EUDI i Wallet Playground: bezpłatne testowanie rzeczywistych procesów obsługi portfela w przeglądarce. Wypróbuj teraz
Jarek Sygitowicz
Jarek Sygitowicz

EUDI Wallet & eIDAS 2.0 Glossary | Assurance levels and signatures (pt. 4)

Last updated: 25 September 2026

EUDI basics, made simple. What gives a credential its legal weight, in 3 minutes.

Authologic's glossary of assurance and signatures defines what gives an identity credential or a signed document its legal weight under eIDAS 2.0: the assurance levels low, substantial and high, electronic seals and qualified timestamps, and the signature tiers SES, AES and QES. Assurance levels grade how reliably a person was identified. Signature tiers grade what a signed document proves.

Every term from every glossary is indexed in the Digital Identity Glossary.

Each entry starts with a plain-language definition and adds the practical and legal detail underneath.

Who does what in the ecosystem (pt. 1) covered the demand side. Who issues, who provides, who guarantees (pt. 2) covered the supply side. What is inside the wallet (pt. 3) covered the contents.

Part 4 covers the vocabulary those three parts kept borrowing without defining. It works on two separate scales, and treating them as one is the most common error in wallet projects.

Written by Jarek Sygitowicz (Co-founder), Authologic.

EUDI Wallet and eIDAS 2.0 Glossary part 4 title card with a map of Europe

What is a level of assurance (LoA) under eIDAS?

A grade attached to an electronic identification means, stating how much confidence a relying party can place in the identity behind it. There are three: low, substantial and high.

In practice: A notified electronic identification scheme states which level its means meet. Low gives limited confidence. Substantial gives substantial confidence, with controls that reduce the risk of identity misuse. High goes further, with controls aimed at preventing that misuse. The technical requirements behind each level, from identity proofing to authentication, are set in a separate implementing act.

Two properties are easy to miss. A level attaches to the means and the scheme behind it, not to a single transaction or a vendor's product. And recognition is conditional. Where a public body requires electronic identification for an online service at substantial or high, it must accept a means issued in another Member State at the same level or above, provided the scheme appears on the Commission's published list, and within twelve months of that listing. Means at level low may be recognised, but no Member State has to.

Related: The EUDI Wallet is an electronic identification means at assurance level high. An implementing act adopted in April 2026 sets out how a user can be onboarded to a wallet with a means at level substantial combined with additional remote procedures that together meet level high.

Authologic works as trust infrastructure here: it routes each user to the best method available at the level the applicable rule requires, so one integration covers markets whose methods sit at different levels.

Who this applies to: Any relying party whose obligation names a level rather than a product, which includes every obliged entity under anti-money laundering rules.

Legal basis: Regulation (EU) No 910/2014 (eIDAS), Article 8 (assurance levels) and Article 6 (mutual recognition), as amended by Regulation (EU) 2024/1183; technical specifications in Commission Implementing Regulation (EU) 2015/1502; wallet assurance level in Article 5a(11); remote onboarding in Commission Implementing Regulation (EU) 2026/798.

What is an electronic seal?

The organisation's equivalent of a signature. Data attached to other data to show where it came from and that it has not been altered. A person signs; a company seals.

In practice: An electronic seal is created by a legal person, a signature by a natural person. That is why seals form a separate family with their own three tiers - electronic seal, advanced electronic seal and qualified electronic seal - which follow the same logic as the signature tiers defined further down.

A qualified electronic seal does not carry the legal effect of a handwritten signature, because organisations do not have handwriting. It benefits from the presumption of data integrity and correctness of origin: the data has not been altered, and it comes from the organisation named.

This is the mechanism underneath What is inside the wallet (pt. 3). An issuer seals a credential when it issues it, and the seal lets a relying party confirm months later that the data came from that issuer and has not changed, without contacting the issuer. Authologic checks that cryptographic proof for the relying party and returns the result in one format across methods.

Who this applies to: Every organisation issuing data that others rely on, and every relying party that needs to prove origin and integrity.

Legal basis: Regulation (EU) No 910/2014 (eIDAS), Article 3(24) to (27) (definitions), Article 35 (legal effects) and Article 24a(1) (recognition), as amended by Regulation (EU) 2024/1183.

What is a qualified electronic timestamp?

Proof, issued by a qualified provider, that given data existed at a given moment. It answers "when", which no seal or signature answers on its own.

In practice: No electronic timestamp can be refused as evidence merely for being electronic. Only a qualified one carries a presumption: that the date and time are accurate and that the data bound to them has not changed. It is recognised in every Member State.

For regulated onboarding its value is evidential. A seal or a signature shows that data is genuine. It does not show when a check was run. That question comes years later, from an auditor or a court, and the timestamp is what answers it.

Related: What counts as evidence of customer due diligence is covered in How Will the EUDI Wallet Change KYC?

Who this applies to: Compliance and audit teams who have to reconstruct what was checked, and when.

Legal basis: Regulation (EU) No 910/2014 (eIDAS), Article 3(33) and (34) (definitions), Article 41 (legal effect), Article 42 (requirements) and Article 24a(6) (recognition), as amended by Regulation (EU) 2024/1183.

What is an electronic signature (SES)?

Any data in electronic form that a person uses to sign. A typed name, a drawn squiggle, a click on a button.

In practice: The definition sets no security requirement. The regulation guarantees one thing only: an electronic signature cannot be refused legal effect or as evidence merely because it is electronic. That protects against automatic rejection. It is not a presumption, and what the signature proves is decided under national law, case by case.

"SES", or "simple electronic signature", is market shorthand. The regulation simply says "electronic signature".

Who this applies to: Anyone treating click-to-accept flows as proof of consent.

Legal basis: Regulation (EU) No 910/2014 (eIDAS), Article 3(10) (definition) and Article 25(1) (legal effects), as amended by Regulation (EU) 2024/1183.

What is an advanced electronic signature (AES)?

An electronic signature uniquely linked to the signatory, capable of identifying them, created with data under their sole control, and linked to the signed data so that any later change shows.

In practice: "Advanced" describes how the signature was made, not who vouched for the signatory. It carries no presumption and does not equal a handwritten signature. What it is worth depends on the certificate and the provider behind it - the two tiers of provider are defined in Who issues, who provides, who guarantees (pt. 2).

Who this applies to: Teams told to "use an advanced signature" without being told which certificate and provider stand behind it.

Legal basis: Regulation (EU) No 910/2014 (eIDAS), Article 3(11) (definition) and Article 26 (requirements), as amended by Regulation (EU) 2024/1183.

What is a qualified electronic signature (QES)?

An advanced electronic signature created by a qualified signature creation device (QSCD) and based on a qualified certificate. The only electronic signature with the legal effect of a handwritten one.

In practice: All three conditions must hold at once: an advanced signature, a qualified device and a qualified certificate. The device can now be remote, managed by a qualified trust service provider on the signatory's behalf, which is what makes qualified signing from a phone, and from a wallet, possible.

Recognition across Member States now sits in Article 24a, added by Regulation (EU) 2024/1183 in place of the former Article 25(3). The rule itself did not change: a qualified signature from one Member State is recognised in all others.

The EUDI Wallet must let every natural person sign with a qualified electronic signature by default and free of charge. Member States may limit free use to non-professional purposes, through proportionate measures.

Authologic operates as a non-qualified trust service provider issuing electronic attestations of attributes, registered with the Polish supervisory authority. Qualified signatures come from qualified providers on national trusted lists.

Who this applies to: Anyone whose process needs a document to hold up the way a paper original would.

Legal basis: Regulation (EU) No 910/2014 (eIDAS), Article 3(12) and (23a) (definitions), Article 25(2) (legal effect), Article 24a(1) (recognition), Article 29a (remote devices) and Article 5a(5)(g) (signing in the wallet), as amended by Regulation (EU) 2024/1183.

What is the difference between assurance levels and signature tiers?

Two separate scales that are often treated as one. Assurance levels grade an identification means. Signature tiers grade a signature. Neither implies the other.

In practice:

Question

Assurance level: low, substantial, high

Signature tier: electronic, advanced, qualified

What is graded

An electronic identification means and the scheme behind it

A signature applied to data

What it answers

How reliably was this person identified

What does this signed document prove

Where it is set

Article 8 and Implementing Regulation (EU) 2015/1502

Articles 3, 25 and 26

Top of the scale gives

Cross-border recognition for public services at substantial or high

Legal effect equal to a handwritten signature

A user identified at level high can still produce a plain electronic signature with no presumption attached. A user identified at level substantial can sign with a qualified signature that does equal a handwritten one. High assurance does not produce a qualified signature, and a qualified signature does not show how the person was identified.

Anti-money laundering rules turn on the first scale. Article 22(6) of the anti-money laundering regulation recognises two routes to verifying identity: identity documents together with information from reliable and independent sources, or electronic identification means at assurance level substantial or high together with relevant qualified trust services. The EUDI Wallet is one such means, not a separate route. The rules apply from 10 July 2027.

Who this applies to: Anyone writing a requirement. A requirement that names a level and one that names a signature tier are met by different products.

Legal basis: Regulation (EU) No 910/2014 (eIDAS), Articles 8, 25 and 26, as amended by Regulation (EU) 2024/1183; Regulation (EU) 2024/1624 (AMLR), Article 22(6).

Diagram of the EUDI Wallet and eIDAS 2.0 glossary series: a frame holding parts one to four, with assurance levels and signatures running across the top, then supply side, wallet contents and demand side, and the identity orchestration glossary below the frame, outside the series

The series so far.

How do assurance levels and signatures fit together?

A user is identified by an electronic identification means, and the scheme behind it carries an assurance level: low, substantial or high. The EUDI Wallet sits at level high.

The data about that user carries its own weight. An issuer's electronic seal proves where it came from and that it is intact, and a qualified electronic timestamp proves when it existed. A person who signs adds a signature tier - electronic, advanced or qualified - and only the qualified one equals a handwritten signature.

The roles behind all of this are in Who does what in the ecosystem (pt. 1), Who issues, who provides, who guarantees (pt. 2) and What is inside the wallet (pt. 3).

Part 5 will cover the machinery that makes all of this checkable in practice: certification, conformity assessment, trusted lists and cross-border recognition.

For the vocabulary underneath all four parts - orchestration, routing, fallback and method coverage - see the Identity Orchestration Glossary. It sits outside the EUDI series because it applies wherever more than one verification method is in play, wallet or no wallet.

Authologic is trust infrastructure for regulated businesses. It orchestrates three generations of identity - document checks, national eIDs and wallets - through one integration, and routes each user to a method at the level the local rule requires.

To test your own position, see the EUDI Wallet Readiness Checklist and Are you ready for July 2027? A 32-question SCA & AMLR readiness checklist.

Every term from every glossary, with the layer it belongs to, is indexed in the Digital Identity Glossary.

Changelog

  • 25 September 2026 - Initial publication (7 entries).

Udostępnij artykuł

Tekst tego artykułu
Multimedia do tego artykułu

Kontakt dla mediów