eIDAS 2.0 - EU Digital Identity Regulation
Evidence request list. 55 controls, 55 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
eIDAS - Electronic Archiving and Ledgers
Provides that electronic archiving data shall not be denied legal effect solely for being electronic (Art 45i), and that a qualified electronic archiving service (Art 45j) must use procedures and technologies capable of ensuring the durability, integrity and legibility of the archived electronic documents/data beyond the technological validity period, provided by a qualified trust service provider.
- Qualified archiving procedures ensuring durability/integrity/legibility
- Archiving without measures to preserve integrity over time
Provides that an electronic ledger shall not be denied legal effect solely for being electronic or non-qualified (Art 45k), and that a qualified electronic ledger (Art 45l) enjoys a presumption of the unique and chronological ordering of data and of their integrity, recorded so as to ensure unique sequential time-stamping, integrity and accuracy of the order, provided by a qualified trust service provider.
- Qualified ledger evidence of sequential time-stamping and integrity
- Relying on a non-qualified ledger where the presumptions are needed
eIDAS - Electronic Attestation of Attributes
Provides that an electronic attestation of attributes shall not be denied legal effect and admissibility solely for being electronic or non-qualified, and that qualified electronic attestations of attributes have the same legal effect as lawfully issued attestations in paper form.
- Acceptance of electronic attestations without denying legal effect
- Rejecting an electronic attestation solely for being electronic
Sets the Annex V requirements for qualified electronic attestations of attributes (incl. verification of the attributes' accuracy and binding to the subject), and provides for their use in public services (Art 45c).
- Qualified EAA conforming to Annex V
- Attribute-accuracy verification records
- Issuing qualified attestations without verifying attribute accuracy
Requires Member States to ensure that, where attributes are attested by or on behalf of public-sector bodies, there are means to verify those attributes against the relevant authentic source, at the user's request, for qualified electronic attestation of attributes.
- Verification interface to authentic sources
- Records of attribute verification at user request
- Issuing public-sector attestations without verification against the authentic source
Sets requirements for electronic attestation of attributes issued by or on behalf of a public-sector body responsible for an authentic source (Art 45f), the issuing of attestations to wallets (Art 45g), and additional rules for the provision of attestation services incl. not combining personal data from attestation with other services without consent (Art 45h).
- Public-sector attestation issuance records
- Consent controls before combining attestation data with other services
- Combining attestation personal data with other data without consent
eIDAS - Electronic Documents
Provides that an electronic document shall not be denied legal effect and admissibility as evidence in legal proceedings solely on the grounds that it is in electronic form.
- Acceptance of electronic documents as evidence
- Rejecting an electronic document solely for being electronic
eIDAS - Electronic Identification Schemes
Allocates liability among the notifying Member State, the party issuing the electronic identification means and the party operating the authentication procedure for failure to comply with their respective obligations in a cross-border transaction.
- Liability allocation documentation for eID issuance and authentication
- No defined liability allocation among issuer/scheme/authentication operator
Requires Member States, where notified eID means or wallets are used, to provide for technical means enabling secure cross-border identity matching of a user to existing records, while ensuring a high level of confidence in the match and respecting data protection.
- Identity-matching procedures and confidence controls
- Erroneous identity matching across borders without confidence safeguards
Provides for the certification of the conformity of notified electronic identification schemes (and the eID means issued under them) with the assurance-level requirements, by accredited conformity assessment bodies.
- Conformity-assessment certificates for the eID scheme
- No independent conformity assessment of the scheme's assurance level
Requires providers of hardware and software (e.g. device manufacturers and operating-system providers) to give wallet providers, where necessary, free-of-charge access to the hardware and software features needed for the wallet to function, on fair, reasonable and non-discriminatory terms, without prejudice to security.
- Access arrangements between OS/hardware providers and wallet providers
- Denying wallet access to device security features (e.g. secure element)
Requires that, where a notified electronic identification means is required under national law to access an online service provided by a public-sector body in one Member State, electronic identification means issued under a notified scheme in another Member State be recognised for cross-border authentication, provided they are at assurance level substantial or high (or low where the service requires low).
- Records of accepting notified eID means from other Member States
- Assurance-level matching for accepted means
- Refusing a notified eID means meeting the required assurance level
Sets the conditions a Member State must satisfy to notify an electronic identification scheme, including that the eID means are issued under the scheme, are usable to access at least one public service requiring eID, that responsibilities for issuer, scheme and authentication are defined, and that the scheme meets the assurance-level requirements.
- Scheme notification documentation
- Defined responsibilities for issuer/scheme/authentication parties
- Notifying a scheme without clear responsibility allocation
Specifies the assurance levels low, substantial and high for electronic identification means under notified schemes, characterised by the degree of confidence in the claimed identity, based on technical specifications, standards and procedures for identity proofing/verification, the means of authentication and management. Levels substantial and high build on the requirements of the level below.
- Assurance-level determination per eID means
- Identity-proofing and authentication evidence supporting the claimed level
- Claiming an assurance level not supported by the proofing/authentication controls
Requires Member States notifying an electronic identification scheme to provide the Commission with the scheme description, assurance levels, the issuing authority, the authentication interoperability arrangements and the liability regime, for publication in the Official Journal.
- Scheme notification submission to the Commission
- Published scheme details
- Operating a cross-border-recognised scheme not properly notified
eIDAS - Electronic Registered Delivery Services
Provides that data sent/received via an electronic registered delivery service shall not be denied legal effect solely for being electronic or non-qualified (Art 43), and that a qualified electronic registered delivery service (Art 44) enjoys a presumption of integrity, sending and receipt by identified parties and accuracy of date/time, provided by one or more qualified trust service providers with high-confidence identification of sender and addressee.
- Qualified registered-delivery records of sending/receipt and time
- Sender/addressee identification evidence
- Treating a non-qualified delivery as carrying the qualified presumptions
eIDAS - Electronic Seals
Provides that an electronic seal shall not be denied legal effect and admissibility solely for being electronic or non-qualified; a qualified electronic seal enjoys a presumption of integrity and correctness of origin of the data it is linked to; and qualified seals based on certificates from one Member State are recognised in all others.
- Acceptance of electronic seals without denying legal effect
- Rejecting an electronic seal solely for being electronic
Requires an advanced electronic seal to be uniquely linked to and capable of identifying the creator (a legal person), created using seal creation data under the creator's control, and linked to the data so any change is detectable.
- Technical evidence seals meet the advanced-seal criteria
- Seal creation data not under the legal person's control
Requires qualified certificates for electronic seals to meet the Annex III requirements and be issued by qualified trust service providers, with status/revocation rules analogous to signature certificates.
- Qualified seal certificate content conforming to Annex III
- Qualified seal certificates missing mandatory Annex III fields
Applies the qualified-signature-creation-device requirements (Annex II), and the remote-management-service requirements (Art 39a), mutatis mutandis to qualified electronic seal creation devices.
- Seal creation device certification
- Evidence of a certified device/remote service for qualified seals
- Using an uncertified device for qualified seals
Applies the validation and preservation requirements for qualified electronic signatures (incl. validation of advanced seals based on qualified certificates, Art 40a) mutatis mutandis to qualified electronic seals.
- Seal validation/preservation processes meeting the signature-equivalent criteria
- Validation not confirming seal certificate validity at sealing time
eIDAS - Electronic Signatures
Provides that an electronic signature shall not be denied legal effect and admissibility as evidence solely because it is electronic or does not meet qualified-signature requirements; a qualified electronic signature has the equivalent legal effect of a handwritten signature; and a qualified electronic signature based on a qualified certificate issued in one Member State is recognised in all others.
- Acceptance of electronic signatures without denying legal effect
- Recognition of qualified signatures cross-border
- Rejecting an electronic signature solely for being electronic
Requires an advanced electronic signature to be uniquely linked to and capable of identifying the signatory, created using electronic signature creation data the signatory can use under their sole control, and linked to the signed data so that any subsequent change is detectable.
- Technical evidence that signatures meet the advanced-signature criteria
- Signature creation data not under the signatory's sole control
Requires qualified certificates for electronic signatures to meet the Annex I requirements, be issued by qualified trust service providers, and (with limited exceptions) not be subject to mandatory additional requirements; revocation takes effect on publication.
- Qualified certificate content conforming to Annex I
- Revocation/status publication evidence
- Qualified certificates missing mandatory Annex I fields
Requires that a qualified electronic signature be created by a qualified electronic signature creation device meeting the Annex II requirements (incl. for remote management services under Art 29a); QSCDs are certified by designated bodies (Art 30) and a list of certified devices is published (Art 31).
- QSCD certification against Annex II
- Evidence the signing device/remote service is a certified QSCD
- Using an uncertified device to create purportedly qualified signatures
Sets the requirements for validating a qualified electronic signature (confirming the certificate validity, integrity of the signed data, and signatory identity at signing time), and provides for qualified validation services (Art 33).
- Validation process meeting the Art 32 criteria
- Qualified validation service evidence where used
- Validation that does not confirm certificate validity at signing time
Provides that a qualified preservation service for qualified electronic signatures may only be provided by a qualified trust service provider using procedures and technologies capable of extending the trustworthiness of the signature beyond the technological validity period.
- Preservation procedures extending signature validity
- Qualified status of the preservation provider
- Relying on signatures past their technological validity without preservation
eIDAS - Electronic Time Stamps
Provides that an electronic time stamp shall not be denied legal effect solely for being electronic or non-qualified (Art 41), and that a qualified electronic time stamp (Art 42) enjoys a presumption of accuracy of the date/time and integrity of the linked data, must bind date/time to data to preclude undetectable change, be based on an accurate time source and be signed/sealed by a qualified trust service provider.
- Qualified time-stamp issuance bound to an accurate time source
- Integrity binding of time to data
- Relying on a non-qualified time stamp where the presumption is needed
eIDAS - European Digital Identity Wallet
Requires each Member State to provide at least one European Digital Identity Wallet enabling users to securely request, store, select, combine and share person identification data and electronic attestations of attributes, to authenticate and to sign with qualified electronic signatures, under the user's sole control, with data minimisation and selective disclosure, free of charge to natural persons, and certified at assurance level high.
- Wallet provision and onboarding records
- Selective-disclosure and data-minimisation design evidence
- User-control and consent logs for data sharing
- Assurance-level high certification
- Sharing more attributes than the relying party requested
- No selective disclosure / user-control mechanism
- Charging natural persons for the wallet
Requires wallet-relying parties to register with the Member State where they are established, to declare the intended use and the data they intend to request, to identify themselves to the wallet, and not to request or retain data beyond what is necessary for the specific service. Relying parties are responsible for carrying out the procedure for authenticating person identification data.
- Relying-party registration records
- Declared-purpose and requested-data register
- Evidence of relying-party self-identification to the wallet
- Requesting attributes beyond the declared purpose
- Operating as a relying party without registration
Requires European Digital Identity Wallets to be certified against the security requirements by conformity assessment bodies designated by Member States, relying on cybersecurity certification schemes where available, with the certification covering the wallet solution and its components.
- Wallet conformity-assessment certificates
- Mapping of wallet components to certified scope
- Deploying a wallet without valid certification
- Certifying only part of the wallet solution
Requires Member States to notify the Commission of certified European Digital Identity Wallets (and any subsequent withdrawal of certification) for publication, supporting transparency and cross-border reliance.
- Notification records to the Commission of certified/withdrawn wallets
- Failing to notify withdrawal of a wallet certification
Requires that, in the event of a security breach or compromise of a European Digital Identity Wallet, the provider suspend the provision and use of the wallet, remediate, inform affected users and the supervisory bodies, and where the breach is not remedied within a set period, withdraw the wallet and notify accordingly.
- Wallet incident response and suspension procedures
- Breach notification records to users and supervisory bodies
- Remediation and withdrawal evidence
- No capability to suspend a compromised wallet
- Failure to notify affected users of a wallet breach
Requires that European Digital Identity Wallets be accepted, in particular by public-sector bodies and by private relying parties required to use strong user authentication for online services, for identification and authentication to access online services across borders, on a mutual-recognition basis.
- Evidence of accepting wallets from other Member States
- Integration records for cross-border wallet authentication
- Refusing a validly certified wallet from another Member State
eIDAS - General Provisions
Establishes the conditions for the mutual recognition of electronic identification means, rules for trust services, and a legal framework for electronic signatures, seals, time stamps, electronic documents, registered delivery services, certificate services for website authentication, electronic attestation of attributes, electronic archiving and the European Digital Identity Wallet.
- Mapping of in-scope eID/trust-service activities to the regulation
- Treating eIDAS as optional where a qualified trust service or wallet is offered in the EU
Applies to electronic identification schemes notified by Member States, to providers of trust services established in the Union, and to providers of the European Digital Identity Wallet. It does not apply to closed systems resulting from private law used among a defined set of participants, and is without prejudice to national or Union law on contract conclusion and validity.
- Determination of whether a service is in-scope (notified eID / Union-established TSP / wallet provider)
- Misclassifying a public-facing trust service as a closed private system
Defines the key terms, including electronic identification, electronic identification means, person identification data, electronic identification scheme, authentication, relying party, trust service, qualified trust service, trust service provider, electronic signature/seal/time stamp, certificate, qualified certificate, electronic registered delivery service, European Digital Identity Wallet, electronic attestation of attributes and the assurance levels low, substantial and high.
- Consistent use of eIDAS-defined terms in policies and contracts
- Conflating non-qualified with qualified trust services
Prohibits restrictions on the provision of trust services originating in another Member State in the fields covered by the regulation, and requires that products and trust services complying with the regulation be permitted to circulate freely in the internal market.
- Evidence that conforming trust services from other Member States are accepted without additional national barriers
- Imposing extra national requirements on conforming EU trust services
Without prejudice to the legal effect of pseudonyms under national law, the use of pseudonyms in electronic transactions shall not be prohibited.
- Support for pseudonymous use where the law does not require identification
- Forcing identification where a pseudonym is permissible
eIDAS - Governance and Supervision
Requires Member States to designate supervisory bodies to supervise European Digital Identity Wallet providers, with powers to monitor compliance, require information and order corrective action, and to report to the Commission and the Cooperation Group.
- Cooperation records with the designated wallet supervisory body
- Failing to respond to supervisory information requests
Requires Member States to designate supervisory bodies for trust service providers, with powers to supervise qualified providers (ex ante and ongoing) and to act ex post on non-qualified providers when made aware of non-compliance or breaches.
- Interaction records with the trust-service supervisory body
- Evidence of acting on supervisory findings
- Not cooperating with the supervisory body
Establishes single points of contact (Art 46c), mutual assistance between supervisory bodies (Art 46d) and the European Digital Identity Cooperation Group (Art 46e) to facilitate cooperation, exchange of best practice and consistent application of the framework across Member States.
- Awareness of the Cooperation Group guidance applicable to the activity
- Ignoring cross-border cooperation guidance
eIDAS - Non-Qualified Trust Services
Requires non-qualified trust service providers to implement appropriate technical and organisational measures to manage the risks to the security of their services, to notify the supervisory body and affected parties of security breaches with significant impact, and to take all appropriate measures in the event of such breaches.
- Risk-based security measures for the trust service
- Breach notification procedures to the supervisory body
- No security risk management for a non-qualified trust service
- No breach notification path
eIDAS - Qualified Trust Services
Requires qualified trust service providers to be audited at their own expense at least every 24 months by a conformity assessment body to confirm continued compliance, and to submit the resulting conformity assessment report to the supervisory body. The supervisory body may also require ad hoc audits.
- Conformity assessment reports at least every 24 months
- Evidence of submission to the supervisory body
- Remediation of audit findings
- Audit interval exceeding 24 months
- Not submitting the conformity assessment report
Requires a trust service provider intending to start providing qualified trust services to submit to the supervisory body a notification with a conformity assessment report; the provider may begin only after the qualified status is granted and indicated in the trusted lists.
- Notification + conformity assessment report to the supervisory body
- Confirmation of trusted-list inclusion before operating as qualified
- Marketing a service as qualified before grant of status
Requires Member States to establish, maintain and publish trusted lists with information on the qualified trust service providers and the qualified trust services they provide, in a secure, signed or sealed form suitable for automated processing.
- Presence and accuracy of the provider's entries in the national trusted list
- Discrepancies between actual qualified services and the trusted list
Allows qualified trust service providers to use the EU trust mark to indicate the qualified trust services they provide, with a link to the relevant trusted list, only after the qualified status is indicated in the trusted list.
- Correct use of the EU trust mark with a trusted-list link
- Displaying the EU trust mark for non-qualified or not-yet-listed services
Sets the core obligations of qualified trust service providers: verify the identity of the person to whom a qualified certificate is issued; employ competent staff and appropriate procedures; use trustworthy systems and products protected against modification; maintain sufficient financial resources/liability insurance; record and keep accessible relevant information; have an up-to-date termination plan; ensure lawful processing of personal data; and report security breaches.
- Identity-verification records for certificate subjects
- Personnel competence and trustworthy-system evidence
- Liability insurance / financial resources
- Termination plan and records retention
- Issuing qualified certificates without verifying subject identity
- No termination plan
- Untrustworthy or unprotected issuance systems
Provides that a qualified trust service, and the qualified status of its provider, granted in one Member State are recognised across all Member States, supporting cross-border use of qualified signatures, seals, time stamps, delivery, certificates and attestations.
- Evidence of accepting qualified trust services from other Member States
- Refusing a qualified trust service recognised in another Member State
eIDAS - Trust Services General Provisions
Makes trust service providers liable for damage caused intentionally or negligently to any natural or legal person due to failure to comply with the regulation. The burden of proving intention or negligence of a qualified trust service provider lies with the person claiming the damage, but is presumed for qualified providers unless they prove the damage occurred without intention or negligence.
- Liability and insurance arrangements
- Records demonstrating due care to rebut the presumption
- No documentation to demonstrate absence of negligence
Provides that trust services provided by trust service providers established in a third country are recognised as legally equivalent to qualified trust services provided by EU providers where the third country's services are recognised under an agreement between the Union and that third country or international organisation.
- Evidence of any applicable Union recognition agreement relied upon
- Treating non-recognised third-country services as qualified
Requires that, where feasible, trust services and the end-user products used in their provision be made accessible to persons with disabilities, in accordance with applicable Union accessibility requirements.
- Accessibility conformance evidence for trust-service products
- No accessibility consideration for end-user products
Requires Member States to lay down rules on penalties for infringements of the regulation that are effective, proportionate and dissuasive.
- Awareness of applicable national penalty regime
- Underestimating exposure to national penalties for non-compliance
eIDAS - Website Authentication
Requires qualified certificates for website authentication to meet the Annex IV requirements and that browsers recognise and display them; web-browser providers must ensure support for and interoperability with qualified website authentication certificates.
- Qualified website-authentication certificate conforming to Annex IV
- Browser recognition/interoperability evidence
- Browsers not recognising qualified website authentication certificates
Provides for cybersecurity precautionary measures, ensuring that any security concerns in relation to qualified certificates for website authentication are addressed without prejudice to the recognition obligations.
- Handling of cybersecurity concerns for website authentication certificates
- No process to address security concerns about issued certificates
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.