Independent public mirror of national PKI trust anchors, not an authority. Certificates are published by each national PKI (e.g., BCCR for Costa Rica); this site mirrors and structures them.
Certificates
16
Roots
5
Intermediates
11
did:pki
16
Updated
Model
Accredited CAs (ETSI Trusted List)
Governing law
Reglamento eIDAS (UE) 910/2014 · Electronic Identification and Trust Services for Electronic Transactions Act (EUTS)
Key algorithms
RSA-2048, RSA-4096, EC P-384, EC P-521
Signature standards
CAdESPAdESXAdESASiC-E
Revocation snapshot
current, refresh due Jan 28, 2027
CapabilitiesID-card (ESTEID)Mobiil-ID / Smart-ID (EID-Q)e-Seal (KLASS3, ORG)Qualified e-signature (eIDAS)

Estonia runs one of the world's most mature national eID systems. The state authority (RIA) contracts trust service providers to operate the PKI under eIDAS: SK ID Solutions AS historically, with the 2025 government root (EEGovCA2025 / ESTEID2025) now operated by Zetes Estonia OÜ. There are several roots rather than a single hierarchy, published via the Estonian ETSI Trusted List. The legacy EE Certification Centre Root CA (RSA-2048) is being retired and no longer issues new CAs, but remains a valid anchor for certificates already issued under it. First directory entry mixing RSA and EC (P-384 and P-521) roots. Phase 1 covers the national qualified anchors; roots were sourced from the SK ID Solutions repository and crt.eidpki.ee and cross-checked against SK's published SHA-1 fingerprints.