Recent amendments to two by-laws governing electronic business introduce significant technical, as well as practical, changes for qualified trust service providers, issuers of qualified electronic certificates, and users of electronic signatures and electronic seals.
The amendments concern the Rulebook on the Requirements to be Met by Qualified Electronic Signature and Electronic Seal Creation Devices and by Designated Bodies, as well as the Rulebook on the Requirements to be Met by Qualified Electronic Certificates. Although the amendments may appear highly technical at first glance, their significance is broader, as the Serbian regulatory framework is increasingly aligned with European ETSI standards and solutions developed within the eIDAS framework.
With regard to qualified electronic signature and seal creation devices, one of the key changes is the departure from prescribing specific cryptographic algorithms and minimum parameters in detail. Instead, the selection of asymmetric cryptographic algorithms, hash functions and their combinations is linked to ETSI TS 119 312 “Cryptographic Suites”.
- This approach enables the regulatory framework to keep pace with developments in cryptographic standards without requiring an amendment to the relevant by-law each time technological standards evolve.
- The amendments also place additional emphasis on reliable user authentication, the ability to use qualified devices across different applications and IT environments, accessibility of trust services for persons with disabilities, and the requirement that, in the case of remotely managed qualified devices, the user retains exclusive control over the data used to create an electronic signature or seal.
At the same time, the amendments concerning qualified electronic certificates introduce more detailed requirements regarding the content of certificates and their technical designation.
Particular attention should be given to:
- the determination and documentation of the Certificate Policy Identifier (OID) in accordance with ETSI EN 319 411-1;
- the mandatory use of the relevant qcStatements in accordance with ETSI EN 319 412-5;
- the clear distinction between certificates for electronic signatures, electronic seals and website authentication;
- the designation of the Republic of Serbia as the applicable jurisdiction through “QcCClegislation – RS”; and
- more precise identification of cases in which the private key is held in a qualified signature or seal creation device compliant with the eIDAS framework, as opposed to a device meeting the requirements prescribed under Serbian law.
An important transitional provision stipulates that qualified certificates issued before the new rules become applicable, and which remain valid as of that date, may continue to be used until their expiry. For qualified trust service providers, this means that the transitional period should be used to review their Certificate Policy and Certification Practice Statement (CPS) documentation, certificate profiles, OID identifiers, qcStatements, cryptographic configurations and remote signing solutions.
For users and businesses, these amendments provide a clearer and more up-to-date framework for electronic transactions, based on internationally recognised standard, especially considering that electronic signatures are increasingly used for the execution of contracts, banking and corporate processes, as well as cross-border transactions.
For additional information or consultations, the Tasić & Partners team is at your disposal.