Level of assurance (LoA)
eIDAS LoA (low, substantial, high) shows how certain a relying party can be that an eID belongs to its user, per EU Regulation 2015/1502.
eIDAS defines three assurance levels for electronic identification - low, substantial and high - laid down in Implementing Regulation 2015/1502, expressing how certain a relying party can be that an eID belongs to the person using it. Formal mutual recognition under these levels applies to eID means issued under notified eIDAS electronic identification schemes, used for access to (cross-border) public services, though the same low/substantial/high vocabulary is also used more broadly by private relying parties to describe the strength of identity assurance they require. The level is determined by the weakest link across the whole chain: identity proofing at issuance, the strength and protection of the means itself, the authentication mechanism, and the issuer's processes.
Services choose the level that fits their risk: means with basic registration and single-factor password authentication typically sit at low; two-factor means sit at substantial; and means with certified hardware and in-person-equivalent proofing sit at high. In the Netherlands, DigiD offers Basis (low), Midden, Substantieel and Hoog variants, and eHerkenning maps EH3 to substantial and EH4 to high; the EUDI Wallet and PID issuance are intended to achieve level high under eIDAS 2, though the certification regime is still being rolled out. Under the Dutch Wdo, per-service minimum levels are designated by underlying decrees and ministerial regulations.