Renewal 2048 4096
Certificate Renewal During the Validity Period
As of January 8, 2026, the ESS QCA certification authority has started issuing qualified certificates with 4096-bit RSA keys. All certificates issued before that date use 2048-bit RSA keys. Since this key length is no longer considered sufficiently secure, all users with an active certificate using a 2048-bit RSA key are now able to renew their certificate and upgrade to a 4096-bit RSA key during the certificate’s validity period. This process is completely free of charge for our users. Below you can find the certificate renewal procedure and instructions for upgrading to a 4096-bit RSA key.
- The certificate renewal process can be completed using the ESS QCA QSCD Manager application, available at: https://tqca.e-smartsys.com/repo/QCAQSCDMAN.zip. Clicking the link will download the application to your computer.
- Your certificate must be inserted into the card reader in order to complete this action. If your certificate indeed uses a 2048-bit RSA key, the following message will appear in red within the application: This certificate uses a 2048-bit RSA key and can be renewed during its validity period.
- After clicking the Renew During Validity Period button, your certificate details will be displayed. The new certificate will be issued with a 4096-bit RSA key, on the same card, with the same attributes, and with the same expiration date as the existing certificate.
- After clicking the Confirm Reissuance Request button, an OTP code will be sent to the email address associated with your certificate. Enter the code into the provided field and click the Verify OTP button.
- If the entered OTP code is correct, the following message will appear: “Your request has been successfully received and is pending processing.” Click the Back button and then click the Renew During Validity Period button again.
Issuance of a qualified certificate for electronic signature
Issuance of a qualified certificate for electronic signature
Issuance of a new qualified electronic signature certificate is performed in three steps:
- validation of the e-mail address to be entered in the certificate body,
- entering data on the user of the certificate,
- identification, issuance and delivery in the chosen RA.
On this page, you can start the process by entering your email address. You must confirm the email address within 24 hours of receiving the “one-time” link.
Please take this opportunity to familiarize yourself with the privacy and personal data protection policy that ESS QCA applies in the process of processing your personal data for the purposes of issuing qualified certificates.
New subscriber registration
New subscriber registration
All legal entities that are not registered subscribers of ESS QCA must first go through the registration process in order to be able to submit requests for issuing qualified electronic signature certificates for their employees (natural persons belonging to legal entities). Registration process for new subscriber within ESS QCA is done in four steps:
- Verification of company registration number and submission of a registration request
- Processing of the request within the RA body and sending email with link for downloading the contract
- Downloading the contract by the subscriber and attaching the signed version of the contract
- Verification of the signed contract within the RA body – completion of the subscriber registration process
Below you can start the process by entering information about the legal entity and attaching (uploading) the Verified Signature form (OP form). After submitting the registration request, further instructions, and notifications about the progress of the process will be sent to the email address of the legal entity.
*The exchange of contracts is done via link that will be sent via email later in the process, and within which the subscriber will be able to download the contract and attach (upload) the signed version of it.
Issuance of a qualified certificate for electronic signature OTP
Issuance of a qualified certificate for electronic signature
Reissuing a qualified certificate for electronic signature OTP
Reissuing a qualified certificate for electronic signature
Change the data of a qualified certificate for electronic signature OTP
Change the data of a qualified certificate for electronic signature
Reissuance of a qualified certificate for an electronic seal OTP
Reissuming a qualified certificate for electronic seal
Issuance of a qualified certificate for an electronic seal OTP
Issuance of a qualified certificate for an electronic seal
Reissuming a qualified certificate for electronic seal
Reissuance of a qualified certificate for an electronic seal
The reissue process refers exclusively to valid/active qualified certificates for electronic seal issued in ESS QCA. The application for reissuance can be submitted only within 30 days until the expiry of the certificate. Reissuance involves issuing a new certificate, the cost of which is at the expense of the user.
The reissuance of qualified certificates for electronic seal is carried out in four steps:
- logging with the existing qualified certificate for electronic seal for which it is necessary to apply for reissue,
- the entry of a request for reissuance,
- validation of the e-mail address to be entered in the certificate authority,
- issuing and awarding certificates in the selected RA authority.