Attestation provider

Attestation provider: the EUDI Wallet role that issues a digital attestation - diploma, licence, mandate - to a wallet, in eIDAS and the ARF.

An attestation provider is any organisation that issues an electronic attestation of attributes into a wallet unit of the EUDI Wallet. The label is not an eIDAS term as such: the regulation defines specific categories of issuer, and the wallet's technical blueprint groups three of them under this one umbrella word - the PID provider issues the wallet's core identity data but is treated as a separate, sibling role rather than one of these three.

Three roles sit under that umbrella, and each carries a different legal weight:

Before any of them can hand an attestation to a wallet, the wallet must be able to check who it is dealing with. That check works through a wallet-relying party access certificate: the Architecture and Reference Framework (ARF) treats attestation providers as wallet-relying parties for this purpose, and requires them to authenticate themselves to the wallet before it accepts anything from them. This is a broader use of 'relying party' than the ordinary relying party (RP) of eIDAS, which covers only parties that request data from a wallet holder.

Note: Being an attestation provider does not by itself mean holding QTSP status. Only the QEAA provider must be qualified; a PID provider, a PUB-EAA provider and an ordinary EAA provider can all issue into a wallet without ever becoming a QTSP.

Frequently asked questions

Back to glossary