eIDAS 2.0 and digital certificates are related but fundamentally different tools. Digital certificates are cryptographic credentials used to verify identity or secure communications, while eIDAS 2.0 is a regulatory framework that defines how digital identity, trust services, and credentials are issued, recognised, and used across the EU. In short, digital certificates are one component within the broader eIDAS ecosystem.
Understanding the distinction matters because eIDAS 2.0 introduces new concepts, such as verifiable credentials and the European Digital Identity Wallet, that go well beyond what traditional certificates can do. The sections below walk through the key differences, how the two relate, and what this means for organisations that rely on certificates today.
How does eIDAS 2.0 go beyond traditional digital certificates?
eIDAS 2.0 goes beyond digital certificates by creating a complete framework for digital identity that covers not just authentication and signing, but also the portable, user-controlled sharing of verified personal and organisational data. Where traditional certificates focus on proving a key belongs to an entity, eIDAS 2.0 enables people and businesses to share specific attributes, such as qualifications or age, without exposing unnecessary personal information.
The original eIDAS regulation, in place since 2014, established mutual recognition of electronic ID systems across EU Member States and introduced qualified trust services including electronic signatures and certificates. However, it left significant gaps: participation was optional for Member States, coverage of the private sector was limited, and there was no standardised way for citizens to carry their identity credentials across borders in a single, secure application.
eIDAS 2.0 addresses these gaps by making the European Digital Identity Wallet mandatory for all Member States. Every EU citizen, resident, and business will be able to use a wallet to store verified identity data, documents such as diplomas or driving licences, and to authenticate or sign digitally across both public and private sector services. This shifts the model from a collection of technical standards for certificates towards a full identity ecosystem built on interoperability, user control, and regulatory certainty.
What are qualified digital certificates under eIDAS?
Qualified digital certificates under eIDAS are cryptographic certificates issued by a Qualified Trust Service Provider (QTSP) that meet the highest security and legal standards defined in the regulation. They are used primarily for qualified electronic signatures (QES) and qualified electronic seals, and they carry the same legal weight as a handwritten signature across all EU Member States.
There are two main types relevant to most organisations:
- Qualified certificates for electronic signatures: Issued to natural persons, these bind a public key to a verified individual identity and are used to sign documents with full legal standing under EU law.
- Qualified certificates for electronic seals: Issued to legal entities such as companies or public bodies, these confirm that a document or data originates from a specific organisation and has not been altered.
QTSPs that issue these certificates are listed on national Trusted Lists, which are published by each EU Member State and compiled into the European Trusted List (EUTL). This public infrastructure is what gives qualified certificates their cross-border legal recognition. A certificate issued by a QTSP in the Netherlands, for example, is automatically recognised in Germany, France, or any other Member State without additional verification steps.
Under eIDAS 2.0, the scope of qualified trust services expands further to include new categories such as qualified electronic attestations of attributes, which are a form of verifiable credential discussed in the next section.
How do verifiable credentials differ from digital certificates?
Verifiable credentials differ from digital certificates in what they represent and how they are used. A digital certificate proves that a cryptographic key belongs to a specific entity. A verifiable credential proves that a specific claim about a person or organisation is true, for example that someone holds a valid driving licence, has completed a degree, or is authorised to act on behalf of a company.
This distinction has practical consequences. With a traditional certificate, the relying party receives proof of identity at the cryptographic level. With a verifiable credential, the holder can selectively share only the attributes that are relevant to a given interaction. Someone proving they are over 18 does not need to share their full date of birth. Someone proving professional qualifications does not need to share their home address. This selective disclosure is a core privacy feature of the verifiable credential model.
Under eIDAS 2.0, a new category called qualified electronic attestations of attributes (QEAAs) brings verifiable credentials into the regulated trust framework. QEAAs are issued by QTSPs and carry legal standing comparable to qualified certificates, but they are designed to describe attributes rather than bind keys. They are the building block for what users will store and share through the EUDI Wallet.
In technical terms, verifiable credentials use open standards such as W3C Verifiable Credentials and formats compatible with the EUDI Wallet architecture, while traditional digital certificates follow X.509 standards. Both rely on cryptographic signatures for integrity, but they serve different purposes within the digital identity landscape.
Can digital certificates and eIDAS 2.0 work together?
Yes, digital certificates and eIDAS 2.0 work together and will continue to do so. Qualified certificates remain a central part of the eIDAS 2.0 trust framework, particularly for electronic signatures, electronic seals, and website authentication. eIDAS 2.0 does not replace certificates; it expands the ecosystem around them.
The practical relationship looks like this:
- Certificates underpin trust services: QTSPs still issue qualified certificates for signatures and seals. These remain legally required for many regulated processes, such as signing contracts, authenticating official documents, or sealing data exchanged between organisations.
- Wallets can carry certificate-based credentials: The EUDI Wallet is designed to store and present both traditional identity documents and verifiable credentials. In some flows, a qualified certificate may be used behind the scenes to sign a credential that is then presented from the wallet.
- Attribute attestations complement certificates: Where a certificate proves who you are, a QEAA proves something about you. Together, they cover a wider range of identity and compliance use cases than either can handle alone.
For organisations operating in regulated sectors such as financial services or government, this means existing certificate-based infrastructure does not become obsolete. Instead, it becomes one layer within a richer identity architecture that also supports wallet-based interactions and attribute sharing.
What does this mean for organisations using certificates today?
For organisations that rely on digital certificates today, eIDAS 2.0 signals a period of expansion rather than replacement. Qualified certificates for signatures and seals remain valid and legally recognised. However, organisations will increasingly need to support new interaction patterns that go beyond what certificates alone can deliver, particularly as the EUDI Wallet becomes more widely adopted.
The most immediate considerations are:
- Compliance readiness: eIDAS 2.0 introduces new obligations for specific regulated sectors and service providers. By 24 December 2026, each EU Member State must have at least one certified EUDI Wallet available for citizens, residents, and businesses, and public bodies must accept notified wallets as a means of identification from that date. Regulated private sector organisations — including those in banking and financial services, healthcare, telecoms, energy, transport, education, social security, drinking water, postal services, digital infrastructure, digital services, and very large online platforms with more than 45 million users in the EU — are required to accept the EUDI Wallet where strong user authentication is legally or contractually required, with that obligation taking effect on 24 December 2027. Organisations in scope need to assess whether their current identity infrastructure can accommodate wallet-based flows alongside certificate-based ones.
- Interoperability: Systems that today rely solely on X.509 certificates for identity verification may need to be updated to handle verifiable credentials and EUDI Wallet presentations, which use different technical standards.
- User experience: Certificates are largely invisible to end users, managed by software or hardware tokens. The EUDI Wallet puts identity management directly in the hands of users, which changes how onboarding, authentication, and consent flows are designed.
- Sector-specific requirements: In healthcare and pharmaceuticals, for example, verifiable credentials could replace paper-based processes for prescriptions or professional qualifications, while qualified certificates continue to underpin document signing and audit trails.
Organisations that act early will be better positioned to handle the transition without disruption. This means auditing current certificate use cases, identifying where verifiable credentials or wallet-based flows could add value, and building towards an architecture that supports both in parallel. Reviewing your implementation approach now, rather than waiting for regulatory deadlines, reduces risk and creates a more scalable foundation for digital identity.
How TrustTech helps with eIDAS 2.0 and digital certificates
Navigating the relationship between eIDAS 2.0, qualified certificates, and verifiable credentials is not straightforward, especially when your organisation already has certificate-based infrastructure in place and needs to evolve without breaking what works. TrustTech is built specifically for this transition.
As a platform designed for EU compliance from the ground up, TrustTech supports organisations across the full identity lifecycle, from first verification to qualified signature, with a single connected infrastructure. In practical terms, this means:
- Qualified electronic signatures and seals that meet the highest eIDAS standards, issued through a trusted and compliant framework
- Reusable identity and KYC flows that reduce repeated verification across services and prepare your processes for wallet-based interactions
- Verifiable credential support aligned with EUDI Wallet architecture, so your organisation is ready for the next generation of digital identity
- Cross-sector expertise in finance, government, healthcare, and science, so the guidance you receive is relevant to your specific regulatory environment
- A platform designed to be in production in under five months, with measurable improvements in onboarding speed and compliance confidence
Whether you are assessing your current certificate infrastructure, preparing for EUDI Wallet integration, or looking to streamline compliance across your organisation, TrustTech provides the expertise and technology to move forward with clarity. Explore our identity solutions or get in touch to discuss your specific situation.