Certification bodies play a central role in eIDAS 2.0 compliance by independently verifying that trust service providers and wallet solutions meet the regulation’s technical and security requirements. Without a successful conformity assessment from a recognized certification body, organizations cannot obtain or maintain qualified status under eIDAS 2.0. This article walks through the most common questions organizations ask about certification bodies, the assessment process, and what to expect when preparing for compliance.
What do certification bodies actually assess under eIDAS 2.0?
Under eIDAS 2.0, certification bodies assess whether a trust service provider or wallet solution meets the regulation’s defined technical, organizational, and security requirements. This includes evaluating identity verification procedures, cryptographic controls, data protection practices, incident management, and the overall security architecture of the service or system being assessed.
The scope of what gets assessed depends on the type of service or product involved. For qualified trust service providers (QTSPs), the assessment covers the full lifecycle of the trust service, from how identities are verified at onboarding to how certificates or signatures are issued, managed, and revoked. For EUDI Wallet solutions, the assessment focuses on whether the wallet meets the requirements set out in the Architecture and Reference Framework (ARF), including security, interoperability, and user control over personal data.
Broadly, a conformity assessment under eIDAS 2.0 examines the following areas:
- Identity proofing and registration procedures
- Key management and cryptographic infrastructure
- Physical and logical security controls
- Incident response and breach notification processes
- Policies and documentation governing the service
- Compliance with applicable implementing regulations and referenced standards
The eIDAS 2.0 framework references a significant number of Commission Implementing Regulations that define specific requirements for different trust services, including qualified electronic signatures, seals, timestamps, registered delivery services, and website authentication certificates. Certification bodies use these implementing regulations, along with harmonized standards, as the basis for their assessments.
How does the conformity assessment process work?
The conformity assessment process under eIDAS 2.0 is a structured audit in which an accredited certification body evaluates a trust service provider or wallet solution against defined requirements. The process typically involves a documentation review, technical testing, and an on-site or remote audit, resulting in a conformity assessment report that determines whether qualified status can be granted.
The process generally follows these stages:
- Preparation and scoping: The organization defines the scope of the assessment, identifies which trust services or wallet components are being assessed, and gathers the required documentation.
- Documentation review: The certification body reviews policies, procedures, technical specifications, and evidence of implemented controls against the applicable standards and implementing regulations.
- Technical testing and audit: Auditors conduct hands-on testing of systems, processes, and controls. This may include penetration testing, review of cryptographic implementations, and interviews with key personnel.
- Findings and remediation: Any gaps or non-conformities identified during the audit are documented. The organization has the opportunity to address critical findings before the final report is issued.
- Conformity assessment report: The certification body produces a formal report. This report is submitted to the relevant national supervisory body as part of the notification or supervision process.
The conformity assessment is not a one-time event. Qualified trust service providers are required to undergo reassessment at least every 24 months to maintain their qualified status. This means that ongoing compliance management is just as important as the initial assessment.
Which certification bodies are recognized under eIDAS 2.0?
Certification bodies recognized under eIDAS 2.0 are conformity assessment bodies (CABs) that have been accredited by a national accreditation body in an EU Member State. Accreditation is granted in accordance with Regulation (EC) No 765/2008 and the specific requirements defined in the eIDAS 2.0 implementing regulation on the accreditation of conformity assessment bodies.
Each EU Member State has a designated national accreditation body, such as the Dutch Accreditation Council (RvA) in the Netherlands or DAkkS in Germany. These national bodies accredit CABs to perform conformity assessments specifically for qualified trust services and, under eIDAS 2.0, for EUDI Wallet solutions.
There is no single pan-European list of all recognized certification bodies, but organizations can identify accredited CABs through their national accreditation body’s public register. It is important to verify that the certification body holds the correct scope of accreditation for the specific type of trust service or wallet component being assessed, as accreditation is typically granted for specific service categories rather than as a blanket approval.
When selecting a certification body, organizations in regulated sectors such as financial services or healthcare should also consider whether the CAB has relevant sector experience, as assessors with domain knowledge are better equipped to evaluate complex service environments.
What’s the difference between certification and supervision in eIDAS 2.0?
Certification and supervision are two distinct but complementary mechanisms in eIDAS 2.0. Certification is a private-sector conformity assessment carried out by an accredited certification body to verify technical and operational compliance. Supervision is a public-sector function carried out by national supervisory bodies to oversee qualified trust service providers on an ongoing basis and enforce regulatory requirements.
Think of it this way: certification is the process that gets an organization onto the qualified trust services list, while supervision is what keeps it there and accountable. A QTSP must first obtain a conformity assessment report from a certification body before it can notify the supervisory body of its intent to provide qualified trust services. Once notified and listed on the national Trusted List, the supervisory body takes over ongoing oversight.
The supervisory body has broader powers than a certification body. It can investigate complaints, require audits, impose corrective measures, and ultimately remove a provider from the Trusted List if serious non-conformities are found. The certification body, by contrast, focuses purely on technical assessment against defined standards and does not have regulatory enforcement powers.
For EUDI Wallet solutions, eIDAS 2.0 introduces a specific certification scheme for wallet providers. Member States are responsible for certifying wallet solutions before they can be listed on the official list of certified EUDI Wallets maintained at the European level. This adds another layer of public oversight on top of the conformity assessment process.
When does an organization need a certification body?
An organization needs a certification body under eIDAS 2.0 when it wants to provide qualified trust services, issue or operate an EUDI Wallet solution, or when it is required by regulation to demonstrate conformity with specific eIDAS 2.0 requirements. Certification is mandatory, not optional, for achieving and maintaining qualified status.
Specifically, a certification body is required in the following situations:
- An organization wants to become a qualified trust service provider and offer services such as qualified electronic signatures, seals, timestamps, or registered delivery.
- A Member State or private entity is developing or operating an EUDI Wallet solution that must be certified before it can be officially listed.
- An existing QTSP is approaching its 24-month reassessment deadline and needs to renew its conformity assessment report.
- An organization is expanding its qualified trust services into new service categories that require a separate or updated assessment.
Organizations that are not seeking qualified status, but are relying parties or wallet relying parties, do not typically need to engage a certification body directly. However, they may still need to meet registration requirements and demonstrate compliance with applicable security and data protection obligations.
For organizations in sectors such as government or science and research, understanding when certification applies is an important early step in any eIDAS 2.0 readiness program. You can explore relevant resources to get a clearer picture of how the regulation applies to your specific context.
How should organizations prepare for a conformity assessment?
Organizations preparing for a conformity assessment under eIDAS 2.0 should start with a gap analysis, build a comprehensive documentation framework, and align their technical infrastructure with the applicable implementing regulations and harmonized standards. Early preparation significantly reduces the time and cost of the assessment itself.
A practical preparation approach involves several key steps. First, identify the exact scope of the assessment by determining which services or components will be assessed and which implementing regulations apply. The eIDAS 2.0 framework includes a large number of Commission Implementing Regulations covering everything from key management and certificate formats to incident reporting and audit trails. Knowing which ones apply to your service is essential before any audit work begins.
Second, build and maintain a robust evidence library. Certification bodies will request documented policies, procedures, technical specifications, and operational records. Organizations that manage their documentation proactively, rather than assembling it under pressure before an audit, tend to have smoother assessment experiences.
Third, conduct internal pre-assessments or readiness reviews before engaging the certification body. This helps identify gaps early and gives teams time to implement remediation without the pressure of an active audit. Many organizations work with external advisors at this stage to get an independent view of their readiness.
Finally, ensure that key personnel across IT, compliance, legal, and operations are aligned on the assessment scope and their individual responsibilities. A conformity assessment touches multiple parts of an organization, and coordination across teams is often what determines whether the process runs smoothly or runs into delays.
How TrustTech helps with eIDAS 2.0 certification readiness
Preparing for a conformity assessment under eIDAS 2.0 is a significant undertaking, especially for organizations that are navigating the regulation for the first time or expanding their qualified trust services. TrustTech supports organizations across every stage of this process, combining deep regulatory knowledge with practical implementation expertise.
Working with TrustTech means you get structured support across the areas that matter most for certification readiness:
- Gap analysis and scoping: Identifying which implementing regulations apply to your services and where your current infrastructure falls short.
- Documentation and policy frameworks: Building the evidence library and governance documentation that certification bodies require.
- Technical implementation: Aligning your identity verification, cryptographic infrastructure, and data exchange processes with eIDAS 2.0 standards.
- Pre-assessment readiness reviews: Independent evaluation of your compliance posture before the formal audit begins.
- Ongoing compliance support: Helping you maintain qualified status through the 24-month reassessment cycle and as the regulatory landscape continues to evolve.
Whether you are a financial institution preparing for QTSP status, a government body involved in EUDI Wallet deployment, or an organization in any regulated sector building toward eIDAS 2.0 compliance, TrustTech provides the digital identity solutions and expertise to move from complexity to clarity. Ready to take the next step? Get in touch with TrustTech to discuss your certification readiness.