Solutions

Industries

Markets

Partnerships

Resources

Get in touch

Mustafa Kucukaytekin, VP Security & Infrastructure at Fourthline

Fourthline's QTSP Status: What It Is and Why It Matters for Our Business Partners

Fourthline's QTSP Status: What It Is and Why It Matters for Our Business Partners

Most qualified signing flows, at some point or another, involve an SMS code. Why? Well, because the company verifying your customer's identity and the company issuing their signing certificate are two different businesses. Fourthline has just changed that. 

On 21 August 2026, Fourthline Trust Services AB was granted status as a Qualified Trust Service Provider (QTSP) in the EU, listed on the EU Trusted List and supervised by Sweden's Post and Telecom Authority (PTS). For compliance teams at regulated institutions, this means that identity verification and qualified electronic signature (QES) issuance now happen in a single, continuous session.  

We sat down with Mustafa Kucukaytekin, VP Security & Infrastructure and one of the leaders behind the programme, to understand what Fourthline's new QTSP status means for the businesses that rely on it. 

Fourthline was granted QTSP status on 21 August 2026. For someone who doesn't live and breathe trust services, what does that actually mean, and why should a financial institution care? 

As the saying goes, providing QES as a QTSP “kills two birds with one stone.” On one hand, you give your business partners a platform that lets their clients sign a document that is legally recognised across the European Union as having the same legal standing as a handwritten signature. On the other hand, you're onboarding that customer by performing identity verification at the very same moment, in the same flow. 

QES is also one of the methods recognised by AMLR (the incoming anti-money laundering regulation) as a valid means of remotely verifying a customer's identity. And because the flow is simple (a selfie and a document scan) user adoption is strong. Compare that to national eID, EUDI Wallet and NFC-based flows, which involve QR codes, PIN codes, chip scanning. That's a lot of steps that many users simply won't complete.  

Before Fourthline became a QTSP, how did qualified signing work? What friction points have been removed? 

Before, we were using a third-party provider for the signing piece. Using a third party isn't necessarily an issue in and of itself, but it creates an ownership problem. When there is a problem in the user journey, you need to find where the user is actually experiencing issues. In this way, the quality of your service doesn't always match what you want to provide to your clients. 

Now, Fourthline owns the entire process from end to end. That means we can deliver the same level of quality for signing that we've been delivering for identity verification for years. From a regulatory perspective, it also means one entity is responsible for audit trails and end-to-end evidence recording. 

Most QES flows on the market end with an SMS code. Fourthline's doesn't. Why does that matter? 

SMS was always designed for delivery, not for security. It was never built with authentication in mind. When you receive an SMS, you can't always be certain who sent it: it could be your mobile operator, or even a bad actor. Furthermore, the delivery itself is fragile: it depends on operator availability, coverage, and plenty of other factors outside of our control.  

Now, extrapolate that to an onboarding flow. The customer has gone through identity verification, provided their documents, their selfie, their biometrics. They reach the final step and the SMS doesn't arrive. That conversion is gone. Statistics show that a significant percentage of drop-offs happen exactly at that SMS delivery step. To be specific, our data shows that the average drop at the QES SMS verification step is ~2%, with a band of about 1–6% across different user bases and business partners 

The reason SMS exists in a typical QES flow is fundamentally structural. Usually, the identity verification happens in one system (such as Fourthline’s) and the signing happens in a completely separate third-party system. The third party has no direct way of knowing that the person requesting the code is the same person who just completed identity verification.  

So, the SMS usually acts like a bridge to re-establish trust. But it's a workaround for a fragmented architecture? 

That’s right. And because Fourthline now performs both the identity verification and the signing in the same user session, we don't need anything to bridge the gap. The trust is already established. We perform some cryptographic operations that eliminate the need for SMS entirely, and the customer moves from verified to signed without interruption. 

When identity verification and certificate issuance sit with different vendors, what accountability gaps can open up? 

Diagnosing failures becomes genuinely complicated, and so many questions come up. Why was the identity result rejected? Why wasn’t the certificate issued? Was the signing service unavailable? Which SLA applies?  

These are questions that have no clean answer when the process is split across multiple vendors. Each party has a different scope, different support processes, different contractual obligations. The quality of the service almost always suffers as a result. Consolidating all these services under one provider reduces all that.  

There's also a vendor management dimension that's becoming increasingly important. Under DORA and NIS2, financial institutions have real obligations around third-party risk and oversight. Working with one provider instead of two or three simplifies that significantly. 

Fourthline Trust Services AB is listed on the EU Trusted List, supervised by Sweden's PTS. What is a Trusted List, and why does it matter? 

If you're not on the Trusted List, you cannot issue qualified electronic signatures. Full stop. Getting listed requires passing a set of ETSI standards, being audited by an accredited conformity assessment body, and having that audit report verified by a national supervisory authority; in our case, PTS in Sweden. It’s only then does your name appear on the list. 

The Trusted List is essentially a public chain of trust; You can think of it somewhat like a browser trust store. When you see HTTPS on a website, you're trusting a public chain that connects that certificate back to a recognised root authority. The EU Trusted List works the same way. When a qualified signature is accepted in any EU member state, it's because the issuing provider is verified on that list. That public accountability is what gives qualified signatures their legal weight. 

AMLR applies from 10 July 2027. Where does QES fit into that picture? 

AMLR explicitly recognises two methods for customer identity verification: physical identity documents and eIDAS-based electronic identification. 

Within eIDAS-based identification, there are three recognised routes: the European Digital Identity (EUDI) Wallet, national eID schemes, and qualified trust services (including QES). So QES is directly in scope as a compliant onboarding method under AMLR. 

What are some advantages of QES compared to eID and EUDI Wallet?  

What makes QES so strong here is that it works uniformly across all member states. With eID, every country provides different data attributes (name, date of birth, etc.). The EUDI Wallet will face similar limitations initially.  

QES doesn't have any of those variations. It doesn't require any prior setup or awareness from the customer, and it provides a unified way of onboarding across all member states. So, because QES has harmonised legal recognition across the EU, Fourthline can consistently offer it across supported markets. 

There's also a forward-looking piece. In August 2027, V2 of the ETSI TS 119 461 standard comes into force. All QTSPs will need to ensure that the identity methods used for certificate issuance satisfy that framework, and will need to be audited against it. Because Fourthline offers both the identity verification and the certificate issuance, we can align to that standard once and deliver it as a single solution.  

What's next for Fourthline Trust Services?  

Looking ahead, there are a few strategic areas we are exploring. One is expanding further into the EUDI Wallet ecosystem, including qualified electronic attestations of attributes, which could allow verified attributes to be issued and used through European Digital Identity Wallets. At the same time, we see opportunities to broaden our signing capabilities beyond today's QES journey. That could include both qualified and non-qualified signatures, different models for one-time and returning users, and more flexible integration options for customers that already operate parts of their own identity or trust infrastructure. 

The broader direction is to make Fourthline's identity and trust capabilities available across a wider range of customer journeys, rather than requiring every customer to follow the same signing model. 

With AMLR applying from July 2027 and new identity proofing requirements for qualified certificate issuance following a month later, it's time to get your signing and onboarding infrastructure in order. If you'd like to understand what working with a single provider for both identity verification and qualified trust services could mean for your business, get in touch with the Fourthline team.  

Not sure where to start? Find out what a Qualified Trust Service Provider actually is. 

Most qualified signing flows, at some point or another, involve an SMS code. Why? Well, because the company verifying your customer's identity and the company issuing their signing certificate are two different businesses. Fourthline has just changed that. 

On 21 August 2026, Fourthline Trust Services AB was granted status as a Qualified Trust Service Provider (QTSP) in the EU, listed on the EU Trusted List and supervised by Sweden's Post and Telecom Authority (PTS). For compliance teams at regulated institutions, this means that identity verification and qualified electronic signature (QES) issuance now happen in a single, continuous session.  

We sat down with Mustafa Kucukaytekin, VP Security & Infrastructure and one of the leaders behind the programme, to understand what Fourthline's new QTSP status means for the businesses that rely on it. 

Fourthline was granted QTSP status on 21 August 2026. For someone who doesn't live and breathe trust services, what does that actually mean, and why should a financial institution care? 

As the saying goes, providing QES as a QTSP “kills two birds with one stone.” On one hand, you give your business partners a platform that lets their clients sign a document that is legally recognised across the European Union as having the same legal standing as a handwritten signature. On the other hand, you're onboarding that customer by performing identity verification at the very same moment, in the same flow. 

QES is also one of the methods recognised by AMLR (the incoming anti-money laundering regulation) as a valid means of remotely verifying a customer's identity. And because the flow is simple (a selfie and a document scan) user adoption is strong. Compare that to national eID, EUDI Wallet and NFC-based flows, which involve QR codes, PIN codes, chip scanning. That's a lot of steps that many users simply won't complete.  

Before Fourthline became a QTSP, how did qualified signing work? What friction points have been removed? 

Before, we were using a third-party provider for the signing piece. Using a third party isn't necessarily an issue in and of itself, but it creates an ownership problem. When there is a problem in the user journey, you need to find where the user is actually experiencing issues. In this way, the quality of your service doesn't always match what you want to provide to your clients. 

Now, Fourthline owns the entire process from end to end. That means we can deliver the same level of quality for signing that we've been delivering for identity verification for years. From a regulatory perspective, it also means one entity is responsible for audit trails and end-to-end evidence recording. 

Most QES flows on the market end with an SMS code. Fourthline's doesn't. Why does that matter? 

SMS was always designed for delivery, not for security. It was never built with authentication in mind. When you receive an SMS, you can't always be certain who sent it: it could be your mobile operator, or even a bad actor. Furthermore, the delivery itself is fragile: it depends on operator availability, coverage, and plenty of other factors outside of our control.  

Now, extrapolate that to an onboarding flow. The customer has gone through identity verification, provided their documents, their selfie, their biometrics. They reach the final step and the SMS doesn't arrive. That conversion is gone. Statistics show that a significant percentage of drop-offs happen exactly at that SMS delivery step. To be specific, our data shows that the average drop at the QES SMS verification step is ~2%, with a band of about 1–6% across different user bases and business partners 

The reason SMS exists in a typical QES flow is fundamentally structural. Usually, the identity verification happens in one system (such as Fourthline’s) and the signing happens in a completely separate third-party system. The third party has no direct way of knowing that the person requesting the code is the same person who just completed identity verification.  

So, the SMS usually acts like a bridge to re-establish trust. But it's a workaround for a fragmented architecture? 

That’s right. And because Fourthline now performs both the identity verification and the signing in the same user session, we don't need anything to bridge the gap. The trust is already established. We perform some cryptographic operations that eliminate the need for SMS entirely, and the customer moves from verified to signed without interruption. 

When identity verification and certificate issuance sit with different vendors, what accountability gaps can open up? 

Diagnosing failures becomes genuinely complicated, and so many questions come up. Why was the identity result rejected? Why wasn’t the certificate issued? Was the signing service unavailable? Which SLA applies?  

These are questions that have no clean answer when the process is split across multiple vendors. Each party has a different scope, different support processes, different contractual obligations. The quality of the service almost always suffers as a result. Consolidating all these services under one provider reduces all that.  

There's also a vendor management dimension that's becoming increasingly important. Under DORA and NIS2, financial institutions have real obligations around third-party risk and oversight. Working with one provider instead of two or three simplifies that significantly. 

Fourthline Trust Services AB is listed on the EU Trusted List, supervised by Sweden's PTS. What is a Trusted List, and why does it matter? 

If you're not on the Trusted List, you cannot issue qualified electronic signatures. Full stop. Getting listed requires passing a set of ETSI standards, being audited by an accredited conformity assessment body, and having that audit report verified by a national supervisory authority; in our case, PTS in Sweden. It’s only then does your name appear on the list. 

The Trusted List is essentially a public chain of trust; You can think of it somewhat like a browser trust store. When you see HTTPS on a website, you're trusting a public chain that connects that certificate back to a recognised root authority. The EU Trusted List works the same way. When a qualified signature is accepted in any EU member state, it's because the issuing provider is verified on that list. That public accountability is what gives qualified signatures their legal weight. 

AMLR applies from 10 July 2027. Where does QES fit into that picture? 

AMLR explicitly recognises two methods for customer identity verification: physical identity documents and eIDAS-based electronic identification. 

Within eIDAS-based identification, there are three recognised routes: the European Digital Identity (EUDI) Wallet, national eID schemes, and qualified trust services (including QES). So QES is directly in scope as a compliant onboarding method under AMLR. 

What are some advantages of QES compared to eID and EUDI Wallet?  

What makes QES so strong here is that it works uniformly across all member states. With eID, every country provides different data attributes (name, date of birth, etc.). The EUDI Wallet will face similar limitations initially.  

QES doesn't have any of those variations. It doesn't require any prior setup or awareness from the customer, and it provides a unified way of onboarding across all member states. So, because QES has harmonised legal recognition across the EU, Fourthline can consistently offer it across supported markets. 

There's also a forward-looking piece. In August 2027, V2 of the ETSI TS 119 461 standard comes into force. All QTSPs will need to ensure that the identity methods used for certificate issuance satisfy that framework, and will need to be audited against it. Because Fourthline offers both the identity verification and the certificate issuance, we can align to that standard once and deliver it as a single solution.  

What's next for Fourthline Trust Services?  

Looking ahead, there are a few strategic areas we are exploring. One is expanding further into the EUDI Wallet ecosystem, including qualified electronic attestations of attributes, which could allow verified attributes to be issued and used through European Digital Identity Wallets. At the same time, we see opportunities to broaden our signing capabilities beyond today's QES journey. That could include both qualified and non-qualified signatures, different models for one-time and returning users, and more flexible integration options for customers that already operate parts of their own identity or trust infrastructure. 

The broader direction is to make Fourthline's identity and trust capabilities available across a wider range of customer journeys, rather than requiring every customer to follow the same signing model. 

With AMLR applying from July 2027 and new identity proofing requirements for qualified certificate issuance following a month later, it's time to get your signing and onboarding infrastructure in order. If you'd like to understand what working with a single provider for both identity verification and qualified trust services could mean for your business, get in touch with the Fourthline team.  

Not sure where to start? Find out what a Qualified Trust Service Provider actually is. 

Fourthline has been certified by EY CertifyPoint to ISO/IEC27001:2022 with certification number 2021-039.

Copyright © 2026 - Fourthline B.V. - All rights reserved.

Fourthline has been certified by EY CertifyPoint to ISO/IEC27001:2022 with certification number 2021-039.

Copyright © 2026 - Fourthline B.V. - All rights reserved.