eIDAS certificates for PSD2: QWAC and QSealC explained
When a PISP calls a bank’s PSD2 interface, the bank has to answer one question before anything else: is this caller a licensed payment service provider? Under PSD2 the answer comes from eIDAS certificates. The regulatory technical standards on strong customer authentication require third-party providers to identify themselves to banks with qualified certificates, and two types are used.
QWAC: the transport certificate
A QWAC — qualified website authentication certificate — identifies the PISP at the connection level. The PISP presents it as the client certificate in a mutual TLS handshake, so the bank knows who is calling before a single request is read.
A QWAC proves identity and protects the channel. It does not, on its own, prove that a particular message came from the PISP unaltered once the TLS session has ended.
QSealC: the signing certificate
A QSealC — qualified certificate for electronic seals — is used to sign the messages themselves. The PISP signs each request, or a digest of it, and the bank can verify long after the fact that the instruction came from that PISP and was not changed in transit. It gives the bank evidence, not just a secure pipe.
Do you need both?
In practice, yes. Banks vary: nearly all require a QWAC for mutual TLS, and many — particularly under Berlin Group NextGenPSD2 — also require every request to be signed with a QSealC. Because requirements differ bank by bank, a PISP that wants broad coverage holds both. MVP Payments will not switch an account to bring-your-own-licence mode until both are installed.
What is inside a PSD2 certificate
PSD2 certificates are ordinary X.509 certificates carrying additional attributes defined by the ETSI standard TS 119 495:
- The authorisation number, in a structured form that identifies the country, the regulator and the firm’s entry on that regulator’s register.
- The PSD2 roles the firm is authorised for.
PSP_PIis payment initiation,PSP_AIis account information,PSP_ICis card-based instrument issuing, andPSP_ASis account servicing — the bank’s own role. - The name of the national competent authority that granted the authorisation.
The bank reads these attributes on every call. A certificate without the
PSP_PI role cannot initiate a payment, whatever the firm’s licence says.
Where certificates come from
Only a qualified trust service provider (QTSP) can issue them — a certificate authority supervised under the eIDAS Regulation and listed on the EU Trusted List. The QTSP verifies the firm’s identity and checks its authorisation against the regulator’s public register before issuing, and certificates are typically valid for one or two years.
Two practical points follow.
- A certificate can only be issued after authorisation, because the QTSP needs a register entry to verify. For integration work before then, bank sandboxes generally accept test certificates — and the MVP Payments sandbox needs none at all.
- Certificates issued by a QTSP in one member state are valid across the EU. A Lithuanian PISP does not need German certificates to reach German banks.
Revocation and expiry
If a firm’s authorisation is withdrawn, its regulator can ask the QTSP to revoke the certificates, and banks are expected to check. That is the mechanism that keeps the register and the network in step.
Expiry is the more common problem. An expired QWAC stops every payment at every bank at the same moment, and it is entirely avoidable. Track expiry dates as operational risks, renew with weeks in hand, and rotate deliberately — new certificate installed and proven before the old one lapses. MVP Payments scans every certificate on the platform daily and raises warnings 30 and 7 days ahead of expiry.
The United Kingdom: OBWAC and OBSeal
After Brexit, UK firms could no longer obtain eIDAS certificates with UK authorisation numbers, and the Financial Conduct Authority changed its rules to allow other certificate types. The UK Open Banking Directory issues its own equivalents to enrolled firms:
| Purpose | EU and EEA | United Kingdom |
|---|---|---|
| Transport — mutual TLS | QWAC | OBWAC |
| Signing | QSealC | OBSeal |
| Issued by | Any qualified trust service provider | The UK Open Banking Directory |
| Proves | Authorisation by an EU or EEA regulator | Authorisation or registration with the FCA |
A PISP working in both the EU and the UK therefore holds two sets of certificates, tied to two authorisations.
Whose certificates, under whose licence
Certificates are the technical expression of the licence, so whoever’s certificates reach the bank is, as far as the bank is concerned, the PISP. When a merchant uses an aggregator, the bank sees the aggregator’s certificates. In the bring-your-own-licence model, the bank sees yours: the infrastructure is shared, the regulated identity is not.
That makes key custody the central question to ask any technical provider. Private keys belong in a dedicated, encrypted secrets store — never in a database, a log or a source repository — with audited access and deliberate, confirmed rotation. For what else to ask, see our guide to outsourcing to a technical service provider.