White paper — public consultation v0.9

What if European digital trust became a shared resource?

As Let's Encrypt did for Web encryption, OTSPI wants to make eIDAS qualified proof available to everyone through APIs: time-stamping, certificates, signatures. Free for the baseline service, open, with a pilot already online.

A working RFC 3161 pilot already runs. Get a time-stamp token in 30 seconds, with no account or API key (test environment, not qualified).

Key figures

Fixed deadlines, very real costs

Digital identity, e-invoicing and Web certificates are becoming mandatory or unavoidable within less than three years. Yet the proof that makes them legally enforceable is still billed per transaction.

  • Digital identity 24.12.2026

    until each of the 27 Member States must provide a European Digital Identity Wallet.

    One year later, banks, energy, transport and telecom operators will have to accept it.

    Regulation (EU) 2024/1183, Art. 5a and 5f
  • E-invoicing 10 million

    economic actors in France affected by mandatory e-invoicing, according to the Ministry of the Economy (broadest scope).

    Receiving e-invoices has been mandatory since 1 September 2026; SMEs and micro-businesses must issue them from 1 September 2027.

    economie.gouv.fr
  • Cost of proof €10,000 excl. VAT / year

    to time-stamp 15,000 documents a month with a qualified provider, at public list prices.

    An act with a near-zero marginal cost, billed token by token.

    White paper, § 2.1
  • Our commitment €0

    for the OTSPI baseline service, identical for everyone and with no prior contract.

    Only enhanced commitments (volumes, availability, support) involve a contribution.

    White paper, § 5.4
  • Web certificates 47 days

    maximum validity of a TLS certificate in 2029, down from 398 days in 2025.

    Nearly eight renewals per year and per site: without automation, nobody will keep up.

    CA/Browser Forum, ballot SC-081v3
  • Dependency 64 %

    of websites rely on a single certificate authority, established outside the Union.

    An exemplary commons, but a single point of dependency for the European Internet.

    W3Techs, September 2026

Who is it for?

Four situations, one principle: proof without a toll

What an open qualified provider changes for those the current model shuts out.

An SME that invoices

Time-stamping 15,000 documents a month costs about €10,000 excl. VAT a year at a qualified provider's public prices. With OTSPI, the baseline service is €0.

A local authority or a university

Long-term archiving, public procurement, diplomas: qualified proof becomes accessible with no tender and no subscription to a single provider.

An open source project

Time-stamp and sign releases through standard APIs (RFC 3161, ACME), with the usual tools and no prior contract.

A freelancer, a micro-business or an association

The EUDI Wallet offers a free qualified signature, but Member States may reserve it for non-professional use. Once you act in a professional capacity, you fall back into the paid model.

The problem

The bottleneck is not the number of providers, but their access model

As of 24 September 2026, the EEA trusted lists include 280 qualified providers, 158 of which offer qualified time-stamping. Yet they all share the same model: prior contract, per-unit pricing, proprietary interfaces and markets fragmented by country.

An end-to-end automatable chain of trust

  1. Identify

    Verifiable attestation of the counterparty, issued from an identity wallet.

    EUDI Wallet · business wallets
  2. Invoice

    Structured invoice issued and transmitted through an approved platform.

    Approved platforms
  3. Seal and time-stamp

    Qualified seal and time-stamp on the fly, through an API, with no per-transaction fee.

    OTSPI's role
  4. Archive

    Transfer to archiving with enforceable proof of integrity for the entire retention period.

    Archiving systems
Step 3 determines the whole chain: if every proof is billed, automation remains reserved for organisations able to absorb the cost.

The Web has been here before. In 2015, fewer than 30 % of Web pages were encrypted. Let's Encrypt, run by a non-profit organisation, made certificates free and automated: around 80 % of pages are encrypted today. OTSPI applies this method to eIDAS qualified services, while fully accepting their specific liability, supervision and audit requirements.

Our response

A public-interest qualified provider

In line with its statutory purpose, OTSPI covers the entire chain of trust and makes it available to everyone on the same terms.

An inalienable commons

A non-profit association under the French law of 1901, currently being formed. Its draft statutes entrench its purpose, permanently forbid any conversion into a commercial company and place assets and keys beyond any appropriation.

Fully open code

The whole software stack is published under the EUPL 1.2, a European copyleft licence compatible with the AGPL v3: improvements stay free, including when they are operated as a service.

Standard APIs, no per-transaction fee

RFC 3161, ETSI EN 319 422, ACME: no proprietary layer. The baseline service is free and identical for everyone; only enhanced commitments involve a contribution.

Governance with segregated duties

Executive management, the Trust Policy Committee and Authority Officers are strictly separated, in line with ETSI EN 319 401 and WebTrust requirements.

Services

A step-by-step roll-out, one service at a time

Each service opens only once the previous one is qualified and stable. Qualified time-stamping comes first: it requires no identity verification and focuses the effort on time accuracy and key protection.

Pilot service

Qualified electronic time-stamping

Compliant with ETSI EN 319 421 and 422 and RFC 3161. Authenticated Galileo (OSNMA) and GPS time reference, oscillator holdover, automatic stop in case of drift. Legal presumption of accuracy (Article 41 of the eIDAS Regulation).

Medium term

European TLS certificate authority

Two branches: DV, issued instantly through ACME with no prior account, under a WebTrust root; OV / QWAC, issued through ACME after a one-time onboarding of the organisation, recognised both by browsers and as eIDAS qualified certificates (regulated uses, PSD2).

Medium term

Qualified seals and signatures

Qualified seal and signature certificates, then remote signing and sealing through an API: seal, time-stamp and archive every e-invoice without subscribing to a single provider.

Medium term, in parallel

Identity and attestations

Electronic attestations of attributes for the EUDI Wallet and business wallets, and open integration building blocks for local authorities, education and associations. Issuing identity data remains the responsibility of Member States.

Proof of concept

The pilot is already running

The RFC 3161 time-stamping service already runs in a public test environment, on an engine written in Rust and published as open source. You can try it right now.

Test environment. Tokens issued are not qualified and have no legal value; they demonstrate how the service works and interoperates. The demo still carries the project's former name, Open eIDAS.

Trust architecture

Verifiable security, not declarative security

The architecture is designed for audit: every control is documented, every ceremony is witnessed, every token issued is recorded in a public log.

Cryptographic isolation

Keys are generated and used exclusively in HSMs certified Common Criteria EAL4+ against the CEN EN 419 221-5 protection profile, hosted in two European sites certified ISO/IEC 27001.

Root key under quorum

Offline root CA, activated by 3 smart cards out of 5 held by separate officers. Backup cards under seal with separate notarial offices, subject to an exclusive activation clause.

Public transparency

Verifiable Merkle log of issued tokens, open source code and reproducible builds, public Certification Practice Statement following RFC 3647, published audit results.

Strictly separated certification hierarchies

OTSPI certification hierarchies On the left, the offline qualified root under a 3-of-5 quorum certifies the time-stamping CA, which certifies the time-stamping units of sites A and B, as well as future qualified CAs for seals, signatures and attestations. On the right, two separate roots: a WebTrust root for browsers and a QWAC root listed on the European trusted list. The WebTrust root certifies a DV sub-CA, which issues DV certificates through instant ACME. A hybrid OV / QWAC sub-CA, holding a single key, is certified both by the WebTrust root and, through cross-signing, by the QWAC root; it issues OV / QWAC certificates after onboarding of the organisation. eIDAS QUALIFIED HIERARCHY TLS CERTIFICATES — WEBTRUST AND QWAC ROOTS cross-sign OTSPI qualified root offline · 3-of-5 quorum Time-stamping CA dedicated intermediate Future qualified CAs seal · signature · attestations TSU A HSM site A TSU B HSM site B WebTrust root OS and browser stores QWAC root EU trusted list DV sub-CA WebTrust only OV / QWAC sub-CA one key · two certificates DV certificates instant ACME OV / QWAC certificates ACME after onboarding certification cross-signing future service
Time-stamping and TLS keys are never shared. The DV branch stays outside the eIDAS scope; an OV / QWAC certificate will be recognised both by browsers and as a qualified certificate once the inclusion and qualification decisions have been obtained.

Statutes

Draft statutes designed so that no one can take over the infrastructure

Many open projects have been bought out, turned into commercial offerings or abandoned. For an infrastructure carrying legal proof over decades, and eventually identity data, this risk is ruled out by design. These safeguards will take effect once the statutes are adopted by the founding general meeting.

Show the seven statutory safeguards
SafeguardStatutory mechanism
Entrenched purposeThe public-interest purpose and the continuity clauses are declared permanent and unamendable (Articles 2 and 13).
No for-profit conversionThe association may never become a commercial company or any other for-profit entity (Article 13.1).
Inalienable assetsSoftware, trademarks, domain names and equipment may not be transferred to a for-profit entity (Article 13.2).
Keys beyond appropriationPrivate keys, root certificates and HSM access are held in technical escrow; nobody may claim any private right over them (Article 8 ter).
Amendment all but impossible75 % quorum, unanimity of voting full members and a veto right for all members; protected articles can only be amended at the order of an authority or an auditor (Articles 11 and 11 bis).
Guaranteed continuityRing-fenced reserve fund for the termination plan, perpetual transfer of assets to a similar body, and mandatory adoption of the same clauses by any successor (Articles 12 bis, 13 and 13 bis).
Universal accessServices available on a universal, neutral and non-discriminatory basis (Article 12 quater).

Just as with the root key, no one can act alone. The full draft statutes are published (in French) on about.otspi.org.

Roadmap

Five phases, from presenting the project to applying for qualification

This roadmap describes the steps OTSPI intends to take. It does not prejudge the opinions of the institutions consulted, nor decisions that fall within their sole competence. No timetable will be set until those opinions have been gathered.

  1. Presenting the project and setting up governance

    Presenting the white paper to the competent authorities and the research community to gather their opinions; setting up the advisory board; revising the roadmap and publishing the multi-year budget.

  2. Test bench and pilot documentation

    Public test environment (RFC 3161 API, transparency log), validation of the time chain, pilot Time-Stamping Policy and Certification Practice Statement, root CA ceremony; first work on identity.

  3. Conformity assessment and application for qualification

    Audit by an accredited body (ETSI EN 319 403-1) and application for qualified status to the supervisory body, which alone is competent to grant it.

  4. European TLS certificate authority

    WebTrust and QWAC roots, DV and OV / QWAC sub-CAs, WebTrust and ETSI audits, applications for inclusion and qualification; ACME service in testing, then in production once the WebTrust root is included.

  5. Seals, signatures and identity

    Qualified seal and signature certificates, remote signing through an API, electronic attestations of attributes for European wallets.

Manifesto

For a free and open digital identity

Ten principles to keep European digital identity and trust services as digital commons. Individuals and organisations can sign it.

Read and sign the manifesto

Call for partners

Join the project

We are looking for specific contributions. Pick yours:

Hosting and sovereign cloud providers

Contribution
Secure colocation and connectivity in two European sites.
Framework
In-kind technology sponsorship, valued and declared.
Offer help →

Funders and foundations

Contribution
Funding for the consultation phase, the test bench and the first audit.
Framework
Digital commons grants, sponsorship, public accountability for the use of funds.
Offer help →

Research laboratories

Contribution
Independent review of the architecture and code: applied cryptography, time metrology, formal methods.
Framework
Scientific collaboration and open publications.
Offer help →

Auditors and eIDAS experts

Contribution
Critical review of policies, the practice statement and procedures ahead of the qualification audit.
Framework
Participation in the advisory board.
Offer help →

Software vendors and e-invoicing platforms

Contribution
Integrating qualified sealing and time-stamping into invoicing and archiving pipelines.
Framework
Universal access on the same terms as everyone else.
Offer help →

Local authorities and public administrations

Contribution
Pilot use cases: evidential archiving, public procurement, EUDI Wallet integration.
Framework
Experimentation on the test environment and dialogue with the advisory board.
Offer help →

Let's discuss your contribution

The white paper is open for public consultation. Your comments, criticism and partnership proposals are welcome, in English or in French. The expense items are detailed in the white paper.

Spread the word

Tell the people around you

OTSPI moves forward thanks to those who talk about it. A share, a forward to the right person or a signature of the manifesto counts as much as funding.