Wallet-relying party access certificate
The certificate a wallet-relying party shows to a wallet to prove who it is, issued by an appointed provider and tied to its registration.
The certificate with which a relying party authenticates itself to a wallet unit before it may ask for anything. In the reference framework it is defined as a certificate for electronic seals or signatures that authenticates and validates the wallet-relying party, issued by a provider of wallet-relying party access certificates.
It is the technical answer to a legal requirement. eIDAS says a relying party has to register in its Member State and identify itself to the user, and that Member States provide a common mechanism for identifying and authenticating relying parties. The access certificate is that mechanism: the wallet checks the certificate, so "who is asking" is not a claim in a web form but something the wallet can verify against a trusted issuer.
Do not confuse it with the registration certificate, which is a different object: the access certificate says who you are, the registration certificate says what you registered to ask for. Together they let a wallet warn a user when a service requests more than it declared - the enforceable side of data minimisation in the wallet ecosystem. The detail is no longer only in the reference framework: Commission Implementing Regulation (EU) 2025/848 requires each member state to authorise at least one certificate authority to issue these certificates, and sets the technical requirements. It applies from 24 December 2026, so a relying party planning for it should read that date as the moment the mechanism has to work, not as the moment to start.