Qualified Electronic Archiving is no longer just a concept, although it was already more than a concept in several European Member States.
With the publication of Commission Implementing Regulation (EU) 2025/2532, in force since 6 January 2026, Europe now has a complete legal and technical framework for archiving electronic data and documents with legal presumptions around integrity and origin.
Yet many organisations still struggle to see how the different layers relate to each other. Let me walk you through the stack.
Layer 1: The Regulation sets the “What”
eIDAS 2 (Regulation (EU) 2024/1183, amending Regulation (EU) No 910/2014) introduces Electronic Archiving as a trust service in its own right.
Article 45j defines the objective: Qualified Electronic Archiving services must ensure the durability and legibility of electronic data and documents beyond their technological validity period, and at least throughout the legal or contractual preservation period, while maintaining their integrity and proof of origin.
That is the level of a regulation: legally binding outcomes, deliberately technology-neutral. It tells you what must be achieved, not how.
An important consequence of Electronic Archiving being part of a Regulation is that the core requirements are harmonised at EU level. National rules may still define retention obligations or sector-specific duties, but they cannot contradict the directly applicable Regulation.
The Regulation remains the leading legal layer: local legislation, standards and technical solutions must align with it.
Layer 2: The Implementing Act sets the standards
Regulations delegate the technical detail to implementing acts. Commission Implementing Regulation (EU) 2025/2532 does exactly that for Qualified Electronic Archiving: it lays down the reference standards and specifications that a Qualified Electronic Archiving Trust Service Provider (QEATSP) must meet.
This is more explicit under eIDAS 2 than before: the Implementing Act points directly to requirements and controls from standards that must be met.
The Annex of the Implementing Act works as a bridge. It takes the legal requirements of Article 45j and maps them onto concrete clauses of recognised standards, primarily CEN/TS 18170:2025 for the archiving-specific requirements and ETSI EN 319 401 for the general trust service provider requirements.
It also references ISO 14721:2025, the OAIS reference model, for long-term preservation concepts.
Layer 3: CEN/TS 18170:2025 sets the “How”
CEN/TS 18170:2025, developed by CEN/TC 468 with active involvement of the European Commission and experts from across Europe, defines the functional, operational and procedural requirements for Electronic Archiving Trust Services (EATS).
It covers the full lifecycle: receipt, ingestion, storage, retrieval and deletion of electronic data and documents, whether born digital or scanned from paper.
It is the first European standard written specifically for the Electronic Archiving Trust Service under eIDAS 2, and it applies to both qualified and non-qualified services.
The control matrix: where audit meets architecture
Here is where it becomes tangible for practitioners. The Implementing Act does not simply say “comply with CEN/TS 18170”.
Its Annex assigns specific clauses to specific obligations: risk management follows one clause, cryptographic controls another, termination planning yet another, with ETSI EN 319 401 clauses layered on top for the general TSP obligations.
The result is effectively a control matrix. Conformity Assessment Bodies (CABs), accredited under Implementing Regulation (EU) 2025/2162, will audit QEATSPs against this matrix. For providers, this means every architectural and procedural choice must be traceable to a control.
For customers, it means comparability: two qualified archiving services in different Member States are assessed against the same set of controls, which is precisely what enables cross-border legal recognition.
How does CEN/TS 18170 relate to OAIS, ETSI TS 119 511 and ISO 14641?
These standards are complementary rather than competing, but they answer different questions:
OAIS (ISO 14721) is the conceptual reference model for long-term digital preservation. It gives us the shared vocabulary of SIP, AIP and DIP and the functional model of an archive. It describes what a preservation system is, not how to audit one. CEN/TS 18170 stays deliberately aligned with OAIS while translating its concepts into auditable requirements.
ETSI TS 119 511 addresses preservation of digital signatures: maintaining the validity of qualified signatures and seals beyond the lifetime of the underlying cryptography. Under eIDAS 2, that remains a distinct service, preservation under Article 34, from archiving under Article 45j.
The Implementing Act even acknowledges this: a QEATSP may rely on a qualified preservation service to maintain the trustworthiness of signed documents in the archive.
ISO 14641 defines requirements for the design and operation of electronic archiving systems and has served as the backbone of several national archiving schemes, including in France and Belgium. It remains a solid operational standard, but it was not written for the eIDAS 2 trust service model.
CEN/TS 18170 pulls these threads together: OAIS thinking, trust service governance in the style of ETSI EN 319 401, and archiving system rigour in the tradition of ISO 14641, all packaged as requirements a CAB can audit against Article 45j.
What is genuinely new in CEN/TS 18170:2025?
A few elements stand out compared with earlier standards:
- Automated integrity reporting. Authorised relying parties must be able to obtain, in an automated way, a report confirming that data retrieved from the archive has retained its integrity from the start of the preservation period. This is a significant step up for audit, litigation and compliance scenarios.
- Format and media independence. Explicit requirements for managing technological obsolescence: format migration, metadata preservation and long-term integrity verification, so that legibility is guaranteed beyond the validity of any given technology.
- Deletion as a first-class function. Controlled, evidenced deletion at the end of retention is a requirement, not an afterthought. In a GDPR world, that matters.
- Designed for cross-border recognition. Because the standard was written for Article 45j and is referenced in the Implementing Act, conformity supports harmonised European legal presumptions around integrity and origin, rather than a patchwork of national schemes.
Where Docbyte stands today
Docbyte is a Qualified Trust Service Provider on the European Trusted List, listed with two qualified preservation trust services at EU level:
- Qualified Preservation of Qualified Electronic Signatures
- Qualified Preservation of Qualified Electronic Seals
In addition to those two qualified preservation services, the Belgian Trust List recognises Docbyte at national level for Qualified Electronic Archiving in Belgium, under a scheme built on ETSI EN 319 401, ISO 14641 and ETSI TS 119 511. That combination works well: Trust Service governance, archiving system rigour and signature preservation in one framework.
This means: our current qualification is grounded in the Belgian national framework and is not yet an eIDAS 2 qualification under Implementing Regulation (EU) 2025/2532. The European framework is new for everyone; no provider could hold an eIDAS 2 QEATS qualification before January 2026.
Our ambition is equally clear: we intend to align our service with CEN/TS 18170:2025 and achieve qualification under the eIDAS 2 framework as soon as possible. The good news is that the distance is short. A scheme built on ETSI EN 319 401, ISO 14641 and ETSI TS 119 511 already covers most of the control matrix; the work now is mapping, closing the gaps and evidencing conformity for the CAB.
Why this matters for regulated industries
If you operate in life sciences, financial services or the public sector, the question is no longer whether to pay attention to qualified electronic archiving, but when your archive strategy should converge on it. A qualified archive with European legal presumptions around integrity and origin changes the economics of application retirement, legacy decommissioning and long-term records retention.
How is your organisation preparing for the shift from national archiving schemes to the harmonised eIDAS 2 framework?