From the 2014 Regulation to eIDAS 2.0
The original eIDAS Regulation entered into force on 17 September 2014. Its trust-service provisions became applicable from 1 July 2016, and mandatory cross-border recognition of notified electronic identification means followed from 29 September 2018.
The 2024 amendment entered into force on 20 May 2024. It introduced the European Digital Identity Wallet, selective disclosure of attributes, qualified electronic attestations of attributes and additional trust-service categories. It also strengthened requirements for providers and created obligations for specified public and private relying parties to accept the Wallet where the statutory conditions are met.
The important deadlines do not run simply from 20 May 2024. Article 5a and related provisions link several deadlines to Commission implementing acts adopted at the end of 2024. The first package entered into force on 24 December 2024. As a result, Member States must provide at least one Wallet by 24 December 2026, while specified private relying parties have a later acceptance deadline, generally 24 December 2027.[10]
Two pillars: identification and trust services
Electronic identification answers the question "who is the person accessing the service?" Trust services answer different questions: who signed or sealed a document, whether data existed at a given time, whether an electronic delivery took place, or whether a website certificate can be trusted.
The distinction matters. An electronic identification means is not an electronic signature. Logging in with a notified eID can establish identity, but it does not automatically create a signature on a document. Conversely, a qualified signature proves the act of the signatory in relation to signed data; it is not a general-purpose login mechanism.
Electronic identification assurance levels
The eIDAS system uses the assurance levels low, substantial and high. Implementing Regulation (EU) 2015/1502[11] defines minimum technical specifications and procedures for those levels. A Member State that notifies a scheme under Article 9 enables cross-border recognition under the conditions of eIDAS.
| Level | Identity proofing and authentication |
|---|---|
| Low | Limited confidence; comparatively simple enrollment and authentication. |
| Substantial | Stronger identity proofing and authentication designed to reduce the risk of impersonation or alteration. |
| High | Stronger identity proofing, resistance to duplication and tampering, and authentication designed to protect against sophisticated attacks. |
Poland has notified its Public Electronic Identification System.[12] The exact assurance level and recognition requirements of a particular means should be checked in the notification and current national documentation rather than inferred from the product name.
A service requiring substantial assurance must accept notified means that satisfy the applicable cross-border recognition rules at substantial or high level. A service requiring high assurance can require the high level. These rules should not be confused with the term "qualified", which belongs to trust services.
Electronic signatures: simple, advanced and qualified
An electronic signature is data in electronic form attached to or logically associated with other electronic data and used by the signatory to sign.
An advanced electronic signature must be uniquely linked to the signatory, capable of identifying the signatory, created using signature-creation data under the control of the signatory with a high level of confidence, and linked to the signed data so that subsequent changes are detectable.
A qualified electronic signature is an advanced signature created by a qualified electronic signature creation device and based on a qualified certificate. Article 25 gives it the legal effect equivalent to a handwritten signature and requires recognition of qualified signatures based on qualified certificates issued in other Member States.
The legal effect of a non-qualified electronic signature cannot be denied solely because it is electronic or because it does not meet qualified-signature requirements. However, equivalence with a handwritten signature is a specific statutory effect of the qualified signature.
Electronic seals, time stamps, delivery and website certificates
Electronic seals are designed primarily for legal persons and support integrity and origin of data. They are not simply "company signatures" in the sense of a declaration of intent by a natural person.
Electronic time stamps bind data to a particular time and provide evidence that the data existed at that time. Qualified time stamps receive the specific presumptions established in eIDAS.
Electronic registered delivery services provide evidence relating to sending and receiving electronic data and protect against risks of loss, theft, damage or unauthorized alteration. Qualified services receive additional legal effects under the Regulation.
Website authentication certificates help authenticate websites and entities. Their legal category is distinct from TLS security as a whole: a certificate does not by itself prove that the web application is secure.
Trust service providers and qualified status
A trust service provider (TSP) may provide trust services without all of them being qualified. A qualified trust service provider (QTSP) is a provider that has been granted qualified status for one or more qualified trust services and appears on the national trusted list.
Qualified status is service-specific. The fact that a company appears on a trusted list does not mean every service it offers is qualified. Users should check the exact service entry and status on the EU Trusted List Browser or the national trusted list.[6][13]
Qualified providers are subject to stricter legal, organizational and technical requirements. They use relevant ETSI standards, maintain security and continuity arrangements, protect cryptographic material, cooperate with supervision and undergo conformity assessment by an accredited conformity assessment body. Article 20 requires a conformity assessment at least every 24 months, with the report submitted to the supervisory body.[1][4]
ETSI EN 319 401 is an important general policy standard for trust service providers. The applicable version should always be verified; in 2026 ETSI published EN 319 401 V3.2.1.[4]
The most important distinction in the trust-service layer is not between one brand and another, but between qualified and non-qualified status. A non-qualified trust service can still be technically strong and legally useful, but it does not receive the specific legal presumptions that eIDAS grants to qualified services. In a dispute, its evidential value is assessed on the ordinary rules of evidence.
Trusted lists
Each Member State publishes a trusted list identifying qualified providers and qualified services. EU tools aggregate those lists. A relying party should not treat a logo, marketing claim or certificate file as sufficient evidence of qualified status; the trusted-list entry is the authoritative operational reference.
The Polish trusted list is published in the European trusted-list format.[13] The set of providers and services can change, so an article or audit report should identify the date on which the list was checked.
Signature formats and long-term validation
The legal level of a signature and the technical format are separate questions. PAdES is commonly used for PDF documents, XAdES for XML, CAdES as a more general cryptographic container, and JAdES for JSON-oriented environments. The receiving system must be able to validate the format it accepts; a legally qualified signature that cannot be technically validated by the recipient is an operational failure even if its legal status is clear.
Long-term evidence also requires more than checking a certificate on the day of signing. For records that must remain verifiable for years, the organization should consider qualified time stamps and long-term validation data. A qualified time stamp can help prove that signed data existed at a particular time and that the signature was created while relevant trust material was valid. The retention design should therefore cover signature validation, revocation information and preservation of evidence, not only storage of the PDF itself.
Qualified providers in Poland
The Polish trusted list[13] identifies providers that have been granted qualified status by the competent supervisory authority. In the edition of 27 August 2026, the list contained nine providers, but their qualified service portfolios differed significantly. This is why procurement should start from the required service and only then from the provider name.
| Entity | Brand | Qualified services |
|---|---|---|
| Asseco Data Systems | Certum | Certificates, time stamps, validation, preservation of signatures and seals, registered delivery |
| Polska Wytwornia Papierow Wartosciowych | Sigillum | Certificates, time stamps, remote signing and sealing devices, registered delivery |
| Krajowa Izba Rozliczeniowa | Szafir | Certificates, time stamps |
| Enigma Systemy Ochrony Informacji | CenCert | Certificates, time stamps, validation, remote signing devices |
| EuroCert | - | Certificates, time stamps |
| Unizeto Technologies | - | Qualified certificates |
| Poczta Polska | - | Qualified electronic registered delivery |
| Autenti | - | Qualified electronic registered delivery, qualified validation of signatures and seals |
| KFJ Inwestycje | - | Qualified electronic registered delivery |
Because the list is dynamic, the current service entry should always be verified immediately before procurement or legal reliance. Brand names can also obscure the legal counterparty. CenCert is a brand used by Enigma Systemy Ochrony Informacji, while other brands may belong to separate companies or corporate groups. The contract, trusted-list entry and certificate policy should therefore identify the legal entity, the exact qualified service and the applicable policy identifier.
Supervision and the national trust infrastructure in Poland
A frequent terminology mistake is to confuse eIDAS supervision with the national cybersecurity certification authority created under the EU Cybersecurity Act. They are different systems. In Poland, supervision of trust services is exercised by the minister competent for digital affairs under the Act of 5 September 2016 on trust services and electronic identification.[3]
The same national framework provides for a public register of trust service providers, the national trusted list and the national certification centre used within the domestic trust infrastructure. The minister may also use statutory mechanisms involving the National Bank of Poland for specified national certification functions.
Supervisory powers include granting and withdrawing qualified status, updating the trusted list, carrying out or ordering controls, requiring remediation and applying the national enforcement mechanisms. The most consequential outcome for a QTSP is not necessarily a fine: loss of qualified status can remove the legal basis on which the qualified service is offered.
The recurring conformity assessment under Article 20 is therefore central. It reviews not only cryptographic algorithms but the organization, personnel, continuity, incident handling, operational controls and service-specific technical requirements of the provider. A provider that passes one audit does not receive permanent qualification; continued status depends on ongoing conformity.
European Digital Identity Wallet
The Wallet is the most visible feature of eIDAS 2.0. Its design is asymmetric: Member States must provide at least one Wallet solution, while use by individuals is voluntary. A person should be able to obtain and present identification data and electronic attestations of attributes and, where applicable, use signature functionality without being forced to reveal more data than necessary.
The Architecture and Reference Framework published by the Commission[5] distinguishes wallet solutions, wallet instances or units, wallet providers, issuers of person identification data and attestations, and relying parties. The separation of roles is important for privacy and accountability.
The implementing acts adopted in late 2024 cover core functionality and integrity, protocols and interfaces, person identification data and electronic attestations of attributes, and notifications to the Commission. Regulation (EU) 2024/2977[10], for example, defines rules for issuance of identification data and attestations to Wallets and was amended in 2026; the current consolidated version should be used for implementation.
Security requirements include secure cryptographic components, integrity protection, authentication of the user, controlled interfaces, privacy safeguards and certification requirements. The legal framework does not justify reducing EUDIW security to the phrase "keys must always be stored in one specific hardware element". Implementations may use different secure hardware and software architectures as long as the applicable legal and certification requirements are met.
Wallet deadlines and Poland
Member States must provide at least one European Digital Identity Wallet within 24 months of the relevant implementing acts, giving the 24 December 2026 deadline used in current implementation planning.[10]
Acceptance obligations apply later. Article 5f covers public-sector bodies requiring electronic identification for online services and specified private-sector relying parties where the statutory conditions are met, including sector and strong-authentication criteria and exceptions for micro and small enterprises. Very large online platforms designated under the Digital Services Act form a separate category. These duties should not be generalized to every website or every business.
For the relevant private relying parties, the main planning date is 24 December 2027. Wallet use remains at the request of the user; acceptance adds a path rather than automatically abolishing existing identification methods.
Poland has been developing its Wallet approach around the mObywatel ecosystem. The Polish Act on trust services and electronic identification[3] supplies the domestic legal framework for supervision and national trust infrastructure and must be aligned with revised eIDAS requirements. Because national implementation work can change quickly, organizations should verify the current legal act and technical integration documentation before procurement or deployment rather than rely on older project descriptions.
Relationship with the GDPR, the AI Act, NIS2 and e-Delivery
GDPR
Processing of personal data under eIDAS remains subject to the GDPR.[7] Wallet design emphasizes data minimization and user control, but neither the Wallet nor qualified status exempts an organization from lawful-basis, transparency, retention, security or data-subject-rights requirements.
Biometric data requires particular care. GDPR Article 9 applies where biometric data are processed for the purpose of uniquely identifying a natural person. eIDAS can provide the identity framework, but it does not automatically create a GDPR legal basis for every biometric processing operation.
AI Act
The AI Act treats biometric systems according to their concrete use. Some practices are prohibited and certain biometric systems may fall within high-risk categories. It is therefore inaccurate to say that every biometric function used in a Wallet is automatically a high-risk AI system. AI Act analysis is required only where the specific component meets its definitions and classification rules.
NIS2
Qualified trust service providers and certain digital-identity actors can also be subject to NIS2/KSC cybersecurity requirements.[8] eIDAS governs trust-service and identity requirements; NIS2 governs cybersecurity risk management and incident obligations within its scope. An audit should identify which requirement comes from which legal regime. An ISO/IEC 27001-based information security management system can help organize common evidence and controls, but it does not replace the legal requirements of eIDAS, the GDPR or NIS2.[9]
Polish e-Delivery
The Polish e-Delivery system is a national electronic-delivery regime that uses legal concepts related to electronic registered delivery but also depends on Polish statutes and implementation rules. An Address for Electronic Delivery is not automatically created for every individual; for many businesses and public entities specific statutory deadlines apply.
For organizations, the important practical lesson is to separate three questions: whether a communication must be delivered through the national e-Delivery system, whether the underlying service is a qualified electronic registered delivery service, and what evidence of sending and receipt the process must preserve.
Audit and security checklist
- Identify all electronic identification means and trust services used by the organization.
- Determine which services are qualified and verify them on trusted lists.
- Check certificate, seal, signature and time-stamp validation procedures, including long-term validation where needed.
- Review protection of private keys and signing or sealing devices.
- Assess continuity, incident management, logging and change management of trust-service integrations.
- For EUDIW, determine whether the organization will issue attributes, provide a Wallet, or act as a relying party.
- Check whether the December 2026 or December 2027 deadlines actually apply to the organization.
- Map personal-data processing and GDPR obligations separately.
- Assess third-party dependencies and the security of APIs and integration components.
- Retain evidence of the legal and technical versions used in the assessment.
Frequently asked questions
- What is eIDAS?
- eIDAS stands for electronic identification, authentication and trust services. Regulation (EU) No 910/2014 created a common EU legal framework for electronic identification and trust services. Its purpose is cross-border recognition: a notified national eID can be used in another Member State under the conditions of the Regulation, while qualified trust services receive Union-wide legal effects. The framework covers much more than signatures: electronic seals, time stamps, electronic registered delivery, website authentication certificates and, after the 2024 amendment, electronic attestations of attributes, electronic archiving, electronic ledgers and the Wallet.
- What changed between eIDAS 1.0 and eIDAS 2.0?
- The original 2014 framework created cross-border recognition of notified electronic identification schemes and the first common legal regime for trust services. Regulation (EU) 2024/1183 expanded the framework around a European Digital Identity Wallet, selective disclosure of attributes and new trust services. The relevant deadlines are linked to implementing acts that entered into force on 24 December 2024: Wallet availability by 24 December 2026 and, for the relevant private relying parties, acceptance generally by 24 December 2027.
- What is a qualified electronic signature?
- A qualified electronic signature, or QES, is an advanced electronic signature created by a qualified electronic signature creation device and based on a qualified certificate. Its distinguishing legal effect is Article 25(2): a qualified electronic signature has the equivalent legal effect of a handwritten signature. This applies across the Union. The Regulation does not, however, abolish special formal requirements such as notarisation where national or Union law requires them.
- What is the difference between a TSP and a QTSP?
- A trust service provider supplies one or more trust services. A qualified trust service provider has obtained qualified status for at least one qualified trust service. Qualification is service-specific and is evidenced through the trusted list, not through a marketing statement. A QTSP is subject to enhanced organizational and technical requirements and to conformity assessment at least every 24 months. Before relying on a provider, verify both the legal entity and the exact service entry.
- What do the assurance levels low, substantial and high mean?
- The levels of assurance describe confidence in an electronic identification means, not the legal level of an electronic signature. Implementing Regulation 2015/1502 defines requirements for the three levels. A service requiring substantial assurance must accept notified means at substantial or high level; a service requiring high assurance can require the high level. These terms should not be confused with "qualified", which belongs to trust services.
- What is a QWAC?
- A QWAC is a qualified certificate for website authentication. It is issued under the eIDAS qualified-trust-service regime and identifies the entity responsible for a website according to the requirements of the Regulation. Its qualified legal status does not mean that the website application, server configuration or entire TLS deployment is secure. The revised framework also contains rules on browser recognition of such certificates and a safeguard for exceptional security concerns.
- When will the EU Digital Identity Wallet be available?
- Member States must provide at least one Wallet within the statutory period linked to the relevant implementing acts. With the first package entering into force on 24 December 2024, the principal availability deadline is 24 December 2026. Use by an individual remains voluntary. Selective disclosure is a central design goal: a user should be able to prove a necessary attribute without automatically presenting an entire identity document.
- Does a qualified signature have the same legal effect as a paper signature?
- A qualified electronic signature has the equivalent legal effect of a handwritten signature under Article 25(2). That does not mean every electronic document automatically satisfies every special form required by law. A transaction requiring a notarial act, for example, must still satisfy the law governing that special form. For long-lived documents, organizations should preserve validation evidence and, where appropriate, qualified time stamps so that the signature remains verifiable after certificate expiry.
- Who issues qualified certificates in Poland?
- The current Polish trusted list is the authoritative source. Qualified certificate services are provided by Asseco Data Systems (Certum), Polska Wytwornia Papierow Wartosciowych (Sigillum), Krajowa Izba Rozliczeniowa (Szafir), Enigma Systemy Ochrony Informacji (CenCert), EuroCert and Unizeto Technologies. The other three entries - Poczta Polska, Autenti and KFJ Inwestycje - cover qualified electronic registered delivery or validation. Do not rely on an old comparison table when selecting a provider.
- Does a SaaS provider have to comply with eIDAS?
- A SaaS provider is not subject to the trust-service-provider regime merely because it delivers software online. Direct eIDAS duties arise when the provider performs a regulated role, for example by providing a trust service or acting as a relying party subject to a Wallet acceptance duty. A SaaS product may nevertheless need eIDAS integration: validating qualified signatures, accepting a notified eID or EUDIW, or preserving evidence from electronic registered delivery.
- What is the relationship between Polish e-Doreczenia and eIDAS?
- The Polish e-Doreczenia regime implements national electronic-delivery processes using concepts that overlap with qualified electronic registered delivery. The national statutory timetable determines which public bodies, companies and entrepreneurs must have an Address for Electronic Delivery and when the public system becomes the required channel. An individual does not automatically receive such an address merely because eIDAS exists.
- Does eIDAS replace the GDPR, NIS2 or an ISMS?
- No. eIDAS regulates electronic identity and trust services. The GDPR governs personal-data processing. NIS2 and the Polish KSC impose cybersecurity-risk-management and incident duties within their scope. An ISO/IEC 27001-based ISMS can provide a shared management structure and evidence base, but it does not turn these different legal obligations into one requirement.
Need consulting in this area?
A free 30-60 minute consultation. No obligations. We discuss needs, scale and a high-level timeline.
Related content
Other competence areas
- IT security audit
- Vulnerability scanning
- Penetration testing
- Device and system hardening
- Email security audit
- KRI compliance audit
- KSC and NIS2 audit
- GDPR compliance audit
- Information security policy
- ISMS - information security management system
- Security awareness - onsite and online
- SOC 24/7 - monitoring and response
Compliance and regulation
Bibliography and sources
All cited sources are publicly available. Checked as of 29 August 2026. EU regulations link to EUR-Lex, standards to ETSI, and the trusted list to its current file.
- [1] regulationEuropean Parliament and Council of the EU (2014). Regulation (EU) No 910/2014 of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market (eIDAS). OJ EU L 257, 28.8.2014. · EUR-Lex
- [2] regulationEuropean Parliament and Council of the EU (2024). Regulation (EU) 2024/1183 of 11 April 2024 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework (eIDAS 2.0). · EUR-Lex
- [3] regulationParliament of the Republic of Poland (2016). Polish Act of 5 September 2016 on trust services and electronic identification. Journal of Laws 2016 item 1579; consolidated text 2024 item 1725. As amended by the Act of 23 January 2026 (Journal of Laws 2026 item 252) · ISAP
- [4] standardEuropean Telecommunications Standards Institute (ETSI) (2026). ETSI EN 319 401 V3.2.1 - Electronic Signatures and Trust Infrastructures (ESI); General Policy Requirements for Trust Service Providers. Published 8 January 2026; replaced V3.1.1 of 2024 · ETSI
- [5] guidelineEuropean Commission, eIDAS Expert Group (2024). Architecture and Reference Framework (ARF) for the European Digital Identity Wallet. · digital-strategy
- [6] guidelineEuropean Commission (2026). EU Trusted List Browser - the aggregated view of Member State trusted lists. · EU
- [7] regulationEuropean Parliament and Council of the EU (2016). Regulation (EU) 2016/679 (GDPR). OJ EU L 119, 4.5.2016. · EUR-Lex
- [8] regulationEuropean Parliament and Council of the EU (2022). Directive (EU) 2022/2555 (NIS2). OJ EU L 333, 27.12.2022. · EUR-Lex
- [9] standardISO/IEC (2022). ISO/IEC 27001:2022 - Information security management systems - Requirements. · ISO
- [10] regulationEuropean Commission (2024). Commission Implementing Regulation (EU) 2024/2977 of 28 November 2024 on person identification data and electronic attestations of attributes issued to European Digital Identity Wallets. OJ EU L, 2024/2977, 4.12.2024. The first of a package of five implementing regulations; the 24- and 36-month periods in Articles 5a and 5f of eIDAS run from their entry into force on 24 December 2024 · EUR-Lex
- [11] regulationEuropean Commission (2015). Commission Implementing Regulation (EU) 2015/1502 of 8 September 2015 on minimum technical specifications and procedures for assurance levels for electronic identification means. OJ EU L 235. · EUR-Lex
- [12] guidelineEuropean Commission (2023). Notification of the Public Electronic Identification System scheme submitted by Poland under Article 9(1) of Regulation (EU) No 910/2014. OJ EU C 136/02, 19.4.2023. · EUR-Lex
- [13] guidelineMinister competent for digital affairs / National Bank of Poland (2026). Trusted list - Republic of Poland (PL TSL), edition No 161 of 27 August 2026. XML format per ETSI TS 119 612 · PL TSL