Glossary
Digital identity is full of acronyms and specialist terms. This glossary explains them one by one.
View
161 terms found
A
AA professional certificate
An AA professional certificate is a qualified certificate that states a verified Accountant-Administratieconsulent (AA) title for signing.
Access management
Access management is deciding and enforcing who may do what: after authentication establishes who you are, authorisation determines what you can reach.
Accountantsregister
The Dutch NBA register in which every AA or RA accountant must be enrolled before using that protected professional title.
AdES signature formats
AdES formats - PAdES, XAdES, CAdES, JAdES - are the ETSI standards defining how signatures are embedded in PDF, XML, CMS and JSON data.
Advanced electronic signature (AdES)
An advanced electronic signature (AdES) meets all four Article 26 eIDAS criteria: unique link, identification, sole control and tamper detection.
AES
AES (Advanced Encryption Standard) is the symmetric-key block cipher used worldwide to encrypt stored data and internet traffic.
Architecture and Reference Framework (ARF)
The Architecture and Reference Framework (ARF) is the EU's technical blueprint for the EUDI Wallet: formats, protocols, roles and certification.
ASiC
ASiC bundles a document with its electronic signature or seal in a ZIP-based container, used when the document format cannot hold one itself.
Association certificate
An association certificate is a qualified certificate that identifies an electronic seal as belonging to an association, not a company.
Attestation provider
Attestation provider: the EUDI Wallet role that issues a digital attestation - diploma, licence, mandate - to a wallet, in eIDAS and the ARF.
Attestation rulebook
The specification of one attestation type: attributes, namespaces, encoding, validity and verification rules. What makes wallet credentials interoperable.
Authentic source
An authentic source is the legally authoritative register - such as the BRP - that EUDI Wallet attestations verify attributes against under eIDAS 2.
B
BAC
BAC (Basic Access Control) lets a passport chip check the reader is authorised before releasing data. Used in eMRTDs, now being replaced by PACE.
Basisregistratie Personen (BRP)
The Dutch population register: municipalities and the non-residents register, who may receive data, and why it is the authentic source behind PID.
Biometric authentication
Biometric authentication verifies identity using a face, fingerprint or iris, checked with liveness detection to prevent spoofing during onboarding.
Biometric liveness detection
Biometric liveness detection confirms a face sample is from a living person, not a photo or spoof. Essential for remote identity verification.
Burgerservicenummer (BSN)
The unique Dutch personal number: who may use it under Article 46 UAVG, why it is an identifier and not proof, and what wallets carry instead.
C
CAdES
CAdES is the ETSI standard for advanced electronic signatures (AdES) using CMS/PKCS#7 binary data, used when content is not a PDF or XML file.
Certificate authority (CA)
A Certificate Authority issues digital certificates within a PKI, binding identities to public keys so browsers and systems can trust them.
Certificate chain
The path from a certificate through intermediates to a trust anchor, and what path validation checks at every link: signature, validity, usage, revocation.
Certificate revocation
Certificate revocation is how PKI marks a certificate untrusted before expiry, checked via CRL and OCSP after key compromise or data changes.
Certificate validity period
Every certificate carries a notBefore/notAfter window - typically one to three years for end-user certificates.
Cleverbase app
The Cleverbase app (formerly Vidua): one high-assurance digital identity to log in, share data and place qualified electronic signatures from your phone.
Cloud Signature Consortium API (CSC API)
The Cloud Signature Consortium (CSC) API is the open standard for remote signing integrations, used by QTSPs and EUDI Wallet signing flows.
Common Criteria (CC)
Common Criteria (ISO/IEC 15408): security certification of IT products against a protection profile, rated EAL1-7. Used for QSCDs and HSMs.
Company certificate
A company certificate names an organisation, not a person, as its holder - the basis for seals, secure websites and business logins.
Conformity assessment body (CAB)
A conformity assessment body (CAB) audits trust service providers against eIDAS and ETSI standards, and may certify EUDI Wallet solutions under eIDAS 2.0.
Conformity assessment report
A conformity assessment report is the audit evidence a CAB issues to prove a trust service provider still meets eIDAS requirements.
CP/CPS
CP and CPS are the public documents defining what a trust service provider promises about certificates and how it delivers on that promise.
CRL
CRL explained: the signed list a certificate authority publishes of revoked certificates, how it works, and how it differs from OCSP.
Cryptographic binding
Cryptographic binding mathematically links a signature, wallet key or authentication to one document, holder or origin, not just an assertion.
Cryptographic key generation
Key generation is creating a cryptographic key pair: a private key (the signature creation data) and the matching public key.
CSR
CSR explained: the self-signed request carrying a public key, sent to a CA to prove key possession before certificate issuance.
Cyberbeveiligingsbesluit
The Dutch decree under the Cyberbeveiligingswet: the duty of care worked out per measure, board training and what an incident report must contain.
Cyberbeveiligingswet (Cbw)
The Cyberbeveiligingswet (Cbw) is the Dutch law implementing NIS2, requiring organisations to manage cyber risk and report incidents.
Cybersecurity Act
The Cybersecurity Act (EU 2019/881) gives ENISA a permanent mandate and sets up the EU framework for certifying ICT products, services and processes.
D
DigiD
DigiD is the Dutch public eID for citizens, issued by Logius, used to log in to government services like the Belastingdienst and municipalities.
Document integrity
Document integrity is the guarantee that content has not changed since a reference moment - the property that turns a digital file into evidence.
DORA
DORA (Regulation 2022/2554) is the EU law on ICT risk, incident reporting and resilience testing for the financial sector, applying since 2025.
DTBS
DTBS is the data a signer intends to sign; DTBS/R is its usually hash-based representation processed by an HSM or QSCD when creating an e-signature.
Dual signature
A dual signature combines a personal electronic signature with an organisational seal on one document under eIDAS, covering intent and origin.
E
eHerkenning
eHerkenning is the Dutch eID scheme for organisations, letting employees log in to government and business services with a registered mandate.
eIDAS
eIDAS (EU Regulation 910/2014) governs electronic signatures, seals and eID across the EU; eIDAS 2 adds the EUDI Wallet and qualified signing.
Electronic attestation of attributes (EAA)
An electronic attestation of attributes (EAA/QEAA) is a signed digital statement - age, diploma, mandate - held in an EUDI Wallet under eIDAS 2.
Electronic identification (eID)
Electronic identification is using an electronic means to prove who you are online.
Electronic machine readable travel document (eMRTD)
The signed chip in a passport or ID card: passive authentication, chip authentication and PACE, and why reading it beats photographing a document.
Electronic registered delivery service (ERDS)
Electronic registered delivery (ERDS) is the trust service that proves sending, receipt and integrity online; QERDS adds legal presumptions under eIDAS.
Electronic seal
An electronic seal is data that organisations attach under eIDAS to prove origin and integrity; creating or validating it is the trust service.
Electronic signature
Under eIDAS, an electronic signature has three levels - simple, advanced (AES) and qualified (QES) - each with different legal effect and use case.
Elliptic curve cryptography (ECC)
Public-key cryptography on elliptic curves: ECDSA, EdDSA and ECDH, short keys, approved curves, and why wallets and smartcards rely on it.
ETSI
ETSI ESI standards define the technical requirements that make eIDAS-based electronic signatures, seals and trust services auditable for QTSPs.
EU Trusted List
The EU Trusted List is the official, machine-readable register of qualified trust service providers and their qualified services.
EUDI Wallet
The European Digital Identity Wallet is the wallet introduced by eIDAS 2. Every member state must offer at least one wallet to its citizens and residents.
European Business Wallet (EBW)
The European Business Wallet is a separate EU regulation proposed in November 2025 for organisations - not an EUDI Wallet issued to a company.
F
FIDO2
FIDO2 and passkeys offer phishing-resistant, passwordless authentication and MFA via a key pair cryptographically bound to the real website.
Foundation certificate
A qualified certificate that identifies the holder of an electronic seal as a foundation, not a company or association.
G
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR): the EU law on personal data - legal basis, minimisation, breach duties for identity and trust services.
H
Handelsregister
The Dutch Handelsregister lists every company doing business in the Netherlands, each with a unique KVK number and public record.
Hardware security module (HSM)
A Hardware Security Module (HSM) is certified, tamper-resistant hardware that protects cryptographic keys for eIDAS-qualified signing, seals and PKI.
Hash
A hash is a data fingerprint from a cryptographic function like SHA-256, used to bind electronic signatures and timestamps to exact content.
I
Identity federation
Identity federation lets users authenticate once and be trusted by other services, via protocols like SAML and OpenID Connect.
Identity provider (IdP)
An identity provider (IdP) authenticates users and vouches for their identity, enabling identity federation and single sign-on across trusted services.
Identity verification
Identity verification (identity proofing) confirms someone's identity with the required assurance before issuing a qualified certificate or wallet PID.
Incident reporting
QTSPs must report incidents fast: NIS2 (24h warning, RDI/NCSC), GDPR breach notification (72h) - eIDAS's own Article 19 duty was repealed in 2024.
Information security management system (ISMS)
The management system behind security: risk assessment, approved policy, owned measures and evidence. What eIDAS Article 24 and an audit expect.
J
JAdES
JAdES is the ETSI standard for embedding advanced electronic signatures in JSON data, built on JWS - used in APIs and digital wallets.
JOSE
JOSE is the IETF family of standards - JWS, JWE, JWK, JWA - for signing and encrypting data in JSON format.
JSON Web Algorithms (JWA)
JSON Web Algorithms (JWA), RFC 7518, names the cryptographic algorithms JWS and JWE use, such as RS256, ES256, HS256 and AES-GCM.
JSON Web Encryption (JWE)
JSON Web Encryption (JWE) is the IETF standard, RFC 7516, for encrypting a JSON payload so only the intended recipient can read it.
JSON Web Key (JWK)
A JSON Web Key (JWK) is a cryptographic key written as JSON text, used to sign and verify JWTs and other JOSE-based tokens.
JSON Web Signature (JWS)
JSON Web Signature (JWS) is the IETF standard (RFC 7515) for signing or authenticating data with JSON, underlying most JSON Web Tokens.
JSON Web Token (JWT)
JSON Web Token (JWT): a compact, signed way to carry claims like identity or session data between systems, defined in IETF RFC 7519.
K
Key ceremony
The scripted, witnessed procedure in which a CA creates or retires a root key inside an HSM, with split knowledge, dual control and an audited record.
L
Level of assurance (LoA)
eIDAS LoA (low, substantial, high) shows how certain a relying party can be that an eID belongs to its user, per EU Regulation 2015/1502.
Logius
The Dutch government organisation behind DigiD, eHerkenning and PKIoverheid: it manages the schemes while others issue the means and the RDI supervises.
Long-term validation (LTV)
Long-Term Validation (LTV) and Long-Term Archival (LTA) keep eIDAS electronic signatures and seals verifiable for decades using archive timestamps.
LTA
LTA is the ETSI baseline signature level that adds renewable archive timestamps to keep signatures verifiable for decades.
M
Management of remote signature and seal creation devices
How a QTSP generates, backs up and destroys the private keys behind remote signing and sealing, under eIDAS Annex II and CEN/ETSI standards.
Mandate
A mandate is legal authorisation to represent someone else - eHerkenning, DigiD Machtigen and EUDI Wallet attestations make it provable online.
mDL
mDL is a mobile driving licence on a smartphone, standardised under ISO/IEC 18013-5 and required by EU law to be issued for the EUDI Wallet.
mdoc
mdoc is the ISO 18013-5 credential format used in the EUDI Wallet, enabling selective disclosure and offline, in-person identity presentation.
N
NIS2
NIS2 (EU 2022/2555): EU cybersecurity directive for essential and important entities, with 24-hour incident reporting and management liability.
Non-repudiation
Non-repudiation means a signatory cannot credibly deny signing a document: the evidence from an electronic or digital signature binds the act to them.
Notified electronic identification scheme
An eID scheme a Member State notified to the Commission: what Article 9 requires, how peer review works and why public bodies abroad must accept it.
O
OAuth 2.0
OAuth 2.0 is the internet's standard framework for delegated authorisation, granting apps scoped, expiring access tokens instead of passwords.
OCSP
OCSP explained: the real-time protocol for checking certificate revocation status, how it differs from CRL, and what OCSP stapling does.
OpenID Connect (OIDC)
OpenID Connect is the identity layer on OAuth 2.0, providing the signed ID token behind "Log in with ..." buttons and enterprise SSO logins.
OpenID4VC
OpenID4VC covers OpenID4VCI (credential issuance) and OpenID4VP (credential presentation), the OAuth 2.0-based protocols behind the EUDI Wallet.
OpenID4VCI
OpenID4VCI is the OpenID protocol wallets use to request and receive digital credentials from an issuer, used in the EUDI Wallet.
OpenID4VP
OpenID4VP is the OpenID protocol that lets relying parties request and verify credentials from a digital wallet, such as the EUDI Wallet.
P
PACE
PACE is the protocol that opens a secure, encrypted channel with a passport or ID card chip before any data is read.
PAdES
PAdES (EN 319 142) is the ETSI standard for embedding electronic signatures and seals inside PDF documents, keeping the file self-contained.
Passkeys
Passkeys are passwordless, phishing-resistant FIDO2 login credentials synced across devices. Learn how they work and differ from security keys.
Person identification data (PID)
PID is the eIDAS 2 identity set (name, birth date, birth place, nationality) for the EUDI Wallet - which attributes are mandatory and who issues them.
PID provider
PID provider: the body a Member State designates to issue the core identity data loaded into an EUDI Wallet. Definition, role and examples.
PKIoverheid
PKIoverheid is the Dutch government PKI (Logius, PvE), used for Digikoppeling, DigiD authentication, and qualified digital signatures and seals.
Policy Authority PKIoverheid (PA)
The governance body behind PKIoverheid: it sets the rules for the Dutch government's PKI hierarchy and admits certificate providers.
Post-quantum cryptography (PQC)
Cryptography that survives quantum computers: ML-KEM, ML-DSA and SLH-DSA, why key exchange is urgent first, and what migration means for signatures.
Professional certificate
A professional certificate adds a verified professional title, such as notary or lawyer, to a qualified electronic signature or seal.
Programme of Requirements (PoR)
The Programme of Requirements (PoR) sets the binding rules every provider must follow to issue certificates in the Dutch PKIoverheid hierarchy.
PSD2
PSD2 is the EU directive (since 2018) requiring strong customer authentication (SCA) and opening banking APIs to licensed third parties.
Pseudonym
A stand-in name that keeps you accountable but not exposed: how eIDAS protects pseudonyms in wallets, logins and qualified certificates.
Public key infrastructure (PKI)
PKI is the system of asymmetric cryptography, certificates and certificate authorities (CAs) that makes digital trust scale.
Public sector electronic attestation of attributes (Pub-EAA)
Pub-EAA: attribute attestations issued by public sector bodies for the EUDI Wallet, with legal effects equal to a qualified EAA under eIDAS.
Q
Qualified certificate
A qualified certificate is the eIDAS PKI certificate underpinning a QES, giving electronic signatures and seals the highest level of legal assurance.
Qualified electronic archiving service
The eIDAS trust service that keeps documents readable and unaltered: qualified archiving gives a presumption of integrity and accurate origin.
Qualified electronic attestation of attributes (QEAA)
QEAA is the qualified electronic attestation of attributes under eIDAS: issued only by a QTSP, with the legal effect of a paper attestation.
Qualified electronic ledger
The eIDAS trust service for ordered records: a qualified ledger presumes unique chronological ordering and integrity, with no technology prescribed.
Qualified electronic registered delivery service (QERDS)
QERDS (qualified electronic registered delivery service) is the eIDAS-regulated delivery service with an EU-wide presumption of integrity and delivery.
Qualified electronic seal
A qualified electronic seal is an advanced electronic seal under eIDAS that gives EU-wide legal presumption of data integrity and origin for organisations.
Qualified electronic signature (QES)
A qualified electronic signature (QES) is the highest eIDAS signature level, legally equal to a handwritten signature EU-wide. Learn how it works.
Qualified electronic timestamp
A qualified electronic timestamp, issued by a QTSP under eIDAS, proves data existed at a time, with legal presumption of accuracy and integrity.
Qualified signature creation device (QSCD)
A QSCD (qualified electronic signature creation device) is certified hardware, such as an HSM, that creates a qualified signature or seal under EU eIDAS.
Qualified trust service provider (QTSP)
A Qualified Trust Service Provider is audited and listed on the EU Trusted List, giving qualified services the strongest legal recognition under eIDAS.
Qualified validation service (QVal)
QVal: the eIDAS trust service where a QTSP checks a qualified signature or seal and returns a result you can rely on.
Qualified website authentication certificate (QWAC)
A QWAC is an EU eIDAS qualified certificate that proves the verified identity behind a website, used widely in PSD2 open banking APIs.
R
RA professional certificate
An RA professional certificate is a qualified certificate proving the signer holds the protected Dutch RA (registered accountant) title.
Registration authority (RA)
Registration Authority (RA): the PKI party that verifies applicant identity and attributes, then passes verified data to the CA for certificate issuance.
Relying party (RP)
A relying party checks someone's digital identity, signature or certificate under eIDAS; wallet-relying parties must register to use the EUDI Wallet.
Remote signing
Remote signing means the signature is created on a server managed by a QTSP instead of on a card or token held by the user.
Rijksinspectie Digitale Infrastructuur (RDI)
The Rijksinspectie Digitale Infrastructuur (RDI, formerly Agentschap Telecom) is the Dutch supervisory body for trust services under eIDAS.
RSA
RSA is an asymmetric cryptographic algorithm based on prime factorisation, widely used for encryption and digital signatures in PKI.
S
SAML 2.0
SAML 2.0 (Security Assertion Markup Language) is the XML-based federation standard behind single sign-on for DigiD, eHerkenning, and eIDAS nodes.
SD-JWT
SD-JWT is an IETF credential format used in the EUDI Wallet, letting holders selectively disclose individual attributes from a signed token.
Selective disclosure
Selective disclosure lets an EUDI Wallet user share only needed attributes, like proving age without revealing a birth date, per GDPR data minimisation.
Signature activation data (SAD)
SAD (Signature Activation Data), defined in EN 419241, binds signatory, key and DTBS/R via SAP to activate a QSCD for eIDAS remote signing.
Signature activation module (SAM)
Signature Activation Module (SAM): the EN 419 241-2 component that enforces sole control in remote signing before each qualified signature is created.
Signature activation protocol (SAP)
The protocol that delivers signature activation data to the activation module, so a key on a server is only used under the signer's sole control.
Signature creation data (SCD)
Signature creation data (SCD) is the private key used to sign; eIDAS requires sole control and, for qualified signing, a certified QSCD.
Signature validation
Signature validation checks the cryptography, certificate trust chain and validity behind an electronic signature or seal, per eIDAS and ETSI standards.
Signature validation report
A signature validation report records TOTAL-PASSED, TOTAL-FAILED or INDETERMINATE status per ETSI standards, so you can archive proof of what was checked.
Single sign-on (SSO)
Single sign-on lets a user authenticate once and then access multiple applications without logging in again.
Sole control
Sole control is the eIDAS requirement, under Annex II, that only the signatory can use their private key, even when held by a QTSP for remote signing.
Sole control assurance level (SCAL)
Sole Control Assurance Level (SCAL) measures remote signing security; SCAL2 requires strong authentication for qualified electronic signatures.
Status list
How status lists let issuers signal attestation revocation or suspension in the EUDI Wallet, without tracking who checks a credential's status.
Strong authentication
Strong authentication (MFA/2FA) combines two independent factors, such as a password and phone, to secure logins and authorise qualified signatures.
Supervisory body
The national authority under eIDAS that supervises trust service providers and grants or withdraws their qualified status.
T
Tamper resistance
Tamper resistance is a device's ability to withstand physical and logical attacks on its keys, certified via Common Criteria, FIPS 140-3, or EN 419221-5.
Termination plan
The plan a qualified trust service provider must keep for the day it stops: who keeps records and revocation data available, and who is told when.
Time-stamping authority (TSA)
A TSA (Time-Stamping Authority) issues electronic timestamps binding a document hash to a moment in time, under eIDAS and RFC 3161 standards.
Trust service
A trust service is an eIDAS-regulated service such as electronic signatures, seals and timestamps; qualified ones are provided by a QTSP in the EU.
Trust service provider (TSP)
A trust service provider (TSP) offers eIDAS trust services such as certificates or timestamps - qualified or not. What it means and how it is supervised.
U
Uitvoeringswet Algemene verordening gegevensbescherming (UAVG)
The Dutch act implementing the GDPR: national choices, the Autoriteit Persoonsgegevens as supervisor and limits on using the BSN.
V
Verifiable credential (VC)
A digitally signed set of claims that a holder can present to a verifier without contacting the issuer - the pattern behind EUDI Wallet attestations.
W
Wallet certification
How an EUDI Wallet is certified under Article 5c eIDAS: designated bodies, European and national schemes, five years validity, biennial vulnerability checks.
Wallet connector
A Wallet Connector lets relying parties accept EUDI Wallet attestations without building the underlying wallet protocols themselves.
Wallet provider
Learn what a wallet provider does under eIDAS 2.0: building, certifying and operating an EUDI Wallet, with recognition under the Dutch Wdo.
Wallet secure cryptographic application (WSCA)
WSCA is the software component in the EUDI Wallet that manages cryptographic keys, working with the WSCD device to bind and present attestations.
Wallet secure cryptographic device (WSCD)
WSCD (Wallet Secure Cryptographic Device): secure hardware or service in the EUDI Wallet storing keys, can be QSCD-certified for qualified signatures.
Wallet unit
The configuration a wallet provider gives one user: wallet instance plus secure application and device. Certification and revocation apply here.
Wallet-relying party access certificate
The certificate a wallet-relying party shows to a wallet to prove who it is, issued by an appointed provider and tied to its registration.
Wallet-relying party registration
Under eIDAS Article 5b, organisations must register as a wallet-relying party before requesting data from an EUDI Wallet user.
Wet beveiliging netwerk- en informatiesystemen (Wbni)
Wbni: the Dutch NIS1 law that made essential providers and government secure their networks and report cyber incidents, replaced by the Cyberbeveiligingswet.
Wet digitale overheid (Wdo)
The Wet digitale overheid (Wdo) is the Dutch act governing DigiD, eHerkenning and assurance levels for digital access to government services.
Wwft
The Wwft is the Dutch AML law (anti-money-laundering act), requiring customer due diligence (CDD/KYC); digital identity enables secure remote onboarding.
WYSIWYS
WYSIWYS ensures the document you see when signing matches exactly what is hashed and signed, protecting signer intent and legal validity.
X
X.509
X.509 is the international standard for digital certificates, used for HTTPS/TLS, S/MIME, and other internet security, now in version 3.
XAdES
XAdES (ETSI EN 319 132) is the standard for embedding electronic signatures and seals in XML data, used for e-invoicing and long-term validation.
XML canonicalization (C14N)
XML canonicalization (C14N) converts an XML document into one fixed byte form, so formatting differences never break a signature.
XML signature (XMLDSig)
XML signature (XMLDSig): the W3C/IETF standard for embedding a digital signature in XML, and the base that XAdES builds on for eIDAS.
Z
Zero-knowledge proof (ZKP)
A proof that a statement holds while revealing nothing else: prove you are over 18 without your date of birth, and keep presentations unlinkable.