Skip to main content

Level of Assurance

Level of assurance, often shortened to LoA, is how much confidence a relying party can place in a claimed identity. eIDAS defines three: low, substantial and high.

The level is set by two things: how thoroughly the person was identified when the credential was first issued, and how well the credential is protected and bound to them afterwards. Commission Implementing Regulation (EU) 2015/1502 sets the technical criteria across four areas: enrolment, the electronic identification means itself, how the holder authenticates with it, and how the issuing body manages and audits the whole process.

Low covers a self-asserted registration with little or no verification of the claimed identity; substantial requires evidence that the identity is genuine, typically checked against a document or registry, and a login that uses more than one factor; high additionally requires that the identity was checked against an authoritative source, in person or by an equivalent remote procedure with comparable assurance, and that the credential sits in tamper-resistant hardware such as a secure element.

It matters because it decides what a credential may be used for: member states must recognise each other's notified eID schemes at substantial or high for access to public services across borders under the original 2014 eIDAS Regulation, and eIDAS 2.0 requires the EUDI Wallet itself to be issued at high, since PID is the anchor every other attestation in the wallet builds on. A relying party outside the public sector is not bound by the same recognition duty and can ask for whatever level its own risk requires: a service checking only that a customer is over 18 may accept a lower level or a single attribute, while one running anti-money-laundering onboarding will insist on high because the legal consequence of getting the identity wrong is far greater.

Can a relying party outside government require a higher level of assurance than eIDAS mandates?

Yes. eIDAS sets a floor: public services must accept notified schemes at substantial or high, and the EUDI Wallet must be issued at high. A private relying party is free to ask for whatever level its own risk demands, accepting a lower level for something like age verification while requiring high, with matching evidence, for anti-money-laundering onboarding or opening a financial account.

Back to the glossary