eIDAS 2.0 & Digital Identity Glossary
Every key term you need to understand, from the eIDAS 2.0 compliance framework to trust services, wallet architecture, and technical standards.
Core Regulation
- eIDAS 2.0The revised EU regulation on electronic identification and trust services, updating the original 2014 eIDAS framework to mandate a European Digital Identity Wallet for all EU citizens.
- Relying PartyAn entity, public or private, that relies on the EUDIW or electronic identification means to verify the identity or attributes of a user for the purpose of providing a service.
- Level of Assurance (LoA)A measure of confidence in the identity verification process, classified as low, substantial, or high under eIDAS, determining the trust level of an electronic identification means.
- PSD2 (Payment Services Directive 2)The EU directive governing payment services and open banking, which intersects with eIDAS 2.0 through strong customer authentication requirements and the potential use of the EUDIW for payment initiation.
- Anti-Money Laundering Authority (AMLA)The new EU authority responsible for overseeing anti-money laundering compliance, whose requirements for customer identity verification intersect directly with eIDAS 2.0 wallet acceptance obligations.
- eID SchemeA national electronic identification system established by a Member State, defining how electronic identities are issued, managed, and used for authentication.
Digital Identity
- European Digital Identity Wallet (EUDIW)A mobile application that every EU Member State must provide to citizens and residents, enabling them to store and present digital identity credentials and attestations across borders.
- Electronic Identification (eID)The process of using electronic means to verify a person's identity, forming the foundation of the eIDAS regulation and the basis for cross-border digital identity in the EU.
- Person Identification Data (PID)The core set of identity attributes, such as name, date of birth, and a unique identifier, issued by a Member State and stored in the EUDIW, forming the foundation of the wallet holder's digital identity.
- Electronic Attestation of Attributes (EAA)A digitally signed attestation that confirms specific attributes of a person, such as age, qualifications, or address, issued by an attribute provider and stored in the EUDIW.
- Self-Sovereign Identity (SSI)A model for digital identity in which individuals fully control their own identity data without depending on a central authority, often leveraging decentralised technologies.
- Selective DisclosureA privacy-enhancing capability that allows a credential holder to present only specific attributes from a credential rather than the entire dataset.
- Mobile Driving Licence (mDL)A digital version of a physical driving licence stored on a mobile device, standardised under ISO 18013-5, and one of the flagship use cases for the European Digital Identity Wallet.
- Attribute ProviderAn entity that is an authentic source of identity attributes and issues Electronic Attestations of Attributes to wallet holders, such as a university issuing a diploma credential.
Trust Services
- Qualified Trust Service Provider (QTSP)An entity granted qualified status by a national supervisory body, authorised to issue qualified certificates, signatures, seals, timestamps, and electronic attestations of attributes under eIDAS.
- Qualified Electronic Signature (QES)The highest form of electronic signature under EU law, created using a qualified certificate and a qualified signature creation device, carrying the legal equivalent of a handwritten signature.
- Qualified Electronic Attestation of Attributes (QEAA)An electronic attestation of attributes issued by a QTSP, carrying a legal presumption of accuracy and cross-border validity equivalent to a legally issued attestation in paper form.
- Electronic Seal (eSeal)An electronic equivalent of a business stamp, used by legal persons to guarantee the origin and integrity of documents and data, with qualified eSeals carrying full cross-border legal effect.
- Electronic TimestampAn electronic attestation that binds data to a particular point in time, providing evidence that the data existed in a certain form at that moment.
- Electronic Delivery (eDelivery)A qualified trust service for transmitting electronic data that provides evidence of sending and receipt, with legal effect equivalent to registered postal mail.
- Remote SigningA cloud-based electronic signing service where the qualified signature creation device is managed by a QTSP, allowing users to create qualified signatures without local hardware.
Technical Standards
- Verifiable Credential (VC)A tamper-evident, cryptographically signed digital credential that can be verified without contacting the issuer, enabling decentralised trust in digital identity systems.
- Decentralized Identifier (DID)A globally unique identifier that can be resolved to a DID document containing public keys and service endpoints, enabling verifiable, self-sovereign digital identity without a central registry.
- Architecture Reference Framework (ARF)The technical specification document that defines the architecture, protocols, credential formats, and security requirements for the European Digital Identity Wallet ecosystem.
- Zero-Knowledge Proof (ZKP)A cryptographic method that allows one party to prove a statement is true without revealing any underlying data, enabling privacy-preserving identity verification.
- OpenID for Verifiable Credentials (OpenID4VC)A family of protocols built on OpenID Connect that standardise the issuance, presentation, and verification of digital credentials, adopted as the core protocol suite for the EUDIW.
- SD-JWT (Selective Disclosure JSON Web Token)A credential format that extends standard JWTs with selective disclosure capabilities, allowing holders to reveal only chosen claims, adopted as a core format for the EUDIW.
- mdoc (ISO 18013-5)A CBOR-based credential format originally developed for mobile driving licences and adopted as a core credential format for the EUDIW, supporting offline verification and selective disclosure.
- Wallet AttestationA cryptographic mechanism that allows a relying party to verify that a wallet application is genuine, certified, and running in a secure environment before accepting credentials from it.
Governance
- Trust FrameworkA set of rules, policies, and technical standards that govern how digital identities and credentials are issued, managed, and verified within a defined ecosystem.
- Large-Scale Pilot (LSP)EU-funded multi-country projects that test the European Digital Identity Wallet in real-world scenarios across various sectors before its full deployment.
- Notified eID SchemeAn eID scheme that a Member State has formally notified to the European Commission, triggering mandatory cross-border recognition by other Member States for public service access.
- Supervisory BodyThe national authority designated by each Member State to oversee trust service providers, ensure compliance with eIDAS requirements, and maintain the national Trusted List.
- Conformity AssessmentThe formal evaluation process, performed by an accredited body, that verifies whether a trust service provider or wallet implementation meets the regulatory and technical requirements of eIDAS.
- Trusted ListAn authoritative, machine-readable registry maintained by each Member State listing all qualified trust service providers and their services, forming the backbone of the eIDAS trust model.
Understand How These Concepts Apply to Your Business
Take our free eIDAS 2.0 readiness assessment and discover which areas of digital identity compliance need your attention.