Electronic identification and trust services for electronic transactions in the internal market (eIDAS)

Regulation (EU) No 910/2014 on electronic identification and trust services for electronic transactions in the internal market—known as eIDAS—is the cornerstone of the EU’s legal framework for digital identity and trust services. It was adopted on 23 July 2014, entered into force on 17 September 2014, and became fully applicable from 1 July 2016 (with some staged application dates for specific provisions). eIDAS replaced the earlier Electronic Signatures Directive (1999/93/EC) and, as a regulation, applies directly in all EU Member States without the need for national transposition, ensuring a more harmonised approach.
eIDAS has two main pillars: electronic identification (eID) and trust services. For eID, it sets conditions under which Member States can notify their national eID schemes to the European Commission. Once notified and accepted, these schemes must be mutually recognized across the EU for access to online public services at the same or lower level of assurance. On the trust services side, eIDAS regulates electronic signatures, seals, timestamps, electronic registered delivery services, website authentication certificates, and the legal status of electronic documents. A key feature is that a qualified electronic signature (QES) under eIDAS must be recognized as having the equivalent legal effect of a handwritten signature throughout the EU.
Over time, the practical significance of eIDAS has increased as more Member States notified their eID schemes and as qualified trust service providers (QTSPs) came under harmonised supervision. The EU Trusted List mechanism allows anyone to verify which providers and services are “qualified” and thus enjoy legal presumptions (e.g., authenticity, integrity, and non-epudiation). Meanwhile, the broader political and economic context led to a revision of the framework: the eIDAS 2.0 proposal, published by the Commission in June 2021, culminated in the adoption of a new amending regulation in 2024. This introduces the European Digital Identity Wallet, expands the catalogue of trust services (e.g., electronic ledgers), and tightens obligations for crossborder usability of digital identities.
In this evolving landscape, organisations—both public and private—need to prepare strategically. First, they should map where and how signatures, seals, identity verification, and registered delivery are used in their processes (e.g., contract signing, customer onboarding, HR, public service access) and assess whether high-assurance or qualified services are required. Second, they should select eIDAScompliant providers, ideally QTSPs, for critical processes and ensure that their document and workflow systems support eIDAS formats (such as PAdES, XAdES, CAdES for signatures). Third, for crossborder interactions, they should ensure their portals and applications are ready to accept notified eID schemes and, looking ahead, integrate with EU Digital Identity Wallets where relevant.
Practically, preparation also includes governance, policies, and awareness. Organisations should develop or update internal policies that define when a simple, advanced, or qualified electronic signature is appropriate, specify acceptable identity assurance levels, and set retention and validation rules for electronic evidence. Legal, IT, and compliance teams should be trained on the implications of eIDAS (and its 2.0 revision), and procurement processes should require vendors to demonstrate eIDAS conformity and interoperability with national eID schemes and future European Digital Identity Wallets. By doing this now, organisations will not only ensure compliance with current eIDAS obligations but also position themselves to take advantage of the more seamless, crossborder digital identity ecosystem that eIDAS 2.0 is designed to create.
Author: Neil Redmond, Director of Cyber Security at PWC and graduate of the Executive MBA
