openideurope.eu

Levels of assurance in eIDAS: low, substantial, high

eIDAS defines three assurance levels for electronic identification: low, substantial and high. What they mean and which one the EU wallet needs.

Digital identityPublished

eIDAS describes how reliable an electronic identity is with three assurance levels: low, substantial and high. They tell a service how much confidence it can place in the claim ‘this user is who they say they are’. The levels come from Regulation (EU) No 910/2014 (eIDAS 2014) and its Implementing Regulation (EU) 2015/1502, and they remain central in eIDAS 2.0.

What the three levels mean

Article 8 of the original regulation defines the levels by the degree of confidence they provide.

Level Confidence in the claimed identity Typical use
Low Limited Low-risk services, convenience logins
Substantial Substantial Many e-government and banking services
High Higher than substantial, aimed at preventing misuse or alteration High-risk transactions, official procedures, the EU wallet

The levels are not about brand or technology, but about outcomes. A smart-card ID, a bank-based scheme or a mobile app can reach a given level if it meets the criteria.

What decides the level

Implementing Regulation (EU) 2015/1502 sets minimum technical specifications and procedures. You can read it on EUR-Lex. It looks at four areas.

  1. Enrolment. How the applicant is registered and how their identity is proofed and verified. This is the step where someone checks an ID document, either in person or remotely.
  2. Management of the electronic identification means. How the credential is designed, issued, delivered, activated, suspended, revoked and renewed.
  3. Authentication. How the user proves each time that they control the means, and how well the mechanism resists attacks such as guessing, eavesdropping, replay or manipulation.
  4. Management and organisation. Governance, information security, record keeping, staff, facilities and audits at the provider.

In broad terms, as the level goes up:

  • Identity proofing becomes stricter. At the lower level the evidence is assumed to be genuine. At substantial it must be checked, and at high there is an additional verification such as comparing a photo or biometric data with the person, or relying on an existing means that already meets the high level.
  • Authentication gets stronger. Low can rely on a single factor with basic protection. Substantial and high require multi-factor authentication, with resistance against attackers of moderate (substantial) or high (high) attack potential.
  • Provider management gets more demanding, including security controls and audits.

Our guide to phishing-resistant MFA shows why the type of second factor matters so much at the higher levels.

Why the levels matter in law

The levels connect directly to legal duties.

  • Mutual recognition. If a public sector body requires electronic identification with a notified level of substantial or high, it must recognise notified eIDs from other member states at that level. Recognition of low is voluntary. See cross-border eID.
  • Notification. Member states notify their eID schemes to the Commission together with the level they achieve. A list of notified schemes is published by the Commission.
  • The EU wallet. The EU Digital Identity Wallet must offer assurance level high.
  • Sector rules. Banks and other regulated firms apply their own authentication rules, such as strong customer authentication in payments. These are related, but not identical to the eIDAS levels. See digital identity for banking.

Examples

  • A forum account registered with only an email address and a password has no assurance level in the eIDAS sense, because no one has proofed your identity.
  • A national eID card used with a PIN and a card reader or a certified app can reach substantial or high, depending on its design. In Germany, the electronic ID card is notified at level high.
  • A bank-run identity scheme may be notified at substantial in some countries.

Treat these as examples, not a ranking: the level of a particular scheme is a matter of its notification and certification.

A level in practice: from enrolment to login

Imagine a national eID app rated ‘high’. At enrolment, the provider checks your passport or ID card and compares the photo or biometric data with you, or relies on another means that already meets level high. The app is then bound to your device with a protected key. Every time you log in to a tax portal, you unlock the app with a PIN or biometrics and it signs a challenge from the portal. A thief who steals only the password-equivalent, or a phisher who sees one login, cannot reuse it.

Compare that with a low-level login: you register with an email address, and later you type a password. Nobody has checked who you are, and the password can be reused anywhere. The difference in effort is the difference between the levels.

Common misunderstandings

  • ‘High’ does not mean unhackable. It means the scheme met strict criteria and has been assessed against high-potential attackers.
  • The level belongs to the scheme, not the service. A service chooses which level it needs; the identity provider’s notified level decides whether its eID qualifies.
  • A level is not a legal identity by itself. It describes confidence in an identification, whereas legal consequences, such as signing a contract, may depend on additional rules like qualified electronic signatures. See cross-border eID for recognition across borders.

What this means for you

If a service says it needs a ‘high’ eID, it is asking for more than a login. You should expect an identity check once (for example with a passport or the national ID card), and a strong authentication each time. For everyday use, that is what makes the wallet and national eIDs different from a password. Understand the distinction in identity versus authentication.

What this means for organisations

Do not ask for a higher level than the risk requires. Matching the level to the risk, low for low-impact actions, substantial for most account and service access, high for sensitive or irreversible actions, keeps sign-up friction down and avoids collecting more identity data than necessary. When you design flows for the wallet, plan for level high and check which attributes you actually need.

Frequently asked questions

What are the three eIDAS assurance levels?

Low gives limited confidence in the claimed identity, substantial gives substantial confidence, and high gives the highest confidence and is meant to prevent misuse or alteration of the identity. They are defined in Article 8 of Regulation (EU) No 910/2014, with the technical criteria in Implementing Regulation (EU) 2015/1502.

Which level does the EU Digital Identity Wallet need?

The wallet must offer assurance level high. This is one reason for its requirements on certification, device-bound keys and strong user authentication.

Is two-factor authentication enough for level high?

Not by itself. Level high combines strict identity proofing at enrolment, for example checking evidence against the person or an authoritative source, with strong authentication that resists attackers with high attack potential. Two factors alone describe only part of the picture.

Do the eIDAS levels match NIST or other frameworks?

Not exactly. NIST SP 800-63 and other national schemes use their own scales for identity proofing and authentication strength. They are comparable in spirit, but there is no official one-to-one mapping to the three eIDAS levels.

More in Digital identity