The WSCA behind your wallet

Every EU Digital Identity Wallet and European Business Wallet requires a Wallet Secure Cryptographic Application (WSCA): the component that secures critical assets under exclusive user control.

On the path to early EUCC certification at EAL4+

Under independent evaluation by Brightsight

Based on open standards such as OAuth 2.0

Transparency in technical specifications and source code

Possibility of a white-label solution in your own wallet

Why every wallet needs a WSCA

By the end of 2026, every EU member state must offer an EU Digital Identity Wallet, with a certified WSCA as a mandatory component. Our WSCA is designed to meet those requirements, providing the evidence needed for your certification process.

Implementing Regulation (EU) 2024/2979 Article 5

Meets the functional requirements

Implementing Regulation (EU) 2024/2979 (Article 5) specifies how a WSCA must protect critical assets and ensure exclusive management by the user. Our architecture is built specifically to meet those requirements.

Read more
Implementing Regulation (EU) 2024/2981 Annex I & Annex IV

Meets the certification requirements

Implementing Regulation (EU) 2024/2981 (Annex I and Annex IV) requires certification of the wallet solution, including the WSCA. We are undergoing evaluation under the EU Cybersecurity Certification Scheme (EUCC), with Brightsight as the independent, accredited body.

Read more
Implementing Regulation (EU) 2015/1502Staatscourant (NL) 2025, 4198

High assurance electronic identification

For eID at high level, the requirements from Implementing Regulation (EU) 2015/1502 apply, along with additional requirements under the Digital Government Act in the Netherlands (Official Gazette 2025, 4198). Our WSCA provides the technical building block to meet these.

Read more

How the WSCA works

The WSCA verifies two factors per transaction: the PIN (knowledge factor) and the phone (possession factor). Each action produces non-repudiable proof. This provides cryptographic assurance that the critical assets of the wallet unit are under sole control of its user. Even the wallet provider or Cleverbase could not circumvent this mechanism.

One PIN entry, multiple actions

The user approves the entire transaction with a single action. You configure access according to your own security policy.

Two consumption models

In your own environment with supported HSMs as WSCD, or hosted as a service, in our Trust Service Provider environment. You integrate the client libraries into your wallet apps.

Scales with you

Horizontally scalable on hardened open-source Linux servers, flexible enough to fit your infrastructure.

Suitable for EU Member States and wallet providers

National wallet teams

You build or outsource a national wallet. Our WSCA follows recognizable standards and deployment models, and in wallet certification you can rely on EUCC evidence.

Wallet providers & wallet solution providers

You want to provide a wallet for a high-assurance use case such as an EUDI Wallet. Our WSCA can be provided as fully white-label, built by a team that has operated digital identity wallets in production since 2018.

Discuss your wallet with us

Schedule a meeting to gather more information or to discuss your needs with our CTO.

Sander Dijkhuis

Sander Dijkhuis

CTO

“Everyone deserves digital tools that are safe yet simple.”

Co-founder Cleverbase in 2016

or

Cleverbase will only use the contact details you provide to us to get in touch with you regarding your question. For more information, you can refer to our privacy statement.

Learn more

Follow the latest developments regarding our WSCA.