Trust Service Provider Concentration .

 

Trust Service Provider Concentration

1. Meaning and Background

Trust Service Provider (TSP) concentration describes a market situation in which a small number of firms control a substantial share of the infrastructure used to establish trust in electronic transactions.

Under the EU framework, trust services include services connected with electronic signatures and seals, electronic timestamps, electronic registered delivery, electronic attestations of attributes, electronic archiving and certificates used for signatures, seals and website authentication. A provider may operate as either a qualified or non-qualified trust service provider.

Concentration becomes important for competition law because trust services can function as an essential gateway into digital markets. Banks, government agencies, healthcare organisations, online platforms and ordinary businesses may depend on recognised certificates or signatures before a transaction can be completed.

The competition concern is therefore not simply that a provider becomes large. The issue arises where concentration gives one or a few providers the ability to exclude rivals, discriminate between customers, raise switching costs, impose restrictive contractual conditions or control access to an important technical infrastructure.

2. Why Trust Service Markets May Become Concentrated

Trust-service markets have several characteristics that can encourage concentration.

Regulatory entry barriers

Qualified trust services cannot normally be supplied merely by entering the market. Under the EU framework, a prospective qualified provider must undergo conformity assessment and obtain qualified status from the relevant supervisory authority. Qualified status is reflected in official Trusted Lists.

Compliance, cybersecurity, auditing, insurance, infrastructure and certification costs can therefore make entry relatively expensive.

Reputation and trust

Customers handling important transactions often prefer providers with a long operating history and recognised reputation.

A new provider may therefore face a circular problem:

few customers → limited reputation → difficulty attracting customers → difficulty achieving scale.

Network and ecosystem effects

Trust services become more valuable when certificates, signatures and verification mechanisms are recognised by many institutions.

Large providers may therefore obtain advantages from existing integrations with banks, governments, cloud services, document-management systems and enterprise software.

Switching costs

Changing TSPs may require organisations to replace certificates, migrate records, modify APIs, retrain employees and reconfigure verification systems.

These costs can create customer lock-in.

Cross-border recognition

Recognition across jurisdictions can also affect competition. The EU framework was specifically designed to enable cross-border use of trust services.

A provider with recognition and integrations across several countries may therefore enjoy substantial advantages over a smaller domestic provider.

The UK provides an interesting current example. The UK government reported in 2026 that there were no UK-registered qualified trust service providers, with organisations continuing to rely heavily on EU-regulated providers. It identified certification costs, regulatory complexity, interoperability and market awareness among relevant barriers.

3. Relevant Market Definition

Competition analysis normally begins by identifying the relevant product and geographic market.

It would usually be inappropriate simply to define one broad market called "digital trust."

Potential product markets could include:

  • qualified electronic signatures;
  • qualified electronic seals;
  • timestamping;
  • website authentication certificates;
  • electronic registered delivery;
  • electronic archiving;
  • electronic attestations of attributes;
  • signature-validation services; and
  • remote signature-device management.

The EU framework itself recognises these as distinct trust-service functions.

A competition authority would examine whether customers could realistically substitute one provider or service for another when prices or contractual conditions changed.

The geographic market could be national, EEA-wide or potentially wider depending on regulatory recognition, technical interoperability and customer requirements.

4. Concentration Does Not Automatically Mean Abuse

A fundamental distinction must be maintained:

high concentration ≠ automatically unlawful conduct.

A firm may legitimately become large because it provides better security, interoperability, reliability or prices.

Competition concerns generally require something more, such as restrictive agreements under Article 101 TFEU, or abusive conduct by a dominant undertaking under Article 102 TFEU.

The important questions are therefore whether the provider possesses substantial market power and, if so, how that power is being exercised.

5. Main Competition Risks

Refusal of access

A dominant provider might control infrastructure that downstream competitors need for verification or authentication.

Competition questions become particularly significant where the input is genuinely indispensable and competitors cannot realistically duplicate it.

Discriminatory interoperability

A provider could technically support its own products while making competing products difficult to integrate.

Examples could include discriminatory API access, certificate-validation rules or compatibility requirements.

Excessive switching barriers

Long contracts, proprietary certificate formats, expensive migration procedures or restrictions on exporting verification records may make customers dependent upon one provider.

Tying and bundling

A powerful TSP could link one service with another.

For example:

certificate + validation + timestamping + document-signing platform

Bundling can create efficiencies, but competition concerns may arise where customers effectively have to purchase an unwanted service to obtain access to a service in which the supplier has substantial market power.

Margin squeeze

A vertically integrated provider might sell an essential upstream trust service to downstream competitors while competing against those companies in the downstream market.

Competition problems can arise where the relationship between upstream and downstream prices makes effective downstream competition extremely difficult.

Exclusive agreements

A TSP might enter exclusive arrangements with major banks, government bodies, platforms or software vendors.

Exclusivity is not automatically unlawful, but widespread agreements may create foreclosure problems where competitors cannot obtain sufficient customers or distribution.

Manipulation of regulatory processes

Because qualified trust services operate within certification and supervisory frameworks, misuse of regulatory mechanisms can itself become relevant to competition analysis in appropriate circumstances.

6. Important Case Laws

There are relatively few major EU competition judgments specifically dealing with modern qualified trust-service-provider concentration. The following cases are therefore important because they establish competition principles directly applicable by analogy to certification, digital infrastructure, interoperability, platform access and concentrated trust-service markets.

Case 1 — Oscar Bronner GmbH v Mediaprint

Case C-7/97

This is one of the central EU cases concerning refusal of access to infrastructure.

Mediaprint operated a major newspaper home-delivery system. A smaller newspaper publisher sought access to that network and argued that refusal amounted to abuse of dominance.

The Court adopted demanding conditions before competition law can require a dominant company to provide competitors access to its infrastructure.

The case is particularly relevant to TSP concentration where a provider controls verification or authentication infrastructure that another company claims it cannot realistically reproduce.

The central lesson is that merely showing that access would make competition easier is insufficient. Indispensability and the competitive consequences of refusal become crucial considerations.

This judgment remains foundational to the EU essential-facilities analysis.

Case 2 — IMS Health GmbH v NDC Health

Case C-418/01

IMS Health controlled a data structure used for pharmaceutical sales information.

Competitors sought access to the structure, creating questions concerning intellectual property rights and refusal to license an input required for competition.

The Court developed the circumstances in which refusal by a dominant undertaking to license protected material could amount to abuse.

For TSP markets, IMS Health is relevant where proprietary standards, certificate structures, databases or technological interfaces become extremely difficult for competing services to avoid.

It demonstrates the interaction between:

intellectual property + interoperability + indispensability + competition law.

A dominant provider's ownership of technology does not automatically create an obligation to share it, but exceptional circumstances can bring Article 102 into operation.

Case 3 — Microsoft v Commission

Case T-201/04

The Microsoft litigation is particularly useful for analysing interoperability.

The Commission found competition problems concerning Microsoft's refusal to provide certain interoperability information for work-group server operating systems and its tying of Windows Media Player.

The General Court substantially upheld the Commission's decision.

The reasoning is highly relevant to digital trust infrastructure because TSP markets similarly depend upon interoperability.

For example, competition concerns could arise where a dominant provider's certificate or validation ecosystem technically prevents rival services from communicating effectively with widely adopted infrastructure.

The case demonstrates that interoperability restrictions can become competition-law issues where they protect dominance and seriously restrict competition in neighbouring markets.

Case 4 — TeliaSonera

Case C-52/09

TeliaSonera concerned telecommunications infrastructure and margin squeeze.

The undertaking supplied upstream ADSL services while also operating in the downstream broadband market.

The Court addressed whether the relationship between the upstream price charged to competitors and the downstream retail price could constitute an abuse under Article 102.

It confirmed that margin squeeze can constitute a distinct form of abusive conduct.

This principle could apply to vertically integrated trust-service markets.

Suppose a dominant provider supplies certificate infrastructure to competing electronic-signature platforms while simultaneously operating its own signature platform.

A pricing structure that prevents equally efficient downstream competitors from competing effectively could potentially raise margin-squeeze concerns.

Case 5 — AstraZeneca v Commission

Case C-457/10 P

AstraZeneca is important because it demonstrates how competition law can interact with regulatory procedures.

The case concerned conduct involving supplementary protection certificates and marketing-authorisation procedures. The Court upheld findings concerning abuse of dominant position involving misleading representations and conduct affecting market entry by generic products and parallel imports.

Its significance for TSP markets lies in the regulatory dimension.

Trust-service providers operate within systems involving supervisory approval, conformity assessment, certification and Trusted Lists.

A dominant company using regulatory procedures strategically to obstruct competitors could therefore face competition scrutiny depending on the circumstances.

Case 6 — Groupement des Cartes Bancaires v Commission

Case C-67/13 P

This case concerned the French payment-card system and measures affecting new entrants.

The Court emphasised that the concept of a restriction of competition "by object" must be interpreted restrictively. The legal and economic context of the arrangement matters.

The case is especially useful for trust-service ecosystems because payment networks and trust infrastructures share certain characteristics:

standards + networks + membership rules + interoperability + new-entry conditions.

Rules established by an industry network should therefore not automatically be labelled anticompetitive merely because they disadvantage some participants.

Authorities must examine their purpose, content and economic and legal context.

Case 7 — AC-Treuhand AG v Commission

Case C-194/14 P

AC-Treuhand was a consultancy firm that assisted cartel participants even though it did not itself operate in the cartelised product markets.

The Court confirmed that an undertaking can fall within Article 101 where it actively and knowingly contributes to implementing an anticompetitive arrangement, even though it operates in a different market.

This principle has considerable relevance to trust-service ecosystems.

A TSP, certification intermediary or technical service company could potentially incur competition liability if it knowingly facilitates coordination among competing companies—for example by administering mechanisms used to implement prohibited market allocation or information exchange.

Simply describing itself as a technical intermediary would not necessarily remove competition-law responsibility.

Case 8 — Deutsche Telekom v Commission

Case C-280/08 P

Deutsche Telekom is another important margin-squeeze judgment.

The company controlled important telecommunications infrastructure while simultaneously competing in downstream markets.

The case established important principles concerning Article 102 and vertically integrated infrastructure providers.

Its relevance to trust-service concentration arises where a dominant TSP simultaneously controls an essential upstream certification or validation function and sells competing downstream digital services.

The telecommunications analogy is particularly useful because both markets may involve:

infrastructure dependence → interoperability → high entry costs → downstream competition.

7. Role of Trusted Lists

Trusted Lists deserve special attention in concentration analysis.

Under the EU framework, qualified status is tied to inclusion in the relevant national Trusted List. The European Commission explains that these lists have legal significance and enable users and market participants to determine whether a provider and its services possess qualified status.

Consequently, regulatory recognition itself can become an important competitive gateway.

Competition analysis may therefore examine whether:

  • qualification requirements are transparent;
  • competing providers can obtain recognition on equivalent terms;
  • technical standards are genuinely necessary;
  • incumbents influence certification requirements;
  • foreign providers face unjustified disadvantages; and
  • recognition rules create unnecessary entry barriers.

8. Standards and Certification Risks

Technical standards are normally beneficial in trust-service markets because signatures and certificates need interoperability and security.

However, competition problems may arise if incumbent providers control standard-setting processes.

For example, incumbents could potentially design requirements that disproportionately increase rivals' costs or make proprietary incumbent technology effectively mandatory.

The competition analysis would need to distinguish genuine cybersecurity and reliability requirements from rules whose practical effect is unjustified foreclosure.

This distinction is particularly important because qualified TSPs are subject to regulatory assessment, supervision and security requirements.

9. Merger and Acquisition Concerns

Concentration may also result from mergers between TSPs.

Authorities examining a hypothetical merger between two major providers could consider:

Horizontal effects: whether removing one independent provider materially reduces customer choice.

Vertical effects: whether the merged provider could restrict access to certificates, identity verification, signing infrastructure or validation services required by downstream competitors.

Conglomerate effects: whether the combined company could bundle trust services with cloud platforms, cybersecurity products, digital identity services or document-management software.

Particular attention may be given to customer switching costs and whether smaller competitors can obtain the inputs and interoperability necessary to compete.

10. Possible Defences and Objective Justifications

Restrictions in trust-service markets are not necessarily anticompetitive.

A provider may justify particular requirements on grounds such as:

  • cybersecurity;
  • fraud prevention;
  • certificate integrity;
  • regulatory compliance;
  • identity verification;
  • system stability;
  • data protection; or
  • interoperability.

These considerations can be particularly significant because trust-service providers perform security-sensitive functions.

The competition analysis therefore needs to ask whether the restriction is genuinely necessary and proportionate, rather than assuming that every technical restriction constitutes exclusion.

11. Practical Competition-Law Framework

A useful assessment can be organised around the following sequence:

Market definition → market shares and concentration → barriers to entry → regulatory qualification → interoperability → switching costs → network effects → conduct of dominant providers → actual or likely foreclosure → objective justification → consumer and efficiency effects.

The strongest competition concerns normally arise when several factors operate together.

For example:

high market share + regulatory barriers + network effects + proprietary standards + customer lock-in + exclusionary conduct

creates a much stronger competition concern than market share alone.

Conclusion

Trust Service Provider concentration sits at the intersection of competition law, cybersecurity, digital identity, certification and platform regulation. Modern EU rules give trust services an increasingly important role in electronic signatures, seals, timestamps, certificates and other digital transactions.

The principal competition risk is not concentration by itself. It is the possibility that control over trusted digital infrastructure allows a powerful provider to exclude competitors through refusal of access, discriminatory interoperability, tying, exclusivity, margin squeeze, excessive switching barriers or strategic use of regulatory procedures.

LEAVE A COMMENT