What a timestamp is
Article 41 of the eIDAS Regulation governs electronic time stamps and states that legal effect cannot be denied to them merely for being electronic. Article 42 sets the requirements for a qualified time stamp.
A qualified time stamp enjoys a presumption of accuracy of the date and time and of the integrity of the data it binds.
The document hash
The underlying mechanism is a cryptographic hash: a digest of the content that changes completely if a single character changes. What gets stamped is the hash, not the document.
That is why a stamp can be verified without revealing the content: recompute the hash and compare.
Blockchain anchoring
Publishing the hash on a public chain adds an independent witness to the date, one that does not depend on the provider still existing ten years from now.
It does not replace the qualified time stamp, which is the one expressly recognised in the regulation. It complements it.
What an auditor usually asks for
- A timestamp applied at the moment of signing
- The document hash stored alongside the document itself
- A documented integrity verification procedure
- Verification possible without relying on the original provider
How integrity is stamped in Kimobox
- 1Enable timestamping on the document types that need it.
- 2Turn on blockchain anchoring for critical records.
- 3Run a full verification at least once, so you know how it is done.
Verification is learned before you need it, not on the day you have to produce it.
Where each figure comes from
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
- Regulation (EU) 910/2014 (eIDAS) on electronic identification and trust services EUR-Lex · 23/07/2014
- Regulation (EU) 2024/1183, European digital identity framework (eIDAS 2) EUR-Lex · 11/04/2024
- Spanish Law 6/2020 on certain aspects of electronic trust services BOE-A-2020-14046 · 12/11/2020