Back to glossary

eIDAS

eIDAS is the European Union regulatory framework for electronic identification and trust services used in electronic transactions.

Updated
eIDAS glossary signal map Prompt Answer Citation Signal

eIDAS is the European Union regulatory framework for electronic identification and trust services used in electronic transactions.

The framework began with Regulation (EU) No 910/2014 and was expanded by Regulation (EU) 2024/1183, which established the European Digital Identity Framework. The amendment is often called “eIDAS 2.0,” although it updates the existing regulation rather than replacing it with a completely separate system.

Together, these rules create common legal and technical foundations for electronic identification, electronic signatures, electronic seals, timestamps, registered delivery services, digital identity wallets, and related services across EU Member States.

Electronic identification and trust services serve different purposes

Electronic identification allows a person or organization to prove who they are when accessing a digital service. For example, a person might use a government-issued electronic identity to sign in to another Member State’s public services portal.

Trust services help establish evidence about an electronic transaction. They can support identity, document origin, integrity, timing, delivery, and preservation.

These concepts overlap, but they are not interchangeable:

  • Electronic identification helps establish who is accessing a service.
  • Signer authentication increases confidence that the person signing is the intended signer.
  • An electronic signature records a natural person’s act of signing.
  • An electronic seal helps show that data originated from a legal entity, such as a company.
  • Timestamps and registered delivery services provide evidence about when an event occurred or when data was sent and received.

Under eIDAS, a company normally uses an electronic seal in its own name. A person authorized to act for that company can use an electronic signature, but the signature alone does not prove that the person had authority to bind the company.

The three electronic signature levels under eIDAS

eIDAS recognizes three levels of electronic signature. Each higher level adds specific identity, security, and integrity requirements.

Level Core requirements Legal treatment
Electronic signature, commonly called simple or standard Electronic data is attached to or logically associated with other electronic data and is used by the signer to sign. Examples can include typing a name or selecting an agreement button when accompanied by signing intent. It cannot be denied legal effect or admissibility as evidence solely because it is electronic or is not qualified. Its evidentiary weight depends on the circumstances and applicable law.
Advanced electronic signature It must be uniquely linked to the signer, capable of identifying the signer, created using signature creation data under the signer’s control with a high level of confidence, and linked to the signed data so later changes are detectable. It provides stronger identity and integrity evidence, but it does not automatically receive the handwritten-signature equivalence reserved for qualified signatures.
Qualified electronic signature It is an advanced signature created using a qualified signature creation device and based on a qualified certificate issued by a qualified trust service provider. It has the equivalent legal effect of a handwritten signature throughout the EU and must be recognized across Member States.

A digital signature is a cryptographic technique, usually involving hashes, certificates, and public and private keys. It can help satisfy advanced or qualified signature requirements, but “digital signature” and “advanced electronic signature that is based on a qualified certificate for electronic signatures and created using a qualified">qualified electronic signature” are not synonyms. The eIDAS classification depends on the complete process, including identity verification, certificate status, control of signing keys, and the type of signature creation device.

Qualified trust services provide regulated assurance

A trust service becomes “qualified” only when it meets the regulation’s requirements, receives qualified status through the relevant national supervisory system, and appears with that status on an EU Member State’s trusted list. A signing platform does not become qualified merely by describing itself as secure or eIDAS compliant.

The eIDAS framework covers services involving:

  • Electronic signatures and electronic seals
  • Electronic timestamps
  • Electronic registered delivery
  • Certificates for website authentication
  • Validation and preservation of signatures and seals
  • Electronic attestations of attributes, such as professional qualifications
  • Electronic archiving
  • Electronic ledgers
  • Management of remote qualified signature and seal creation devices

For example, a qualified timestamp can support evidence that particular data existed at a particular time. A qualified electronic registered delivery service can provide regulated evidence about sending and receiving data. Neither service independently proves that every statement inside a document is true.

Cross-border recognition has defined limits

eIDAS reduces friction between national systems, but it does not create one central EU identity provider.

Member States must recognize qualifying notified electronic identification methods from other Member States when the regulation’s conditions apply. Qualified electronic signatures and qualified trust services also receive EU-wide recognition under the framework.

For example, a qualified signature based on a qualified certificate issued in one Member State should not lose its qualified status simply because the recipient is in another Member State. Trusted lists help systems confirm whether the provider and service held qualified status at the relevant time.

This does not mean every private website must accept every national electronic ID. Recognition and acceptance duties depend on the type of service, required assurance level, sector, and applicable eIDAS provisions.

The European Digital Identity framework in September 2026

The 2024 amendment expanded eIDAS around the European Digital Identity Wallet, often shortened to EUDI Wallet. Each Member State must make at least one certified wallet available under the common framework by the end of 2026.

A wallet is intended to let users identify themselves, authenticate to services, store and present identity data or electronic attestations, and create qualified electronic signatures. Qualified signing through the wallet must be available to natural persons free of charge for nonprofessional purposes.

As of September 2026, the amended legal framework is in force, but the wallet rollout is still approaching its end-of-2026 deadline. Availability and practical deployment can therefore differ between Member States. References to the EUDI Wallet should not imply that every resident or business already has access to a fully deployed wallet.

What eIDAS does not guarantee

eIDAS does not make every electronically signed document enforceable. It establishes legal effects, recognition rules, and requirements for identification and trust services, but other questions remain subject to EU law, national law, and the facts of the transaction.

It does not automatically establish:

  • That the signer understood or freely accepted the document
  • That the signer had legal capacity or organizational authority
  • That the agreement’s terms are lawful
  • That a required witness, notary, or special form was properly used
  • That the document will be accepted outside the EU
  • That a provider or workflow is qualified
  • That fraud, coercion, credential theft, or procedural errors are impossible

The appropriate signature level depends on the transaction, evidence required, sector rules, and relevant jurisdiction. For a broader discussion, see are electronic signatures legally binding?. This entry provides general educational information, not legal advice.

FAQ

Is eIDAS the same as eIDAS 2.0?

“eIDAS 2.0” is an informal name for the framework after Regulation (EU) 2024/1183 amended the original eIDAS Regulation. The updated framework includes European Digital Identity Wallets and additional trust services.

Does eIDAS require a qualified signature for every contract?

No. Many transactions may use standard or advanced electronic signatures. A qualified signature may be required by specific laws, authorities, or risk policies, but eIDAS does not impose it on every agreement.

Can a nonqualified electronic signature be valid?

Yes. An electronic signature cannot be denied legal effect or admissibility solely because it is electronic or nonqualified. Whether it satisfies a particular requirement depends on the applicable law and evidence.

Does eIDAS apply automatically outside the EU?

No. A qualified signature receives defined recognition across EU Member States. Its treatment in a non-EU country depends on that country’s laws, contractual arrangements, and any applicable international recognition framework.