Who is eIDAS v2 Certification for Qualified Electronic Attestation of Attributes Aimed At?
This new qualified trust service is designed for a broad ecosystem of both public and private stakeholders who are responsible for guaranteeing these attributes or acting as providers of trusted data:
- Public Administrations and State Services: Ministries, regional authorities, or agencies managing authentic sources of data (civil registries, driving licenses, professional cards).
- Educational Institutions and Universities: For issuing certified diplomas and student statuses that are natively verifiable across Europe.
- Professional Bodies and Federations: Medical associations, bar associations, accountants' councils, or chambers of commerce for issuing representation mandates (such as official company registry extracts).
- Private Companies and Software Vendors: Banks, insurance companies, or technology trust service providers wishing to operate interoperable digital identity infrastructures.
.
What are the challenges of certification for issuers?
For Trust Service Providers (TSPs), obtaining eIDAS v2 qualified certification presents three strategic challenges:
- Automatic Legal Validity: In accordance with the European eIDAS v2 Regulation, a qualified electronic attribute attestation has absolute legal validity and cannot be rejected solely on the basis of its electronic format. It provides uniform legal assurance across all 27 EU countries.
- Native interoperability with the EUDI Wallet: QEAA are the fuel of digital identity. The technical requirements ensure that a certified attestation can be integrated and shared across all member identity wallets, in accordance with Implementing Regulation (EU) 2024/2979.
- Privacy by Design: Unlike the transmission of an entire paper document, qualified electronic attestation solutions enable selective disclosure. The user can prove a single attribute (e.g., “being of legal age”) without revealing the rest of their personal data.
Regulatory Framework and Assessment Standards for Qualified Electronic Attestations of Attributes (QEAA)
An Electronic Attestation of Attributes is qualified when it is issued by a Qualified Trust Service Provider (QTSP) audited against a strict framework. The provider must verify the origin of the attribute, guarantee its authenticity, ensure its traceability, and maintain a robust cryptographic framework.
| Reference | Main Objective | Scope for Attestations of Attributes (QEAA) | ||
| ETSI EN 319 401 | General Requirements | Governance, organization, security, and internal control of the provider. | ||
| ETSI EN 319 412 (series) | Profiles and Formats | Structured modeling, certificate profiles, and data formats for qualified attributes. | ||
| ETSI TS 119 461 | Identity verification | Secure enrollment procedures and validation of the connection to authentic attribute sources. | ||
| CEN/TS 17489 (series) | Attribute Management | Lifecycle management, publication, revocation, and long-term validity of evidence. | ||
| Implementing Regulation (EU) 2025/1569 | Implementing Act (EU) | Legal rule mandating the technical and security requirements for issuing QEAAs.. |
Your Questions About the eIDAS Service: Qualified Electronic Certificate
-
What is a Qualified Electronic Attestation of Attributes (QEAA)?
A Qualified Electronic Attestation of Attributes (QEAA) is a document or dataset in electronic form that is officially linked to the identity of a natural or legal person. Issued by a Qualified Trust Service Provider (QTSP) audited in compliance with Implementing Regulation (EU) 2025/1569, it provides tamper-proof proof of specific characteristics (diploma, professional status, company identifier) extracted directly from official registries or authentic sources. -
What is the link between Attestations of Attributes and the EUDI Wallet (European Digital Identity Wallet)?
The European Digital Identity Wallet (EUDI Wallet) serves as the secure mobile container on the citizen's smartphone, while the Qualified Electronic Attestations of Attributes (QEAA) represent its verifiable content. The EUDI Wallet relies on Implementing Regulation (EU) 2024/2982 to store these certified attributes and allow users to selectively share them with administrations or third parties across the European Union. -
What types of attributes or use cases are covered by this qualified service?
The scope of qualified electronic attestation of attributes issuance services covers numerous use cases: the issuance of corporate mandates or representation powers for a company (company registry extracts), professional titles and credentials (doctors, lawyers), instantaneous validation of university diplomas, as well as the cross-border digitization of driving licenses, insurance certificates, or social security entitlements. -
What is the difference between a qualified electronic attestation of attributes (QEAA) and a standard attestation?
The major difference lies in the level of legal certainty. To deliver qualified attestations, the provider must successfully pass an eIDAS v2 conformity assessment audit conducted by an accredited third-party body such as LSTI. Unlike standard attestations, only qualified attestations benefit from automatic legal validity and automatic cross-border recognition before courts and administrations in all 27 EU Member States. -
How does LSTI intervene in the qualification process?
LSTI acts exclusively as an accredited Conformity Assessment Body (CAB). LSTI's auditors examine the logical infrastructure, the cryptographic security of the issuance keys, and the compliance of practices. At the conclusion of the audit, LSTI issues a certificate and a Conformity Assessment Report (CAR), which serves as factual proof for the national supervisory body (ANSSI in France) to grant the official qualification of the service.
Why Choose LSTI?

Recognized expertise
With more than twenty years of experience, LSTI supports more than 300 organizations in France and across Europe as a certification body and leading assessment center, operating in the fields of cybersecurity, digital trust, and information security.

Specialized Auditors
Our audit teams are composed of experienced professionals who are well-versed in ANSSI’s cybersecurity standards, information security management practices, and European digital trust frameworks. Their approach ensures rigorous, balanced assessments that are tailored to each organization’s operational context.

Independent Third Party and Dedicated Support
Accredited by ANSSI, LSTI ensures impartiality, transparency, and consistency throughout the entire process: preparation, audits, monitoring, and renewals. A dedicated point of contact ensures continuity and clarity throughout the certification process.




