Qualified Digital Signing at Scale for the EU Market

Table of Contents

Enabling Trusted, eIDAS-Compliant Remote Signatures. Powering Secure and Compliant Digital Transactions.

A leading European provider of digital signing and workflow automation software helps organizations streamline client onboarding, document management, and ongoing risk assessment. Its platform delivers secure electronic signatures using national electronic identities and supports integrated compliance workflows for regulated industries. Following rapid growth and platform expansion, the provider continued to scale its services to support high-volume, regulated digital transactions across multiple European markets.

To meet growing demand, the organization required a qualified remote digital signing solution that could integrate seamlessly into existing workflows, support multiple identity providers and trust components, comply with eIDAS, ETSI, and ISO 27001, and scale efficiently without per-signature cost constraints,while delivering the highest level of digital trust in the European market.

ISS Solution: Digital Signatures & Signing, part of ILM

ISS deployed its Identity Lifecycle Management (ILM) platform for Digital Signatures & Signing, enabling the provider to deliver trusted and qualified remote signing services at scale. The solution provides comprehensive support for qualified electronic signatures, sealing, and timestamping, integrating with certification authorities, Common Criteria-certified QSCDs, and Signature Activation Modules (SAMs). ILM enables users to securely sign documents from any location, at any time, while ensuring sole control, non-repudiation, and regulatory compliance.

Built on a cloud-native, vendor-agnostic architecture, ILM allows the platform to adapt cryptographic components over time, switching providers or authorities as needed, while remaining compliant and future-proof.

Key Capabilities Delivered

  • eIDAS-compliant qualified remote signing, sealing, and timestamping
  • High-capacity signing infrastructure with no marginal cost per additional signature
  • Standards-based interfaces to avoid vendor lock-in
  • Cloud-native architecture for scalability and operational efficiency
  • Support for all eIDAS signature levels, from advanced to qualified
  • Crypto agility to rapidly adapt to algorithm and regulatory changes

Results

  • Trusted, qualified digital signing services aligned with EU regulatory requirements
  • Scalable signing operations supporting platform growth and high transaction volumes
  • Improved customer trust through certified and auditable signing workflows
  • Future-proof cryptographic foundation supporting new use cases and providers
  • Seamless integration into Penneo’s existing digital trust and compliance platform

Popular Case Studies

Smart Cities & Infrastructure

A global electric vehicle manufacturer needed to support ISO 15118-compliant Plug & Charge across its growing network of vehicles, charge points, and service providers. As EV adoption accelerated, the company required a unified trust infrastructure that could authenticate vehicles, chargers, and mobility service providers automatically — eliminating user friction while maintaining cryptographic control and compliance with international standards.

Smart Cities & Infrastructure

Smart infrastructure operators face escalating risks as PLCs, SCADA systems, elevators, building management systems (BMS), and connected city services converge on digital networks. These assets are long-lived, safetycritical, and regulated under IEC 62443, SIL 3/4, and NIST SP 800-82. Challenges include legacy assets with expired credentials, PLC-driven elevators integrated into fire and BMS systems, and emergency phone lines converted to IP/VoIP, creating new attack surfaces. SCADA/DCS controllers managing power, water, and city services are also exposed to cyber and compliance risks, compounded by fragmented visibility across suppliers and infrastructure. To meet safety and regulatory demands, operators require a resilient, audit-ready trust foundation ensuring compliance and uptime.

Power, Energy & Utilities

A leading U.S. power utility needed to secure and modernize its digital trust infrastructure across IT and OT networks. With thousands of certificates, keys, and secrets spread across enterprise applications, SCADA devices, and mobile endpoints, the risk of outage, cyberattack, and compliance gaps was rising sharply. At the same time, the organization faced increasing regulatory pressure and had committed to a full digital transformation by 2030, requiring a more resilient, unified trust foundation.

Resource Library

Post-Quantum Cryptography Implementation Guide

Deep dive into post-quantum crypto deployment strategies for embedded systems

Post-Quantum Cryptography Implementation Guide

Deep dive into post-quantum crypto deployment strategies for embedded systems
Ready to Secure Your Trust Lifecycle?

Let's secure your entire trust lifecycle from the physical edge to the cloud, the sea, and beyond.