Comparison
Self-hosted TSA or eIDAS qualified timestamps?
Both give your documents a cryptographically verifiable date. The right choice depends on what matters more in your scenario: cost and speed at volume, or automatic legal recognition across the EU. Here is an honest side-by-side look.
Need eIDAS Qualified Timestamps?
We provide eIDAS Qualified Timestamps issued by a Qualified Trust Service Provider (QTSP) listed in the European Union Trusted Lists (EUTL) under the eIDAS Regulation. If you need qualified timestamps with full legal effect across the EU, visit our dedicated website qtsa.eu.
Visit qtsa.eu →| TSA Server (self-hosted) | eIDAS qualified timestamps (qtsa.eu) | |
|---|---|---|
| What it is | Your own RFC 3161 Time Stamping Authority, running on your Windows / IIS server, signing with your key and your policy. | Timestamps issued by a supervised Qualified Trust Service Provider, listed on the EU Trusted List. |
| Cost model | One-time license from 1450 EUR — unlimited timestamps forever, no per-token fees. High volume costs nothing extra. | Paid per timestamp. Affordable for documents that need it; expensive as a default for millions of objects. |
| Speed & volume | LAN latency, up to 100 timestamps/second, no rate limits, works in air-gapped networks. | Internet round-trip to the provider; subject to service quotas and connectivity. |
| Legal recognition | Standards-compliant proof under your own policy. Acceptance depends on the trust configuration of whoever validates it. | Automatic legal presumption across the EU under eIDAS — recognized out of the box by validation tools such as DSS and Adobe Acrobat. |
| Operations | You manage the TSA certificate (own CA, commercial CA or self-signed) and, if you want hardware key protection, an HSM. | Nothing to operate — keys, HSMs, audits and supervision are the provider's job. |
| Data location | Only hashes exist, and they never leave your network. | Only hashes are sent to the provider — no document content, but an external call per timestamp. |
| Best for | Bulk invoice and report sealing, LTA renewals for internal archives, log sealing for NIS2 / DORA, isolated networks, R&D proof of existence. | Contracts and documents with regulatory weight, cross-border disputes, anything a court or authority must accept without discussion. |
The practical rule of thumb
Choose the self-hosted TSA when volume rules
If you timestamp thousands of objects a day — invoices out of an ERP, archive batches, log digests — per-token pricing scales badly and an external call sits on your critical path. A one-time license with unlimited, LAN-speed timestamps wins on both cost and speed. The trade-off: the certificate, and optionally an HSM, are yours to manage.
Choose qualified when legal weight rules
If a document may end up in front of a court, a regulator or a business partner abroad, a qualified timestamp is accepted across the EU without any discussion about your internal setup — DSS, Adobe and public validators recognize it out of the box. The trade-off: each timestamp costs money.
Most of our customers combine the two: the internal TSA handles the high-volume workloads, and qualified timestamps from qtsa.eu seal the documents where EU-wide legal effect is worth paying for. The two share the same RFC 3161 protocol, so switching endpoints per workflow is a one-line configuration change.
Still not sure which fits your case?
Describe your workflow — document types, volumes, who validates them — and we'll give you a straight answer, even if that answer is "use the qualified service".