas-910-2014/artikel-30 (hämtad 2026-08-26, bevis sha256:106ec07d141ff21e, bygge legal-2026-08-25).