Regulations & Standards

Compliance
Center

Your guide to the regulations and standards that shape certificate management — what each one requires, who it applies to, and how EverTrust solutions help you meet it.

eIDAS 2.0

EU Regulation

The European framework for electronic identification and trust services, establishing standards for digital signatures, seals, timestamps, and website authentication certificates.

Digital Identity Trust Services Qualified Certificates

GDPR

EU Regulation

The General Data Protection Regulation mandates robust data protection measures, where PKI and certificate management play a critical role in ensuring encrypted communications and data integrity.

Data Protection Privacy Encryption

DORA

EU Regulation

The Digital Operational Resilience Act sets requirements for ICT risk management in the financial sector, including cryptographic key management and certificate governance.

Financial Services ICT Risk Operational Resilience
Upcoming

Cyber Resilience Act

EU Regulation

New horizontal cybersecurity requirements for products with digital elements, imposing secure-by-design obligations including certificate and cryptographic material management.

Product Security IoT Software Supply Chain

EU Cybersecurity Act

EU Regulation

Establishes the ENISA cybersecurity certification framework for ICT products, services, and processes. Supports certification posture management and compliance with EUCC schemes.

ENISA Certification Framework EUCC

NIS2 Directive

EU Directive

Strengthened cybersecurity obligations for essential and important entities across the EU, with expanded scope covering certificate management and PKI infrastructure.

Cybersecurity Critical Infrastructure Risk Management

PSD2

EU Directive

The Payment Services Directive mandates QWACs and Qualified Seals for payment service providers and TPPs, requiring robust PKI for secure open banking APIs.

Open Banking QWACs Payment Services

CER Directive

EU Directive

The Critical Entities Resilience Directive complements NIS2 for physical and cyber resilience of critical entities, requiring certificate-based access control for critical infrastructure.

Critical Entities Resilience Access Control
Upcoming

EU Digital Identity Wallet

EU Framework

The EUDI Wallet framework extends eIDAS 2.0, creating massive PKI demand for wallet credential issuance at scale — from qualified electronic attestations to person identification data.

Digital Identity Wallet Verifiable Credentials

RGS

National Regulation

The Referentiel General de Securite defines security requirements for French public administration information systems, mandating ANSSI-accredited certificates for government services.

France ANSSI Public Administration

LPM

National Regulation

The Loi de Programmation Militaire imposes strict security obligations on Operators of Vital Importance (OIV), including cryptographic controls and certificate management for critical national infrastructure.

France OIV National Defense

IT-Sicherheitsgesetz / BSI

National Regulation

Germany's IT Security Act and BSI standards require KRITIS operators to implement robust cryptographic controls. BSI TR-03145 governs CA operations and certificate management.

Germany BSI KRITIS

ENS

National Regulation

Spain's Esquema Nacional de Seguridad establishes digital certificate requirements for e-government services, mandating certificate inventory and lifecycle management at Medium and High assurance levels.

Spain E-Government Security Framework

Perimetro di Sicurezza Nazionale Cibernetica

National Regulation

Italy's National Cybersecurity Perimeter mandates PKI-based access control and certificate-based authentication for strategic organizations operating within the national cyber perimeter.

Italy Cyber Perimeter Strategic Infrastructure

ISO/IEC 27099

International Standard

The dedicated PKI certificate lifecycle management standard, directly mapping to discovery, governance, and automation workflows for certificate operations.

PKI Lifecycle Certificate Management Governance

PCI DSS v4.0

Industry Standard

Payment Card Industry Data Security Standard requires strict certificate lifecycle management for securing cardholder data environments and encrypted communications.

Payment Security TLS/SSL Key Management

SOC 2 Type II

Industry Standard

Service Organization Control audit framework requiring demonstrable key lifecycle management, certificate rotation policies, HSM usage, and comprehensive audit logging.

Audit Key Rotation Trust Services Criteria

ETSI EN 319 Standards

Technical Standard

European standards (EN 319 401, 411, 412) defining general policy and security requirements for Trust Service Providers, governing PKI operations, qualified certificate issuance, and TSP compliance.

Trust Services Qualified Certificates TSP Requirements
Why it matters

PKI is at the heart of
every compliance framework

From encrypting sensitive data to authenticating digital identities, certificates are the foundational layer that enables regulatory compliance. As regulations multiply and tighten, managing your PKI infrastructure becomes a strategic imperative — not just a technical task.

47
days: new maximum TLS certificate lifespan by 2029
€10M+
potential fines under NIS2 for non-compliance
160k+
entities newly in scope under NIS2 across the EU
100%
of these frameworks require robust certificate management

Need help navigating compliance?

Our team of PKI and compliance experts can help you understand regulatory requirements and implement the right certificate management strategy.

Get in touch