Skip to main content

ETSI and NIST Technical Standards

Overview of key ETSI and NIST standards guiding our cryptographic design and signature validation, including eIDAS, and FIPS 204.

Updated over 8 months ago

Purpose of This Document

This article outlines the core ETSI and NIST technical standards that underpin the cryptographic implementations in Virifi’s Solution Proposal. These standards ensure interoperability, legal compliance, and resilience to both current and emerging threats — including quantum-based attacks.


ETSI (European Telecommunications Standards Institute)

ETSI provides the technical specifications for eIDAS-compliant electronic signatures used across the EU and by regulated entities globally. The following standards are directly implemented:


Signature Format Standards

  • ETSI EN 319 142-1 (PAdES)

    Digital signatures embedded into PDF files.

  • ETSI EN 319 132-1 (XAdES)

    XML-based digital signature structures for data contracts, workflows.

  • ETSI TS 119 182-1 (JAdES)

    JSON-compatible signatures aligned with JOSE, for APIs and modern applications.

  • ETSI EN 319 122-1 (CAdES)

    Signatures for CMS-based (binary) systems, system-to-system communication.


Validation & Reporting

  • ETSI TS 119 102-2 – Signature Validation Reports (XAdES, PAdES, etc.)

    Provides machine-readable validation status and diagnostics.


NIST (National Institute of Standards and Technology)

NIST defines cryptographic standards for secure digital signatures and key management, widely adopted in both federal and international domains.


Post-Quantum Cryptography

  • FIPS 204 – ML-DSA (Module-Lattice-Based Digital Signature Algorithm)

    Post-quantum secure signature algorithm used in our Cloud HSM configurations.


Traditional Standards (Referenced Where Applicable)

  • FIPS 140-2 / 140-3 – Hardware cryptographic module validation

  • FIPS 186-5 – Digital Signature Standard (covers RSA, DSA, ECDSA)

  • SP 800-57 / SP 800-131A – Key management, cryptoperiods, algorithm transition guidelines


Why These Standards Matter

  1. Compliance with CBJ Requirements – Both ETSI eIDAS and NIST standards are explicitly referenced in the CBJ Digital Signature Challenge.

  2. Legal Validity – ETSI ensures signatures hold weight across EU and affiliated jurisdictions.

  3. Security Future-Proofing – FIPS 204 aligns with post-quantum strategy.

  4. Technical Interoperability – Systems that use these standards are compatible across regulated financial infrastructures.

Did this answer your question?