Conformity assessment body (CAB)
A conformity assessment body (CAB) audits trust service providers against eIDAS and ETSI standards, and may certify EUDI Wallet solutions under eIDAS 2.0.
A Conformity Assessment Body (CAB) is the accredited auditor that assesses whether a trust service provider meets the eIDAS requirements, using the ETSI standards (EN 319 401 and the service-specific norms) as the audit criteria. More generally, a CAB is any accredited body that verifies compliance against defined standards. CAB audits under eIDAS apply only to qualified trust services; at EU level there is no equivalent mandatory conformity assessment for non-qualified trust services, though member states may impose their own national requirements. Before a trust service provider can be granted qualified status, it must undergo an initial conformity assessment; the resulting report is submitted, together with the provider's notification of intention, to a supervisory body such as the RDI, which examines the report before granting qualified status. For periodic audits carried out while a provider holds qualified status, Article 20(1) of eIDAS 910/2014 requires the qualified trust service provider (QTSP) to submit the CAB's conformity assessment report to the supervisory body within three working days of receiving it from the CAB. The supervisory body may also order an ad hoc conformity assessment at any time under Article 20(2), for example in response to a complaint or suspected non-compliance, rather than waiting for the next periodic audit. Regulation (EU) 2024/1183 (eIDAS 2.0) left that duty where it was: the amended Article 20(1) still reads that qualified trust service providers shall submit the resulting report within three working days of receipt. The 24-month cycle at the provider's own expense was already there in 2014. What eIDAS 2 added to paragraph 1 is that the audit must now also confirm compliance with Article 21 of NIS2, and it introduced Article 20(1a), obliging the provider to announce a planned audit a month in advance and to let the supervisory body attend as an observer. Commission Implementing Regulation (EU) 2025/2162 of 27 October 2025, adopted under Article 20(4), further specifies the accreditation requirements for CABs, the format of the conformity assessment report, and the criteria for the conformity assessment scheme. The CAB only reports its findings - it is the supervisory body that verifies the report and grants, confirms, or withdraws qualified status, which is then reflected on the EU Trusted List.
CABs are accredited under the EU accreditation regulation (765/2008) specifically for eIDAS; a QTSP must, at its own expense, undergo re-assessment at intervals of at most 24 months. Examples of organisations accredited as CABs for eIDAS audits include TUV Informationstechnik GmbH (TUViT), LSTI, and the British Standards Institution (BSI). Under eIDAS 2.0, CABs designated by member states under the amended Article 5c certify EUDI Wallet solutions. Commission Implementing Regulation (EU) 2024/2981 of 28 November 2024 now sets out the requirements and procedures for this certification, including the requirements for the CABs that carry it out, rather than leaving this to a still-pending EU cybersecurity certification scheme under the Cybersecurity Act. These wallet-certification CABs are accredited under the 765/2008 regulation, though this designation and scope differ from the accreditation used for trust service audits. Certification of QSCD devices is a separate process, carried out by bodies designated under Article 30 of eIDAS rather than by CABs auditing trust service providers.