Operation of a certification service provider Display
Certification service providers issue qualified certificates or qualified time stamps within the meaning of the Signature Act (SigG).
No authorisation is required for the operation of such a certification service, but the activity must be notified to the competent body and proof must be provided that the conditions for operation are met.
If you want to receive a quality mark for your certification services, you can voluntarily become accredited as a certification service provider .
Who should I contact?
The responsibility lies with the Federal Network Agency.
This procedure can also be carried out through a "Point of Single Contact". The "Point of Single Contact" is a special service offered by municipalities and the state for service providers.
Requirements
- A certification service may only be operated by those who have the necessary for its operation.
- Reliability
- Expertise and
- financial security.
- Furthermore, it must be ensured that the requirements of the Signature Act (SigG) and the Signature Ordinance (SigV) are met in the following areas:
- compliance with the obligations of certification providers,
- design of the content of qualified certificates,
- the period of validity of qualified certificates,
- the scope, amount and structure of the guarantees permitted.
Further requirements or obligations of a certification-service-provider, which were not or not detailed in this short list (e.g. identity verification, documentation, blocking, obligation to inform, maintenance of a certificate directory, products to be used) can be found in the Signature Act (SigG) and the Signature Ordinance (SigV).
Which documents are required?
- written or electronically signed notification with the name and addresses of the certification provider and the name of the legal representative
- Certificate of good conduct according to § 30 paragraph 5 Federal Central Register Act (BZRG)
- Current excerpt from the commercial register or a comparable document
- Documents proving the required technical, administrative and legal expertise according to § 4 paragraph 2 sentence 3 of the Signature Act (SigG)
- Security concept with implementation description
- Proof of financial security according to § 12 SigG
§ 30 paragraph 5 Federal Central Register Act (BZRG)
What are the fees?
Fees apply. These depend on the time required and the expenses.
What deadlines do I have to pay attention to?
The notification of the operation of a certification service must take place at the latest with the start of operation of the certification provider. Otherwise, according to § 21 No. 2 of the Signature Act (SigG), a fine of up to 10,000.00 euros may be imposed.
Legal basis
§ 24 No. 1, 3 and 4 Signature Act (SigG)
§ 9 Signature Ordinance (SigV)
§ 12 Signature Ordinance (SigV)
What else should I know?
Should circumstances arise as a result of which the requirements for the operation of a certification service are no longer met, this must be reported to the competent body without delay.
Technically approved by
Lower Saxony Ministry of the Interior and Sport
Author
List-ID 080 (whitelist; Status: 13.09.2018)
The text was automatically translated based on the German content.