10 References
10 References¶
10.1 Commission Regulations and Decisions¶
Several of the Commission Implementing Regulations listed below have since been amended by Commission Implementing Regulation (EU) 2026/1730, (EU) 2026/1731, and (EU) 2026/1735; the title of each amending act identifies the Implementing Regulation it amends. The references below point to the original acts and will be updated to the consolidated versions once these are available.
| Item Reference | Regulation name/details |
|---|---|
| CID 2015/1505 | Commission Implementing Decision (EU) 2015/1505 of 8 September 2015 laying down technical specifications and formats relating to trusted lists pursuant to Article 22(5) of Regulation (EU) No 910/2014 of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market. |
| Directive 2016/2102 | Directive (EU) 2016/2102 of the European Parliament and of the Council of 26 October 2016 on the accessibility of the websites and mobile applications of public sector bodies |
| Directive 2019/882 | Directive (EU) 2019/882 of the European Parliament and of the Council of 17 April 2019 on the accessibility requirements for products and services |
| European Digital Identity Regulation | Regulation (EU) 2024/1183 of the European Parliament and of the Council of 11 April 2024 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework |
| Risk Register | Commission Implementing Regulation (EU) 2024/2981, Annex I of 28 November 2024 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and the Council as regards the certification of European Digital Identity Wallets |
| CIR 2024/2977 | Commission Implementing Regulation (EU) 2024/2977 of 28 November 2024 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards person identification data and electronic attestations of attributes issued to European Digital Identity Wallets |
| CIR 2024/2979 | Commission Implementing Regulation (EU) 2024/2979 of 28 November 2024 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards the integrity and core functionalities of European Digital Identity Wallets |
| CIR 2024/2980 | Commission Implementing Regulation (EU) 2024/2980 of 28 November 2024 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards notifications to the Commission concerning the European Digital Identity Wallet ecosystem |
| CIR 2024/2981 | Commission Implementing Regulation (EU) 2024/2981 of 28 November 2024 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and the Council as regards the certification of European Digital Identity Wallets |
| CIR 2024/2982 | Commission Implementing Regulation (EU) 2024/2982 of 28 November 2024 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards protocols and interfaces to be supported by the European Digital Identity Wallet Framework |
| CIR 2025/846 | Commission Implementing Regulation (EU) 2025/846 of 6 May 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards cross-border identity matching of natural persons |
| CIR 2025/847 | Commission Implementing Regulation (EU) 2025/847 of 6 May 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards reactions to security breaches of European Digital Identity Wallets |
| CIR 2025/848 | Commission Implementing Regulation (EU) 2025/848 of 6 May 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards the registration of wallet-relying parties |
| CIR 2025/849 | Commission Implementing Regulation (EU) 2025/849 of 6 May 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards the submission of information to the Commission and to the Cooperation Group for the list of certified European Digital Identity Wallets |
| CIR 2025/1566 | Commission Implementing Regulation (EU) 2025/1566 of 29 July 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards reference standards for the verification of the identity and attributes of the person to whom the qualified certificate or the qualified electronic attestation of attributes is to be issued |
| CIR 2025/1567 | Commission Implementing Regulation (EU) 2025/1567 of 29 July 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards the management of remote qualified electronic signature creation devices and of remote qualified electronic seal creation devices as qualified trust services |
| CIR 2025/1568 | Commission Implementing Regulation (EU) 2025/1568 of 29 July 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards procedural arrangements for peer reviews of electronic identification schemes and for cooperation on the organisation of such reviews within the Cooperation Group and repealing Commission Implementing Decision (EU) 2015/296 |
| CIR 2025/1569 | Commission Implementing Regulation (EU) 2025/1569 of 29 July 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards qualified electronic attestations of attributes and electronic attestations of attributes provided by or on behalf of a public sector body responsible for an authentic source |
| CIR 2025/1570 | Commission Implementing Regulation (EU) 2025/1570 of 29 July 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards notification of information on certified qualified electronic signature creation devices and certified qualified electronic seal creation devices |
| CIR 2025/1571 | Commission Implementing Regulation (EU) 2025/1571 of 29 July 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards the formats and procedures for annual reports by supervisory bodies |
| CIR 2025/1572 | Commission Implementing Regulation (EU) 2025/1572 of 29 July 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards the format and procedures for notification of intention and verification with regard to the initiation of qualified trust services |
| CIR 2025/1929 | Commission Implementing Regulation (EU) 2025/1929 of 29 September 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards the binding of date and time to data and establishing the accuracy of the time sources for the provision of qualified electronic time stamps |
| CIR 2025/1942 | Commission Implementing Regulation (EU) 2025/1942 of 29 September 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards qualified validation services for qualified electronic signatures and qualified validation services for qualified electronic seals |
| CIR 2025/1943 | Commission Implementing Regulation (EU) 2025/1943 of 29 September 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards reference standards for qualified certificates for electronic signatures and qualified certificates for electronic seals |
| CIR 2025/1944 | Commission Implementing Regulation (EU) 2025/1944 of 29 September 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards reference standards for processes for sending and receiving data in qualified electronic registered delivery services and as regards interoperability of those services |
| CIR 2025/1945 | Commission Implementing Regulation (EU) 2025/1945 of 29 September 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards the validation of qualified electronic signatures and of qualified electronic seals and the validation of advanced electronic signatures based on qualified certificates and of advanced electronic seals based on qualified certificates |
| CIR 2025/1946 | Commission Implementing Regulation (EU) 2025/1946 of 29 September 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards qualified preservation services for qualified electronic signatures and for qualified electronic seals |
| CIR 2025/2160 | Commission Implementing Regulation (EU) 2025/2160 of 27 October 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards reference standards, specifications and procedures for the management of risks to the provision of non-qualified trust services |
| CIR 2025/2162 | Commission Implementing Regulation (EU) 2025/2162 of 27 October 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and the Council as regards the accreditation of conformity assessment bodies performing the assessment of qualified trust service providers and the qualified trust services they provide, the conformity assessment report and the conformity assessment scheme |
| CID 2025/2164 | Commission Implementing Decision (EU) 2025/2164 of 27 October 2025 amending Implementing Decision (EU) 2015/1505 as regards the version of the standard on which the common template for the trusted lists is based |
| CIR 2025/2527 | Commission Implementing Regulation (EU) 2025/2527 of 16 December 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards reference standards for qualified certificates for website authentication |
| CIR 2025/2530 | Commission Implementing Regulation (EU) 2025/2530 of 16 December 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards requirements for qualified trust service providers providing qualified trust services |
| CIR 2025/2531 | Commission Implementing Regulation (EU) 2025/2531 of 16 December 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards reference standards and specifications for qualified electronic ledgers |
| CIR 2025/2532 | Commission Implementing Regulation (EU) 2025/2532 of 16 December 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards reference standards and specifications for qualified electronic archiving services |
| CIR 2026/248 | Commission Implementing Regulation (EU) 2026/248 of 2 February 2026 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards the formats of advanced electronic signatures and advanced electronic seals recognised by public sector bodies |
| CIR 2026/798 | Commission Implementing Regulation (EU) 2026/798 of 7 April 2026 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards reference standards and specifications for the remote onboarding of users to the European Digital Identity Wallet |
10.2 International and European standards and technical specifications¶
Note: All standards and technical specifications listed in this section are undated. A link is added to the entry for the respective document on the Standards and Technical Specifications Roadmap, which contains the latest information regarding the targeted version.
| Item Reference | Standard name/details |
|---|---|
| ISO/IEC 18013-5 | ISO/IEC 18013-5, Personal identification - ISO-compliant driving licence - Part 5: Mobile driving licence (mDL) application |
| ISO/IEC 18013-7 | ISO/IEC 18013-7, Personal identification - ISO-compliant driving licence - Part 7: Mobile driving licence (mDL) add-on functions |
| ISO/IEC 23220-2 | ISO/IEC 23220-2, - Cards and security devices for personal identification — Building blocks for identity management via mobile devices - Part 2: Data objects and encoding rules for generic eID systems |
| ISO 3166-1 | ISO 3166-1: Codes for the representation of names of countries and their subdivisions - Part 1: Country codes: alpha-2 country |
| ISO 3166-2 | ISO 3166-2: Codes for the representation of names of countries and their subdivisions - Part 2: Country subdivision code |
| ISO/IEC 5218 | ISO/IEC 5218 Codes for the representation of human sexes |
| ISO/IEC 19794-5 | ISO/IEC 19794-5 Biometric data interchange formats — Part 5: Face image data |
| ISO/IEC 39794-5 | ISO/IEC 39794-5 Extensible biometric data interchange formats — Part 5: Face image data |
| ETSI TS 119 101 | ETSI TS 119 101 - Electronic Signatures and Infrastructures (ESI); Policy and security requirements for applications for signature creation and signature validation |
| ETSI TS 119 602 | ETSI TS 119 602: Electronic Signatures and Infrastructures (ESI); Lists of trusted entities; Data model |
| ETSI TS 119 612 | ETSI TS 119 612: Electronic Signatures and Infrastructures (ESI); Trusted Lists |
| ETSI EN 319 411-1 | ETSI EN 319 411-1 - Electronic Signatures and Infrastructures (ESI); Policy and security requirements for Trust Service Providers issuing certificates; Part 1: General requirements |
| ETSI EN 319 411-2 | ETSI EN 319 411-2 - Electronic Signatures and Infrastructures (ESI); Policy and security requirements for Trust Service Providers issuing certificates; Part 2: Requirements for trust service providers issuing EU qualified certificates |
| ETSI TS 119 411-8 | ETSI TS 119 411-8 - Electronic Signatures and Trust Infrastructures (ESI); Policy and security requirements for Trust Service Providers issuing certificates; Part 8: Access Certificate Policy for EUDI Wallet Relying Parties |
| ETSI TS 119 412-6 | ETSI TS 119 412-6 - Electronic Signatures and Trust Infrastructures (ESI); Certificate Profiles; Part 6: Certificate profile requirements for PID, Wallet, EAA, QEAA, and PSBEAA providers |
| ETSI TS 119 431-1 | ETSI TS 119 431-1 - Electronic Signatures and Infrastructures (ESI); Policy and security requirements for trust service providers; Part 1: TSP service components operating a remote QSCD / SCDev. |
| ETSI TS 119 431-2 | ETSI TS 119 431-2 - Electronic Signatures and Infrastructures (ESI); Policy and security requirements for trust service providers; Part 2: TSP service components supporting AdES digital signature creation |
| ETSI TS 119 432 | ETSI TS 119 432 - Electronic Signatures and Infrastructures (ESI); Protocols for remote digital signature creation |
| ETSI TS 119 471 | ETSI TS 119 471 - Electronic Signatures and Trust Infrastructures (ESI); Policy and Security requirements for Providers of Electronic Attestation of Attribute Services |
| ETSI TS 119 472-1 | ETSI TS 119 472-1 - Electronic Signatures and Trust Infrastructures (ESI); Profiles for Electronic Attestations of Attributes; Part 1: General requirements |
| ETSI TS 119 472-2 | ETSI TS 119 472-2 - Electronic Signatures and Trust Infrastructures (ESI); Profiles for Electronic Attestation of Attributes; Part 2: Profiles for EAA/PID Presentations to Relying Party |
| ETSI TS 119 472-3 | ETSI TS 119 472-3 - Electronic Signatures and Trust Infrastructures (ESI); Profiles for Electronic Attestation of Attributes; Part 3: Profiles for issuance of EAA or PID |
| ETSI TS 119 475 | ETSI TS 119 475 - Electronic Signatures and Trust Infrastructures (ESI); Relying party attributes supporting EUDI Wallet user's authorisation decisions |
| ETSI TS 119 478 | ETSI TS 119 478 - Electronic Signatures and Trust Infrastructures (ESI); Specification of interfaces related to Authentic Sources |
| ETSI EN 301 549 | ETSI EN 301 549 - Accessibility requirements for ICT products and services |
| ETSI EN 319 132-1 | ETSI EN 319 132-1 - Electronic Signatures and Infrastructures (ESI); XAdES digital signatures; Part 1: Building blocks and XAdES baseline signatures (XAdES) |
| ETSI TS 119 182-1 | ETSI TS 119 182-1 - Electronic Signatures and Infrastructures (ESI); JAdES digital signatures; Part 1: Building blocks and JAdES baseline signatures |
| ETSI EN 319 122-1 | ETSI EN 319 122-1 - Electronic Signatures and Infrastructures (ESI); CAdES digital signatures; Part 1: Building blocks and CAdES baseline signatures |
| ETSI EN 319 162-1 | ETSI EN 319 162-1 - Electronic Signatures and Infrastructures (ESI); Associated Signature Containers (ASiC); Part 1: Building blocks and ASiC baseline containers |
| ETSI EN 319 162-2 | ETSI EN 319 162-2 - Electronic Signatures and Infrastructures (ESI); Associated Signature Containers (ASiC); Part 2: Additional ASiC container types |
| PSD2 | Directive (EU) 2015/2366 of the European Parliament and of the Council on payment services in the internal market (PSD2) |
| ETSI EN 319 142-1 | ETSI EN 319 142-1 - Electronic Signatures and Infrastructures (ESI); PAdES digital signatures; Part 1: Building blocks and PAdES baseline signatures |
| ECCG Agreed Cryptographic Mechanisms v2.0 | ECCG Agreed Cryptographic Mechanisms v2.0 |
| CEN EN 419 241-1 | CEN EN 419 241-1 - Trustworthy Systems Supporting Server Signing - Part 1: General System Security Requirements |
| SD-JWT VC | SD-JWT-based Verifiable Credentials (SD-JWT VC). |
| RFC 2119 | RFC 2119 - Key words for use in RFCs to Indicate Requirement Levels |
| RFC 3339 | RFC 3339 - Date and Time on the Internet: Timestamps |
| RFC 9562 | RFC 9562 - Universally Unique IDentifiers (UUIDs) |
| RFC 5280 | RFC 5280 - Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile |
| RFC 5322 | RFC 5322 - Internet Message Format |
| RFC 3647 | RFC 3647 - Internet X.509 Public Key Infrastructure Certificate Policy and Certification Practices Framework |
| RFC 7519 | RFC 7519 - JSON Web Token (JWT) |
| RFC 8259 | RFC 8259 - The JavaScript Object Notation (JSON) Data Interchange Format |
| RFC 8392 | RFC 8392 - CBOR Web Token (CWT) |
| RFC 8610 | RFC 8610 - Concise Data Definition Language (CDDL): A Notational Convention to Express Concise Binary Object Representation (CBOR) and JSON Data Structures |
| RFC 8943 | RFC 8943 - Concise Binary Object Representation (CBOR) Tags for Date |
| RFC 8949 | RFC 8949 - Concise Binary Object Representation (CBOR) |
| Token Status List | Token Status List - Token Status List (TSL) |
| CSC API | Cloud Signature Consortium API Specification v2.0 |
| GP OMAPI | GPD_SPE_075 Open Mobile API Specification, GlobalPlatform |
| GP CS | GPC_SPE_034 Card Specification, GlobalPlatform |
| GSMA SAM | GSMA Secured Applications for Mobile, GSM Association |
| W3C VCDM v2.0 | Sporny, M. et al, Verifiable Credentials Data Model v2.0, W3C Recommendation |
| W3C VC-JOSE-COSE | Jones, M. et al, Securing Verifiable Credentials using JOSE and COSE, W3C Recommendation |
| W3C VC Data Integrity | Sporny, M. et al, Verifiable Credential Data Integrity 1.0, W3C Recommendation |
| W3C Digital Credentials API | Caceres, M., Cappalli, T., Goto, S. et al, W3C Digital Credentials API, Draft Community Group Report |
| W3C WebAuthn | Jeff Hodges et al, Web Authentication, An API for accessing Public Key Credentials Level 2, W3C Recommendation |
| CTAP | John Bradley et al,Client to Authenticator Protocol (CTAP), FIDO Alliance |
| OpenID4VCI | Lodderstedt, T. et al., OpenID for Verifiable Credential Issuance, OpenID Foundation. |
| OpenID4VP | Terbu, O. et al., OpenID Connect for Verifiable Presentations, OpenID Foundation. |
| OIDC | Sakimura, N. et al., OpenID Connect Core 1.0, OpenID Foundation. |
| EKYC | Lodderstedt, T. et al., OpenID Connect for Identity Assurance Claims Registration 1.0, OpenID Foundation. |
| EKYC Schema | Lodderstedt, T. et al., OpenID Identity Assurance Schema Definition 1.0, OpenID Foundation. |
| HAIP | Yasuda, K. et al, OpenID4VC High Assurance Interoperability Profile, OpenId Foundation. |
| IANA-JWT-Claims | IANA JSON Web Token Claims Registry |
| FCAF | Functional Conformance Assessment Framework, governed by the European Commission in cooperation with the Member States through the EDICG |
10.3 Topics from Annex 2¶
Note: All topics listed in this section are undated. The ARF main document and Annex 2 are always updated in combination. A link is added to the respective Topic in the latest version of Annex 2.
| Item Reference | Standard name/details |
|---|---|
| [Topic 4] | Annex 2 - mDL Rulebook |
| [Topic 6] | Annex 2 - Relying Party authentication and User approval |
| [Topic 7] | Annex 2 - Attestation revocation and revocation checking |
| [Topic 9] | Annex 2 - Key Attestation and Wallet Instance Attestation |
| [Topic 10] | Annex 2 - Issuing a PID or attestation to a Wallet Unit |
| [Topic 11] | Annex 2 - Pseudonyms |
| [Topic 12] | Annex 2 - Attestation Rulebooks |
| [Topic 16] | Annex 2 - Signing documents with a Wallet Unit |
| [Topic 18] | Annex 2 - Combined presentations of attributes |
| [Topic 19] | Annex 2 - User Navigation requirements (Dashboard logs for transparency) |
| [Topic 20] | Annex 2 - Strong User authentication for electronic payments |
| [Topic 24] | Annex 2 - User identification in proximity scenarios |
| [Topic 25] | Annex 2 - Unified definition and controlled vocabularies for attributes |
| [Topic 27] | Annex 2 - Registration of PID Providers, Providers of QEAAs, PuB-EAAs, and (non-qualified) EAAs, and Relying Parties |
| [Topic 29] | Annex 2 - Representation paradigm |
| [Topic 30] | Annex 2 - Interaction between Wallet Units |
| [Topic 31] | Annex 2 - PID Provider, Wallet Provider, Attestation Provider, Access Certificate Authority, and Provider of registration certificates notification and publication |
| [Topic 34] | Annex 2 - Migrate to a different Wallet solution |
| [Topic 38] | Annex 2 - Wallet Unit revocation |
| [Topic 40] | Annex 2 - Wallet Instance installation and Wallet Unit activation and management |
| [Topic 42] | Annex 2 - Requirements for QTSPs to access Authentic Sources |
| [Topic 43] | Annex 2 - Embedded disclosure policies |
| [Topic 44] | Annex 2 - Relying Party registration certificates |
| [Topic 48] | Annex 2 - Blueprint for requesting data deletion to Relying Parties |
| [Topic 50] | Annex 2 - Blueprint to report unlawful or suspicious request of data |
| [Topic 51] | Annex 2 - PID or attestation deletion |
| [Topic 52] | Annex 2 - Relying Party intermediaries |
| [Topic 53] | Annex 2 - Zero-Knowledge Proofs |
| [Topic 54] | Annex 2 - Accessibility |
| [Topic 55] | Annex 2 - Certificate Transparency |
| [Topic 56] | Annex 2 - Wallet Provider Support and Maintenance |
10.4 Technical Specifications published by the Commission¶
Note: All Technical Specifications listed in this section are undated. A link is added to the latest version of the respective Technical Specification, published by the Commission.
| Item Reference | Technical Specification name/details |
|---|---|
| Technical Specification 1 | Specification of EUDI Wallet Trust Mark |
| Technical Specification 2 | Specification of systems enabling the notification and subsequent publication of Provider information |
| Technical Specification 3 | Specification of Wallet Unit Attestations (WUA) used in issuance of PID and Attestations |
| Technical Specification 4 | Specification of Zero-Knowledge Proof (ZKP) Implementation in EUDI Wallet |
| Technical Specification 5 | Specification of common formats and API for Relying Party Registration information |
| Technical Specification 6 | Common Set of Relying Party Information to be Registered |
| Technical Specification 7 | Specification of Common Interface for Data Deletion Requests to Relying Parties |
| Technical Specification 8 | Specification of Common Interface for reporting of Relying Parties to Data Protection Authorities |
| Technical Specification 9 | Specification of Wallet to Wallet interactions |
| Technical Specification 10 | Data Portability and Download (Export) |
| Technical Specification 11 | Specification of interfaces and formats for the catalogue of attributes and the catalogue of attestations |
| Technical Specification 12 | Specification of Strong Customer Authentication (SCA) Implementation with the Wallet |
| Technical Specification 13 | Specification for the implementation of Zero-Knowledge Proofs based on arithmetic circuits in the EUDI Wallet |
| Technical Specification 14 | Specification for the implementation of Zero-Knowledge Proofs based on multi-message signatures in the EUDI Wallet |