eIDAS 2

What characterises Trust Services

Trust Services under eIDAS 2 are digital services that must meet particularly high requirements for security, integrity and legal validity. They may only be provided by Qualified Trust Service Providers (QTSP) who have successfully undergone an assessment by an accredited Conformity Assessment Body.

Our assessment services

We support qualified and non-qualified TSP throughout the entire lifecycle from the initial assessment to surveillance and re‑assessments, and throughout your setup and introduction of new eIDAS 2 services. This ensures that your services remain compliant, secure and reliable at all times.

  • Signatures and seals with EU‑wide legal effect
  • Timestamps as tamper‑proof evidence of the time and existence of digital data
  • Preservation services to ensure the long‑term legal validity of signatures and seals
  • Archiving services for audit‑proof long‑term storage of digital content
  • Registered delivery services (ERDS) providing proof of dispatch, receipt and data integrity
  • Ledgers for trustworthy, audit‑secure records
  • Attestations of attributes (EAA) as a foundation of the European Digital Identity Wallet
  • Website Authentication Certificates (QWACs) for verified identity and maximum trustworthiness online – here we also provide Audit Attestations following CA/Browser-Forum Requirements, ETSI or WebTrust based.

 

We also offer eIDAS Module- or Component-Certifications for service provider in all areas, as for eIDAS compliant user identification from LoA low to high.

Certifications are carried out by us at TÜV AUSTRIA GmbH, Vienna as an EU wide accredited eIDAS Conformity Assessment Body.

Your benefits

  • Legal certainty across the entire EU through eIDAS-certification for Qualified Trust Services
  • Fast and secure market access thanks to clear, auditable processes
  • Future‑proof compliance with all relevant standards, including legals – eIDAS, EU Implementing Regulations, NIS2 obligations and national legal requirements as well as norms, like ETSI/CEN or CA/B-Forum-Requirements.

Contact us today to have your trust services assessed, certified, and future‑proofed in full compliance with eIDAS 2.

eID Schemes under eIDAS 2 are notified on national level and enable European Member States to provide electronic identification for their citizens across public and private services. eIDAS 2 defines how identities are issued and managed, forming the basis for the EU‑wide recognition of electronic identities on Level of Assurance (LoA) – low, substantial, or high.

Core elements of the eID Scheme include:

  • identity proofing and registration process,
  • authentication mechanisms for any use-cases,
  • identity lifecycle management.

 

Of further importance are governance, liability, and supervision arrangements.

Our assessment services

We support Identification Service Providers (IDP) for eID Schemes and eID Scheme operators throughout the entire service lifecycle – from the initial idea via possible assessments as well as further into the introduction of new eID related services. This allows your service to demonstrate the required level of eIDAS 2 compliance at all times.

We work on all three Levels of Assurance (LoA) — low, substantial, or high:

  • assessment of identity proofing- and registration processes,
  • validation of authentication mechanisms and cryptographic procedures,
  • review of lifecycle management,
  • risk‑based security assessment aligned with the assurance level,
  • ongoing monitoring and reassessment following changes or security incidents.
 

We also offer eIDAS Module- or Component-Certifications for service provider in all areas, as for eIDAS compliant user identification from LoA low to high.

Certifications are carried out by us at TÜV AUSTRIA GmbH, Vienna as an EU wide accredited eIDAS Conformity Assessment Body.

Your benefits

  • Legal certainty across the entire EU by evidencing eIDAS compliance
  • Fast and secure market access thanks to clear, auditable processes
  • Future proof compliance with relevant standards, including eIDAS 2, EU-Implementing Regulations, NIS2 obligations and national legal requirements as well as technical norms, like ETSI/CEN-Requirements.

Get in touch with us to ensure your eID services are fully eIDAS 2‑compliant, secure, and successfully positioned in the market.

The European Digital Identity Wallet (EUDIW) is the secure digital solution that allows natural and legal persons to store, manage, and present identity data and electronic attestations in electronic form. The Wallet is a core building block of the EU’s digital identity framework and enables cross-border, privacy-preserving identification and authentication across public and private services.

The EUDIW allows users to:

  • identify and authenticate themselves online and offline,
  • receive and present electronic attestations of attributes (e.g. age, qualifications, mandates, licenses and certificates),
  • create qualified electronic signatures and seals,
  • share data under full user control with selective disclosure.

 

A Wallet must be provided free of charge by each Member State and must support a high level of security and user autonomy. It is not itself a trust service but acts as a secure interface to eID schemes and Qualified Trust Services.

Conformity-Assessment Requirements

Under eIDAS 2, a conformity assessment is mandatory before a Wallet solution may be issued or recognised by a Member State.

Key requirements include:

  • Independent conformity assessment by an accredited body designated by Member States
  • High Level of Assurance (LoA high)
  • Cybersecurity and data protection compliance
  • Interoperability and standard compliance

Legal Effect

Once conformant, the EUDIW must be accepted across the EU for services requiring electronic identification at the same or lower assurance level.

Please don’t hesitate to ask us at TÜV AUSTRIA / TÜV TRUST IT in case you need any support or conformity assessment service in this area!

The strategy for a digital EU internal market has long been at the top of the European Commission’s priority list. As a result, regulations such as the eIDAS 2 Regulation (EU Regulations 910/2014 and 2024/1183) have emerged, covering electronic identities (eID), the wallet (EUDIW), and trust services such as the Qualified Electronic Signature (QES). These regulations establish a common foundation to ensure secure electronic interactions between private individuals, businesses, and public entities. They define the legally binding framework across the EU for digital financial transactions and trade relations, as well as for secure data exchange in other areas of the economy and public administration.

Both service providers and users are confronted with a series of binding laws: eIDAS 2, NIS 2, and national requirements in the EU member states.

Contact us: We are accredited across Europe for eIDAS 2 conformity assessments of eID, wallets, and trust services. We are happy to support your projects with tailored, needs-based guidance, and we also offer topic-specific workshops and training sessions.

Contact

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Name*
Data privacy*