As early as 2027, it will be possible to securely identify oneself using the European Digital Identity Wallet via smartphone and to manage various supporting documents digitally. Business preparations are already underway for both the issuers and the relying parties, and these preparations will be largely defined by the types of supporting documents to be processed.
The eIDAS Regulation classifies these so-called credentials into different categories based on varying requirements and legal status. While an analytical look at the contents of the EUDI Wallet is therefore more complex than that of a physical wallet, it does point the way toward the future of digital identities in Europe.
Table of Contents
What Credentials Mean for the EUDI Wallet
Identity cards, driver’s licenses, college transcripts, insurance policies, or membership certificates. All these documents are typical credentials that will be available in the EUDI Wallet in the future for digital identification and to verify various authorizations. Some of these are issued by government agencies, others by private companies. They all contain attributes of varying levels of sensitivity and complexity—such as name, age, account number, or student ID number—which together form a comprehensive picture of a person’s identity. For data minimization purposes, only the information strictly necessary for the specific purpose is retrieved from the wallet, whether it’s to open a bank account or rent a car.
To ensure that this heterogeneous data is handled in a manner that complies with regulatory requirements, the eIDAS Regulation classifies credentials—in addition to personal identity data (PID)—into EAA, QEAA, and PuB-EAA based on the type of source, the reliability of the issuing authority, and the associated liability. By the time of implementation at the latest, the organizations involved must be clear about the type of credentials to be processed. This is because it determines which organizational obligations—such as conformity assessments, registration, or supervisory requirements—they must fulfill as issuing or processing entities.
Definition: Verifiable Credentials (VCs) are documents that are securely stored in the EUDI Wallet and cryptographically signed by the issuer. They differ based on requirements and legal status.
PID – Personal Identification Data
Personal Identification Data (PID) plays a somewhat special role. This is a digital equivalent of an ID card, with the data it contains stored in the wallet. Accordingly, the group of authorized issuers is limited to government agencies or government-authorized private entities. Another notable aspect is what will likely be the most common user scenario initially: the activation of the EUDI Wallet. In Germany, PIDs are added to the wallet based on identification via the online ID function (eID). Once issued and verified, PIDs can be linked to other credentials or used independently as proof of identity.
Key Data at a Glance:
- Required Attributes: Last Name, First Name, Date of Birth, Place of Birth, Nationality
- Optional Attributes (Excerpt): Address (multiple subfields), unique administrative identifier, maiden name, gender, email address
- Verification level for identity/attribute verification: high
- Legal status: full-fledged government-issued proof of identity
- Formats: SD-JWT VC, mDoc
- Possible use cases: account opening, KYC, age verification, access to government services
Implications and Significance for Companies
Private companies without a government mandate are not permitted to issue PID credentials, but these are an initial component of every EUDI wallet, which a relying party is either required to accept or at least has an interest in accepting: This is because they result in the same use cases and economic effects as the eID in typical identification and KYC processes, not least cost savings and increased efficiency. The extent of these benefits depends heavily on the frequency of end-user adoption. The EUDI wallet could surpass the eID in this regard, as it leverages the convenience of smartphones and allows not only online transactions but also fully digital offline use on-site. Furthermore, the large number of applications enabled by additional credential types could drive up end-user adoption and, consequently, the ROI for businesses.
EAA – Electronic Attestations of Attributes
Electronic Attestations of Attributes (EAA) encompass significantly more types of documentation than the PID. They are issued by private, public, or industry-specific entities such as universities, banks, or associations and certify various affiliations and authorizations, for example, as a university transcript, a bank confirmation (such as regarding creditworthiness), or a certificate of membership in an association. There are no specific restrictions on who may issue these documents, but by definition, they are issued by so-called Trust Service Providers (TSPs), which must meet the requirements of the eIDAS Regulation.
There is currently no formal mandatory qualification, but registration rules are to be implemented at the discretion of national legislation. The issuance of QEAA and PuB-EAA is more heavily regulated; these are subject to a stricter trust model and are legally equivalent to original physical documents. EAA is therefore the umbrella term, but in practice it is often used to refer to non-qualified or private-sector credentials.
Non-qualified EAA
These credentials are expected to be flexibly applicable in the private sector.
- Mandatory attributes: no requirements; the issuer decides
- Verification level for identity/attribute verification: not required by law
- Legal status: Based on contracts and terms and conditions; no obligation to accept
- Formats (selection): SD-JWT, mDoc, W3C Verifiable Credential
- Issuers: Trust Service Providers (TSPs) such as private companies and associations
- Possible use cases: Issuing airline tickets, verifying memberships, ticket validation
QEAA – Qualified Electronic Attestations of Attributes
A Qualified Electronic Attestation of Attributes (QEAA) may be issued exclusively by Qualified Trust Service Providers (QTSPs) that have attained a qualified status as defined in the eIDAS Regulation. This requires a successful conformity assessment by an accredited assessment body as well as approval by the competent national supervisory authority.
All EU countries must maintain and publish corresponding lists of qualified trust service providers (Trusted Lists). The listed organizations are subject to regular audits to ensure the long-term technical and organizational integrity of the issued QEAA. Due to the strictly regulated and audited status of their issuers, these have the same legal effect as a physical original document; the main difference from simple EAA lies in matters of liability:
If damage results from a non-qualified EAA, the burden of proof lies with the relying party – it must prove that the issuer caused the error intentionally or through negligence. In the case of a QEAA, the burden of proof is reversed (Art. 13 of the eIDAS Regulation): The issuing QTSP must prove that it is not at fault.
- Mandatory attributes (excerpt): strictly regulated under eIDAS, issuer identifier, unique identification of the recipient, the certified attribute itself, unique QEAA status
- Verification level for identity/attribute verification: high
- Issuer: QTSP
- Legal status: Equivalent to paper-based documents; presumption of accuracy; liability rests with the issuing QTSP
- Possible use cases: KYC verification, regulated professional certifications
PuB–EAA – Public Electronic Attestations of Attributes
Similar to PID, Public Electronic Attestations of Attributes (PuB-EAA) are issued by public authorities or their contractors, but they encompass attributes beyond mere identity. The attributes originate from an authentic, notified source that is designated by and held accountable by the EU member state. The content is issued by the authority itself, or the authority acts as an authentic source for the commissioned issuer. A qualified electronic seal certificate from a QTSP is used to ensure legally secure sealing. This grants the PuB-EAA the same presumption of integrity and authenticity of origin as a physical official seal.
- Required attributes: Vary by document type, but must comply with the government-mandated schema
- Level of identity/attribute verification: High
- Legal status: Equivalent to paper originals; accepted throughout the EU
- Issuers: Public agencies and authorities, as well as their contractors
- Possible use cases: Certificate of residence, tax assessment notice, college transcript
Two primary credential formats
Even though not all details have been finalized yet, technical specifications for issuing and verifying credentials are already in place. The choice of format depends less on the type of attributes and more on the presentation channel – the EUDI Wallet is designed for both online and on-site use.
- mDoc (mobile Document), a compact, binary-encoded format according to ISO/IEC 18013-5, supports both presentation methods: fast wireless transmission via NFC in person as well as online verification.
- SD-JWT VC, the text-based JSON format, is primarily designed for online verification, but not for traditional NFC tap interactions.
Online verification is technically standardized using the OpenID4VP protocol, which can transmit both SD-JWT and mDoc credentials remotely to the verifier. The verifier is the technical component that sends the verification request from the relying party to the wallet and cryptographically verifies the response.
From a technical standpoint, the types of credentials listed differ only marginally. The most significant differences stem not from the code itself, but from legislation—specifically, the legal status of the issuers, their oversight, and their liability.
Outlook for Companies – Preparing Despite Unresolved Issues
One thing is certain: The EUDI wallet will contain PID, EAA, QEAA, and PuB–EAA, all of which follow a data-minimal verification logic. In accordance with data minimization, only those attributes that are essential for the specific purpose are read – unlike with many physical documents. The regulatory framework is already clear: PIDs are reserved for government agencies or their direct contractors; QEAAs and PuB–EAAs are strictly regulated; and non-qualified EAAs can be used flexibly. The implications vary depending on an organization’s role in the wallet ecosystem:
- As an issuer of non-qualified EAA, the general requirements for trust service providers must be met, whereas QEAA requires a complex and costly qualification process as a QTSP.
- Relying parties must determine early on which attributes they actually need for each use case and for what purpose, as this information legally binds the subsequent retrieval of data.
In addition, it is already necessary to align the overarching business objectives with the existing legal framework comprising eIDAS 2.0, ARF specifications, and national legislation. As an experienced specialist in EUDI wallet integration, AUTHADA can support companies in the implementation process and guide them through the ongoing technical and regulatory details. One of the most important questions remains unresolved: Which specific credentials will ultimately be assigned to EAA or QEAA?
The main difference here lies in liability, which stems from the strictly regulated legal status of QTSPs as QEAA issuers. A detailed rulebook already exists for the PID, specifying how its attributes are structured and encoded. For most other credentials, however, this counterpart is still missing. This and other aspects are the subject of ongoing standardization, while a Europe-wide trust infrastructure is taking shape with the EUDI Wallet.
Is your company interested in issuing or processing credentials for the EUDI Wallet? We would be happy to assist you with the technical implementation. Please contact us.
Would you like to be kept up to date with our newsletter?
Don’t miss any news and subscribe to our newsletter. You can subscribe here.
