Certificate Renewal During the Validity Period

As of January 8, 2026, the ESS QCA certification authority has started issuing qualified certificates with 4096-bit RSA keys. All certificates issued before that date use 2048-bit RSA keys. Since this key length is no longer considered sufficiently secure, all users with an active certificate using a 2048-bit RSA key are now able to renew their certificate and upgrade to a 4096-bit RSA key during the certificate’s validity period. This process is completely free of charge for our users. Below you can find the certificate renewal procedure and instructions for upgrading to a 4096-bit RSA key.

 

  1. The certificate renewal process can be completed using the ESS QCA QSCD Manager application, available at: https://tqca.e-smartsys.com/repo/QCAQSCDMAN.zip. Clicking the link will download the application to your computer.
  2. Your certificate must be inserted into the card reader in order to complete this action. If your certificate indeed uses a 2048-bit RSA key, the following message will appear in red within the application: This certificate uses a 2048-bit RSA key and can be renewed during its validity period.
  3. After clicking the Renew During Validity Period button, your certificate details will be displayed. The new certificate will be issued with a 4096-bit RSA key, on the same card, with the same attributes, and with the same expiration date as the existing certificate.
  4. After clicking the Confirm Reissuance Request button, an OTP code will be sent to the email address associated with your certificate. Enter the code into the provided field and click the Verify OTP button.
  5. If the entered OTP code is correct, the following message will appear: “Your request has been successfully received and is pending processing.” Click the Back button and then click the Renew During Validity Period button again.