Attestation Provider
Attestation Provider is the collective term for the three roles the ARF defines for issuing attribute credentials: a QEAA Provider, a PuB-EAA Provider, and a non-qualified EAA Provider. Which one an issuer is determines how much trust a relying party can place in what it issues.
A QEAA Provider is a qualified trust service provider listed on a national Trusted List, so its attestations carry the eIDAS 2.0 legal presumption of accuracy, the same legal weight a qualified electronic signature has. A PuB-EAA Provider is a public sector body, or an entity acting on its behalf, issuing attestations without going through qualified certification, because its own public mandate already establishes the trust a relying party needs. An EAA Provider is any other organisation issuing attestations at whatever assurance level it can support, which covers most private-sector use cases such as a professional body confirming a licence or an employer confirming a role. All three draw on Authentic Sources for the attributes they attest, and a relying party checks the Trust Anchor behind an Attestation Provider to know which of the three it is dealing with, since the legal weight of the resulting credential depends entirely on that classification. A verifier accepting an attestation for a regulated process, opening a bank account under KYC rules for example, typically needs a QEAA or PuB-EAA rather than an ordinary EAA, while a loyalty scheme or an internal company badge can rely on the lower bar an EAA Provider offers. The ARF requires each Attestation Provider to register itself and the attestation types it issues, so the distinction between the three roles is enforceable rather than a matter of a provider's own claim.
Related terms
Can an EAA Provider issue the same attestations as a QEAA Provider?
No. An EAA Provider issues attestations at whatever assurance level it can support, without the qualified certification a QEAA Provider holds. A relying party that needs the eIDAS 2.0 legal presumption of accuracy, for a regulated KYC process for example, has to rely on a QEAA or PuB-EAA Provider rather than an ordinary EAA Provider's attestation.