Skip to content

Evidence request lists

eIDAS 2.0 - EU Digital Identity Regulation

Evidence request list. 55 controls, 55 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

eIDAS - Electronic Archiving and Ledgers

EIDAS-Art.45j
Qualified electronic archiving services

Provides that electronic archiving data shall not be denied legal effect solely for being electronic (Art 45i), and that a qualified electronic archiving service (Art 45j) must use procedures and technologies capable of ensuring the durability, integrity and legibility of the archived electronic documents/data beyond the technological validity period, provided by a qualified trust service provider.

Artefacts an auditor will ask for
  • Qualified archiving procedures ensuring durability/integrity/legibility
Where this commonly fails
  • Archiving without measures to preserve integrity over time
EIDAS-Art.45l
Qualified electronic ledgers

Provides that an electronic ledger shall not be denied legal effect solely for being electronic or non-qualified (Art 45k), and that a qualified electronic ledger (Art 45l) enjoys a presumption of the unique and chronological ordering of data and of their integrity, recorded so as to ensure unique sequential time-stamping, integrity and accuracy of the order, provided by a qualified trust service provider.

Artefacts an auditor will ask for
  • Qualified ledger evidence of sequential time-stamping and integrity
Where this commonly fails
  • Relying on a non-qualified ledger where the presumptions are needed

eIDAS - Electronic Attestation of Attributes

EIDAS-Art.45b
Legal effects of electronic attestation of attributes

Provides that an electronic attestation of attributes shall not be denied legal effect and admissibility solely for being electronic or non-qualified, and that qualified electronic attestations of attributes have the same legal effect as lawfully issued attestations in paper form.

Artefacts an auditor will ask for
  • Acceptance of electronic attestations without denying legal effect
Where this commonly fails
  • Rejecting an electronic attestation solely for being electronic
EIDAS-Art.45d
Requirements for qualified electronic attestation of attributes

Sets the Annex V requirements for qualified electronic attestations of attributes (incl. verification of the attributes' accuracy and binding to the subject), and provides for their use in public services (Art 45c).

Artefacts an auditor will ask for
  • Qualified EAA conforming to Annex V
  • Attribute-accuracy verification records
Where this commonly fails
  • Issuing qualified attestations without verifying attribute accuracy
EIDAS-Art.45e
Verification of attributes against authentic sources

Requires Member States to ensure that, where attributes are attested by or on behalf of public-sector bodies, there are means to verify those attributes against the relevant authentic source, at the user's request, for qualified electronic attestation of attributes.

Artefacts an auditor will ask for
  • Verification interface to authentic sources
  • Records of attribute verification at user request
Where this commonly fails
  • Issuing public-sector attestations without verification against the authentic source
EIDAS-Art.45f
Public-sector and additional rules for attestation of attributes

Sets requirements for electronic attestation of attributes issued by or on behalf of a public-sector body responsible for an authentic source (Art 45f), the issuing of attestations to wallets (Art 45g), and additional rules for the provision of attestation services incl. not combining personal data from attestation with other services without consent (Art 45h).

Artefacts an auditor will ask for
  • Public-sector attestation issuance records
  • Consent controls before combining attestation data with other services
Where this commonly fails
  • Combining attestation personal data with other data without consent

eIDAS - Electronic Documents

EIDAS-Art.46
Legal effects of electronic documents

Provides that an electronic document shall not be denied legal effect and admissibility as evidence in legal proceedings solely on the grounds that it is in electronic form.

Artefacts an auditor will ask for
  • Acceptance of electronic documents as evidence
Where this commonly fails
  • Rejecting an electronic document solely for being electronic

eIDAS - Electronic Identification Schemes

EIDAS-Art.11
Liability for electronic identification

Allocates liability among the notifying Member State, the party issuing the electronic identification means and the party operating the authentication procedure for failure to comply with their respective obligations in a cross-border transaction.

Artefacts an auditor will ask for
  • Liability allocation documentation for eID issuance and authentication
Where this commonly fails
  • No defined liability allocation among issuer/scheme/authentication operator
EIDAS-Art.11a
Cross-border identity matching

Requires Member States, where notified eID means or wallets are used, to provide for technical means enabling secure cross-border identity matching of a user to existing records, while ensuring a high level of confidence in the match and respecting data protection.

Artefacts an auditor will ask for
  • Identity-matching procedures and confidence controls
Where this commonly fails
  • Erroneous identity matching across borders without confidence safeguards
EIDAS-Art.12a
Certification of electronic identification schemes

Provides for the certification of the conformity of notified electronic identification schemes (and the eID means issued under them) with the assurance-level requirements, by accredited conformity assessment bodies.

Artefacts an auditor will ask for
  • Conformity-assessment certificates for the eID scheme
Where this commonly fails
  • No independent conformity assessment of the scheme's assurance level
EIDAS-Art.12b
Access to hardware and software features

Requires providers of hardware and software (e.g. device manufacturers and operating-system providers) to give wallet providers, where necessary, free-of-charge access to the hardware and software features needed for the wallet to function, on fair, reasonable and non-discriminatory terms, without prejudice to security.

Artefacts an auditor will ask for
  • Access arrangements between OS/hardware providers and wallet providers
Where this commonly fails
  • Denying wallet access to device security features (e.g. secure element)
EIDAS-Art.6
Mutual recognition of electronic identification

Requires that, where a notified electronic identification means is required under national law to access an online service provided by a public-sector body in one Member State, electronic identification means issued under a notified scheme in another Member State be recognised for cross-border authentication, provided they are at assurance level substantial or high (or low where the service requires low).

Artefacts an auditor will ask for
  • Records of accepting notified eID means from other Member States
  • Assurance-level matching for accepted means
Where this commonly fails
  • Refusing a notified eID means meeting the required assurance level
EIDAS-Art.7
Eligibility for notification of electronic identification schemes

Sets the conditions a Member State must satisfy to notify an electronic identification scheme, including that the eID means are issued under the scheme, are usable to access at least one public service requiring eID, that responsibilities for issuer, scheme and authentication are defined, and that the scheme meets the assurance-level requirements.

Artefacts an auditor will ask for
  • Scheme notification documentation
  • Defined responsibilities for issuer/scheme/authentication parties
Where this commonly fails
  • Notifying a scheme without clear responsibility allocation
EIDAS-Art.8
Assurance levels of electronic identification schemes

Specifies the assurance levels low, substantial and high for electronic identification means under notified schemes, characterised by the degree of confidence in the claimed identity, based on technical specifications, standards and procedures for identity proofing/verification, the means of authentication and management. Levels substantial and high build on the requirements of the level below.

Artefacts an auditor will ask for
  • Assurance-level determination per eID means
  • Identity-proofing and authentication evidence supporting the claimed level
Where this commonly fails
  • Claiming an assurance level not supported by the proofing/authentication controls
EIDAS-Art.9
Notification of electronic identification schemes

Requires Member States notifying an electronic identification scheme to provide the Commission with the scheme description, assurance levels, the issuing authority, the authentication interoperability arrangements and the liability regime, for publication in the Official Journal.

Artefacts an auditor will ask for
  • Scheme notification submission to the Commission
  • Published scheme details
Where this commonly fails
  • Operating a cross-border-recognised scheme not properly notified

eIDAS - Electronic Registered Delivery Services

EIDAS-Art.44
Legal effect and requirements for qualified electronic registered delivery services

Provides that data sent/received via an electronic registered delivery service shall not be denied legal effect solely for being electronic or non-qualified (Art 43), and that a qualified electronic registered delivery service (Art 44) enjoys a presumption of integrity, sending and receipt by identified parties and accuracy of date/time, provided by one or more qualified trust service providers with high-confidence identification of sender and addressee.

Artefacts an auditor will ask for
  • Qualified registered-delivery records of sending/receipt and time
  • Sender/addressee identification evidence
Where this commonly fails
  • Treating a non-qualified delivery as carrying the qualified presumptions

eIDAS - Electronic Seals

EIDAS-Art.35
Legal effects of electronic seals

Provides that an electronic seal shall not be denied legal effect and admissibility solely for being electronic or non-qualified; a qualified electronic seal enjoys a presumption of integrity and correctness of origin of the data it is linked to; and qualified seals based on certificates from one Member State are recognised in all others.

Artefacts an auditor will ask for
  • Acceptance of electronic seals without denying legal effect
Where this commonly fails
  • Rejecting an electronic seal solely for being electronic
EIDAS-Art.36
Requirements for advanced electronic seals

Requires an advanced electronic seal to be uniquely linked to and capable of identifying the creator (a legal person), created using seal creation data under the creator's control, and linked to the data so any change is detectable.

Artefacts an auditor will ask for
  • Technical evidence seals meet the advanced-seal criteria
Where this commonly fails
  • Seal creation data not under the legal person's control
EIDAS-Art.38
Qualified certificates for electronic seals

Requires qualified certificates for electronic seals to meet the Annex III requirements and be issued by qualified trust service providers, with status/revocation rules analogous to signature certificates.

Artefacts an auditor will ask for
  • Qualified seal certificate content conforming to Annex III
Where this commonly fails
  • Qualified seal certificates missing mandatory Annex III fields
EIDAS-Art.39
Qualified electronic seal creation devices

Applies the qualified-signature-creation-device requirements (Annex II), and the remote-management-service requirements (Art 39a), mutatis mutandis to qualified electronic seal creation devices.

Artefacts an auditor will ask for
  • Seal creation device certification
  • Evidence of a certified device/remote service for qualified seals
Where this commonly fails
  • Using an uncertified device for qualified seals
EIDAS-Art.40
Validation and preservation of qualified electronic seals

Applies the validation and preservation requirements for qualified electronic signatures (incl. validation of advanced seals based on qualified certificates, Art 40a) mutatis mutandis to qualified electronic seals.

Artefacts an auditor will ask for
  • Seal validation/preservation processes meeting the signature-equivalent criteria
Where this commonly fails
  • Validation not confirming seal certificate validity at sealing time

eIDAS - Electronic Signatures

EIDAS-Art.25
Legal effects of electronic signatures

Provides that an electronic signature shall not be denied legal effect and admissibility as evidence solely because it is electronic or does not meet qualified-signature requirements; a qualified electronic signature has the equivalent legal effect of a handwritten signature; and a qualified electronic signature based on a qualified certificate issued in one Member State is recognised in all others.

Artefacts an auditor will ask for
  • Acceptance of electronic signatures without denying legal effect
  • Recognition of qualified signatures cross-border
Where this commonly fails
  • Rejecting an electronic signature solely for being electronic
EIDAS-Art.26
Requirements for advanced electronic signatures

Requires an advanced electronic signature to be uniquely linked to and capable of identifying the signatory, created using electronic signature creation data the signatory can use under their sole control, and linked to the signed data so that any subsequent change is detectable.

Artefacts an auditor will ask for
  • Technical evidence that signatures meet the advanced-signature criteria
Where this commonly fails
  • Signature creation data not under the signatory's sole control
EIDAS-Art.28
Qualified certificates for electronic signatures

Requires qualified certificates for electronic signatures to meet the Annex I requirements, be issued by qualified trust service providers, and (with limited exceptions) not be subject to mandatory additional requirements; revocation takes effect on publication.

Artefacts an auditor will ask for
  • Qualified certificate content conforming to Annex I
  • Revocation/status publication evidence
Where this commonly fails
  • Qualified certificates missing mandatory Annex I fields
EIDAS-Art.29
Qualified electronic signature creation devices (QSCDs)

Requires that a qualified electronic signature be created by a qualified electronic signature creation device meeting the Annex II requirements (incl. for remote management services under Art 29a); QSCDs are certified by designated bodies (Art 30) and a list of certified devices is published (Art 31).

Artefacts an auditor will ask for
  • QSCD certification against Annex II
  • Evidence the signing device/remote service is a certified QSCD
Where this commonly fails
  • Using an uncertified device to create purportedly qualified signatures
EIDAS-Art.32
Validation of qualified electronic signatures

Sets the requirements for validating a qualified electronic signature (confirming the certificate validity, integrity of the signed data, and signatory identity at signing time), and provides for qualified validation services (Art 33).

Artefacts an auditor will ask for
  • Validation process meeting the Art 32 criteria
  • Qualified validation service evidence where used
Where this commonly fails
  • Validation that does not confirm certificate validity at signing time
EIDAS-Art.34
Qualified preservation service for qualified electronic signatures

Provides that a qualified preservation service for qualified electronic signatures may only be provided by a qualified trust service provider using procedures and technologies capable of extending the trustworthiness of the signature beyond the technological validity period.

Artefacts an auditor will ask for
  • Preservation procedures extending signature validity
  • Qualified status of the preservation provider
Where this commonly fails
  • Relying on signatures past their technological validity without preservation

eIDAS - Electronic Time Stamps

EIDAS-Art.41
Legal effect and requirements for qualified electronic time stamps

Provides that an electronic time stamp shall not be denied legal effect solely for being electronic or non-qualified (Art 41), and that a qualified electronic time stamp (Art 42) enjoys a presumption of accuracy of the date/time and integrity of the linked data, must bind date/time to data to preclude undetectable change, be based on an accurate time source and be signed/sealed by a qualified trust service provider.

Artefacts an auditor will ask for
  • Qualified time-stamp issuance bound to an accurate time source
  • Integrity binding of time to data
Where this commonly fails
  • Relying on a non-qualified time stamp where the presumption is needed

eIDAS - European Digital Identity Wallet

EIDAS-Art.5a
European Digital Identity Wallets

Requires each Member State to provide at least one European Digital Identity Wallet enabling users to securely request, store, select, combine and share person identification data and electronic attestations of attributes, to authenticate and to sign with qualified electronic signatures, under the user's sole control, with data minimisation and selective disclosure, free of charge to natural persons, and certified at assurance level high.

Artefacts an auditor will ask for
  • Wallet provision and onboarding records
  • Selective-disclosure and data-minimisation design evidence
  • User-control and consent logs for data sharing
  • Assurance-level high certification
Where this commonly fails
  • Sharing more attributes than the relying party requested
  • No selective disclosure / user-control mechanism
  • Charging natural persons for the wallet
EIDAS-Art.5b
Wallet-relying parties

Requires wallet-relying parties to register with the Member State where they are established, to declare the intended use and the data they intend to request, to identify themselves to the wallet, and not to request or retain data beyond what is necessary for the specific service. Relying parties are responsible for carrying out the procedure for authenticating person identification data.

Artefacts an auditor will ask for
  • Relying-party registration records
  • Declared-purpose and requested-data register
  • Evidence of relying-party self-identification to the wallet
Where this commonly fails
  • Requesting attributes beyond the declared purpose
  • Operating as a relying party without registration
EIDAS-Art.5c
Certification of wallets

Requires European Digital Identity Wallets to be certified against the security requirements by conformity assessment bodies designated by Member States, relying on cybersecurity certification schemes where available, with the certification covering the wallet solution and its components.

Artefacts an auditor will ask for
  • Wallet conformity-assessment certificates
  • Mapping of wallet components to certified scope
Where this commonly fails
  • Deploying a wallet without valid certification
  • Certifying only part of the wallet solution
EIDAS-Art.5d
Publication of certified wallets

Requires Member States to notify the Commission of certified European Digital Identity Wallets (and any subsequent withdrawal of certification) for publication, supporting transparency and cross-border reliance.

Artefacts an auditor will ask for
  • Notification records to the Commission of certified/withdrawn wallets
Where this commonly fails
  • Failing to notify withdrawal of a wallet certification
EIDAS-Art.5e
Security breach of wallets

Requires that, in the event of a security breach or compromise of a European Digital Identity Wallet, the provider suspend the provision and use of the wallet, remediate, inform affected users and the supervisory bodies, and where the breach is not remedied within a set period, withdraw the wallet and notify accordingly.

Artefacts an auditor will ask for
  • Wallet incident response and suspension procedures
  • Breach notification records to users and supervisory bodies
  • Remediation and withdrawal evidence
Where this commonly fails
  • No capability to suspend a compromised wallet
  • Failure to notify affected users of a wallet breach
EIDAS-Art.5f
Cross-border reliance on wallets

Requires that European Digital Identity Wallets be accepted, in particular by public-sector bodies and by private relying parties required to use strong user authentication for online services, for identification and authentication to access online services across borders, on a mutual-recognition basis.

Artefacts an auditor will ask for
  • Evidence of accepting wallets from other Member States
  • Integration records for cross-border wallet authentication
Where this commonly fails
  • Refusing a validly certified wallet from another Member State

eIDAS - General Provisions

EIDAS-Art.1
Subject matter

Establishes the conditions for the mutual recognition of electronic identification means, rules for trust services, and a legal framework for electronic signatures, seals, time stamps, electronic documents, registered delivery services, certificate services for website authentication, electronic attestation of attributes, electronic archiving and the European Digital Identity Wallet.

Artefacts an auditor will ask for
  • Mapping of in-scope eID/trust-service activities to the regulation
Where this commonly fails
  • Treating eIDAS as optional where a qualified trust service or wallet is offered in the EU
EIDAS-Art.2
Scope

Applies to electronic identification schemes notified by Member States, to providers of trust services established in the Union, and to providers of the European Digital Identity Wallet. It does not apply to closed systems resulting from private law used among a defined set of participants, and is without prejudice to national or Union law on contract conclusion and validity.

Artefacts an auditor will ask for
  • Determination of whether a service is in-scope (notified eID / Union-established TSP / wallet provider)
Where this commonly fails
  • Misclassifying a public-facing trust service as a closed private system
EIDAS-Art.3
Definitions

Defines the key terms, including electronic identification, electronic identification means, person identification data, electronic identification scheme, authentication, relying party, trust service, qualified trust service, trust service provider, electronic signature/seal/time stamp, certificate, qualified certificate, electronic registered delivery service, European Digital Identity Wallet, electronic attestation of attributes and the assurance levels low, substantial and high.

Artefacts an auditor will ask for
  • Consistent use of eIDAS-defined terms in policies and contracts
Where this commonly fails
  • Conflating non-qualified with qualified trust services
EIDAS-Art.4
Internal market principle

Prohibits restrictions on the provision of trust services originating in another Member State in the fields covered by the regulation, and requires that products and trust services complying with the regulation be permitted to circulate freely in the internal market.

Artefacts an auditor will ask for
  • Evidence that conforming trust services from other Member States are accepted without additional national barriers
Where this commonly fails
  • Imposing extra national requirements on conforming EU trust services
EIDAS-Art.5
Pseudonyms in electronic transactions

Without prejudice to the legal effect of pseudonyms under national law, the use of pseudonyms in electronic transactions shall not be prohibited.

Artefacts an auditor will ask for
  • Support for pseudonymous use where the law does not require identification
Where this commonly fails
  • Forcing identification where a pseudonym is permissible

eIDAS - Governance and Supervision

EIDAS-Art.46a
Supervision of the European Digital Identity Wallet framework

Requires Member States to designate supervisory bodies to supervise European Digital Identity Wallet providers, with powers to monitor compliance, require information and order corrective action, and to report to the Commission and the Cooperation Group.

Artefacts an auditor will ask for
  • Cooperation records with the designated wallet supervisory body
Where this commonly fails
  • Failing to respond to supervisory information requests
EIDAS-Art.46b
Supervision of trust services

Requires Member States to designate supervisory bodies for trust service providers, with powers to supervise qualified providers (ex ante and ongoing) and to act ex post on non-qualified providers when made aware of non-compliance or breaches.

Artefacts an auditor will ask for
  • Interaction records with the trust-service supervisory body
  • Evidence of acting on supervisory findings
Where this commonly fails
  • Not cooperating with the supervisory body
EIDAS-Art.46e
European Digital Identity Cooperation Group

Establishes single points of contact (Art 46c), mutual assistance between supervisory bodies (Art 46d) and the European Digital Identity Cooperation Group (Art 46e) to facilitate cooperation, exchange of best practice and consistent application of the framework across Member States.

Artefacts an auditor will ask for
  • Awareness of the Cooperation Group guidance applicable to the activity
Where this commonly fails
  • Ignoring cross-border cooperation guidance

eIDAS - Non-Qualified Trust Services

EIDAS-Art.19a
Requirements for non-qualified trust service providers

Requires non-qualified trust service providers to implement appropriate technical and organisational measures to manage the risks to the security of their services, to notify the supervisory body and affected parties of security breaches with significant impact, and to take all appropriate measures in the event of such breaches.

Artefacts an auditor will ask for
  • Risk-based security measures for the trust service
  • Breach notification procedures to the supervisory body
Where this commonly fails
  • No security risk management for a non-qualified trust service
  • No breach notification path

eIDAS - Qualified Trust Services

EIDAS-Art.20
Supervision of qualified trust service providers

Requires qualified trust service providers to be audited at their own expense at least every 24 months by a conformity assessment body to confirm continued compliance, and to submit the resulting conformity assessment report to the supervisory body. The supervisory body may also require ad hoc audits.

Artefacts an auditor will ask for
  • Conformity assessment reports at least every 24 months
  • Evidence of submission to the supervisory body
  • Remediation of audit findings
Where this commonly fails
  • Audit interval exceeding 24 months
  • Not submitting the conformity assessment report
EIDAS-Art.21
Initiation of a qualified trust service

Requires a trust service provider intending to start providing qualified trust services to submit to the supervisory body a notification with a conformity assessment report; the provider may begin only after the qualified status is granted and indicated in the trusted lists.

Artefacts an auditor will ask for
  • Notification + conformity assessment report to the supervisory body
  • Confirmation of trusted-list inclusion before operating as qualified
Where this commonly fails
  • Marketing a service as qualified before grant of status
EIDAS-Art.22
Trusted lists

Requires Member States to establish, maintain and publish trusted lists with information on the qualified trust service providers and the qualified trust services they provide, in a secure, signed or sealed form suitable for automated processing.

Artefacts an auditor will ask for
  • Presence and accuracy of the provider's entries in the national trusted list
Where this commonly fails
  • Discrepancies between actual qualified services and the trusted list
EIDAS-Art.23
EU trust mark for qualified trust services

Allows qualified trust service providers to use the EU trust mark to indicate the qualified trust services they provide, with a link to the relevant trusted list, only after the qualified status is indicated in the trusted list.

Artefacts an auditor will ask for
  • Correct use of the EU trust mark with a trusted-list link
Where this commonly fails
  • Displaying the EU trust mark for non-qualified or not-yet-listed services
EIDAS-Art.24
Requirements for qualified trust service providers

Sets the core obligations of qualified trust service providers: verify the identity of the person to whom a qualified certificate is issued; employ competent staff and appropriate procedures; use trustworthy systems and products protected against modification; maintain sufficient financial resources/liability insurance; record and keep accessible relevant information; have an up-to-date termination plan; ensure lawful processing of personal data; and report security breaches.

Artefacts an auditor will ask for
  • Identity-verification records for certificate subjects
  • Personnel competence and trustworthy-system evidence
  • Liability insurance / financial resources
  • Termination plan and records retention
Where this commonly fails
  • Issuing qualified certificates without verifying subject identity
  • No termination plan
  • Untrustworthy or unprotected issuance systems
EIDAS-Art.24a
Recognition of qualified trust services

Provides that a qualified trust service, and the qualified status of its provider, granted in one Member State are recognised across all Member States, supporting cross-border use of qualified signatures, seals, time stamps, delivery, certificates and attestations.

Artefacts an auditor will ask for
  • Evidence of accepting qualified trust services from other Member States
Where this commonly fails
  • Refusing a qualified trust service recognised in another Member State

eIDAS - Trust Services General Provisions

EIDAS-Art.13
Liability and burden of proof of trust service providers

Makes trust service providers liable for damage caused intentionally or negligently to any natural or legal person due to failure to comply with the regulation. The burden of proving intention or negligence of a qualified trust service provider lies with the person claiming the damage, but is presumed for qualified providers unless they prove the damage occurred without intention or negligence.

Artefacts an auditor will ask for
  • Liability and insurance arrangements
  • Records demonstrating due care to rebut the presumption
Where this commonly fails
  • No documentation to demonstrate absence of negligence
EIDAS-Art.14
International aspects

Provides that trust services provided by trust service providers established in a third country are recognised as legally equivalent to qualified trust services provided by EU providers where the third country's services are recognised under an agreement between the Union and that third country or international organisation.

Artefacts an auditor will ask for
  • Evidence of any applicable Union recognition agreement relied upon
Where this commonly fails
  • Treating non-recognised third-country services as qualified
EIDAS-Art.15
Accessibility for persons with disabilities

Requires that, where feasible, trust services and the end-user products used in their provision be made accessible to persons with disabilities, in accordance with applicable Union accessibility requirements.

Artefacts an auditor will ask for
  • Accessibility conformance evidence for trust-service products
Where this commonly fails
  • No accessibility consideration for end-user products
EIDAS-Art.16
Penalties

Requires Member States to lay down rules on penalties for infringements of the regulation that are effective, proportionate and dissuasive.

Artefacts an auditor will ask for
  • Awareness of applicable national penalty regime
Where this commonly fails
  • Underestimating exposure to national penalties for non-compliance

eIDAS - Website Authentication

EIDAS-Art.45
Requirements for qualified certificates for website authentication

Requires qualified certificates for website authentication to meet the Annex IV requirements and that browsers recognise and display them; web-browser providers must ensure support for and interoperability with qualified website authentication certificates.

Artefacts an auditor will ask for
  • Qualified website-authentication certificate conforming to Annex IV
  • Browser recognition/interoperability evidence
Where this commonly fails
  • Browsers not recognising qualified website authentication certificates
EIDAS-Art.45a
Cybersecurity precautionary measures

Provides for cybersecurity precautionary measures, ensuring that any security concerns in relation to qualified certificates for website authentication are addressed without prejudice to the recognition obligations.

Artefacts an auditor will ask for
  • Handling of cybersecurity concerns for website authentication certificates
Where this commonly fails
  • No process to address security concerns about issued certificates
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.