HomeBlog
IdentiGate Research

Insights on Digital Identity
& e-Signatures

In-depth analysis for professionals navigating digital identity, eIDAS compliance, and electronic signatures across logistics, insurance, healthcare and beyond.

58 articles

Cybersecurity

What Happens if Someone Denies They Signed Digitally?

The signature carries the burden of proof — but the burden falls back on whoever relied on it if the evidence chain behind the signature isn't complete. Under eIDAS Article 25(2), Qualified Electronic Signatures presume authenticity unless the challenger rebuts it. For Advanced signatures, the party asserting the signature has to demonstrate identity binding, integrity, and time — and courts have been consistent since 2020 that thin proofing evidence loses the case.

Mairi Kutberg · 12 min read Read...
Cybersecurity

What Encryption Does a Digital Signature Use?

Strictly speaking, digital signatures don't encrypt anything — they use asymmetric cryptography to sign a hash of the data. The signer's private key transforms the hash into a signature; the corresponding public key verifies it. In 2026 production: RSA-PSS with SHA-256 (RFC 8017), ECDSA over P-256 or P-384 (RFC 6979), and Ed25519 (RFC 8032). ETSI TS 119 312 sets which cryptographic suites are acceptable for AdES, and the post-quantum migration is starting to reshape the algorithm shortlist through 2030.

Gustav Poola · 13 min read Read...
Cybersecurity

What Makes a Digital Signature Legally Valid?

Three things stacked in the right order under eIDAS Article 25: non-discrimination in principle for any electronic signature, equivalence to a handwritten signature only for Qualified Electronic Signatures under Article 25(2), and successful validation under the Article 32 procedure. The gap that costs cases in court is between 'the signature exists' and 'the signature validates against Article 32 requirements' — and the identity-proofing under the signing certificate is where most legal-validity claims quietly break.

Mairi Kutberg · 12 min read Read...
Cybersecurity

Digital Certificate vs Digital Signature: What's the Difference?

A digital certificate is a signed statement about a public key and its holder's identity, issued by a Certificate Authority. A digital signature is a cryptographic operation produced by the corresponding private key over document data. The certificate proves who the signer is; the signature proves the document is intact and was signed by that signer. Different objects, complementary purposes, and the confusion between them is where most eIDAS audit findings actually land.

Gustav Poola · 11 min read Read...
Cybersecurity

Do Digital Signatures Require Proof of Identity?

Yes — and the proof requirement scales with the legal tier. Simple Electronic Signatures need no formal proofing. Advanced Electronic Signatures (AdES) under eIDAS Article 26 must be uniquely linked to a verifiably identified signer. Qualified Electronic Signatures require identity proofing by a Qualified Trust Service Provider before certificate issuance. The gap most platforms hit is between having a certificate and the certificate being bound to a globally verifiable person.

Mairi Kutberg · 11 min read Read...
Cybersecurity

How Do I Verify Someone's Digital Signature Is Authentic?

Through a structured five-stage validation chain defined by ETSI EN 319 102-1 — confirm the signature matches the document hash, resolve the signing certificate back to a trusted root, validate the certificate was not revoked at the signing moment, check the cryptographic algorithm policy was acceptable at the signing moment, and verify the signing time itself. The trust roots resolve against the EU Trusted List under eIDAS Article 22. Each stage produces a distinct verification result; a failure at any stage tells the verifier what specifically broke.

Gustav Poola · 13 min read Read...
Healthcare

EHDS Secondary Use: Who Verifies the Researcher Asking for Patient Data?

The Health Data Access Body (HDAB) in each Member State is the gatekeeper. Designated by 26 March 2027 under Article 36 of the European Health Data Space Regulation, the HDAB verifies the researcher's identity, affiliation, ethics approval, and proposed processing scope at the data permit application step — and only then issues access to the Secure Processing Environment where the underlying patient data sits. The chain terminates at the researcher's identity record; the strength of every downstream control depends on the strength of that record.

Mairi Kutberg · 12 min read Read...
Healthcare

How Does Doctor Identity Move Across EU Borders in 2026?

Through three overlapping credential schemas — the doctor's national professional certificate (issued by the home medical register), an extended EU Professional Card under Directive 2005/36/EC (planned, not yet operational for physicians), and a Person Identification Data attestation in their EUDI Wallet under Regulation (EU) 2024/1183 (provisioned by 6 December 2026). None of the three yet covers the full cross-border scope alone. The deployment question for digital health platforms in 2026 is which schema to read first and which to fall back to.

Gustav Poola · 12 min read Read...
Logistics

Who Holds the Proof — the eCMR Record or the Platform?

39 countries accept eCMR. eFTI becomes mandatory in July 2027. Yet the data model underneath still records signers as plain text — and most digitisation puts the proof in the platform, not the record. That architecture choice decides who owns the truth.

Gustav Poola · 12 min read Read...
Healthcare

Cross-Border ePrescription: Who Verifies the Prescribing Doctor?

The doctor is verified at the home Member State, asserted across the eHDSI network through a federation of National Contact Points for eHealth, and re-validated at the dispensing Member State's contact point. The cryptographic chain terminates at the home country's national medical register. EHDS 2025 harmonises the exchange format and adds the European Health Data Access Body layer, but the identity-proofing of the doctor still sits with the home Member State's trust framework and its credentialing body.

Mairi Kutberg · 11 min read Read...
Cybersecurity

What Happens When AI Agents Need to Collaborate With Humans?

The collaboration boundary becomes a delegation interface. Under the EU AI Act Article 14 human-oversight obligation and emerging Know Your Agent (KYA) frameworks, the agent's authority chain must terminate at a verifiably-identified human delegator — and every handoff back to that human must re-verify the human at the moment of decision. The handoff is not a chat exchange; it is an identity-bound control transfer, and the engineering question is whose identity is on each side of the boundary.

Gustav Poola · 11 min read Read...
Cybersecurity

What's the Difference Between a Digital ID and a Digital Wallet?

A digital ID is the verifiable credential that proves who you are — issued by a trust framework like eIDAS, a passport chip, or a national eID scheme. A digital wallet is the user-controlled container that holds those credentials and presents them to verifiers under selective disclosure. The wallet does not produce identity; it carries identity that has to be issued at the proofing layer first.

Mairi Kutberg · 12 min read Read...
Cybersecurity

How Long Do Digital Signatures Remain Valid?

A digital signature is verifiable while its underlying certificate is valid — typically one to three years. After expiry, the signature is still cryptographically intact, but extra evidence is needed to verify it. Long-term validation (LTV) under PAdES-LTA, XAdES-A and CAdES-LTA, anchored by a Qualified Timestamp from a QTSP, extends verifiability indefinitely. IdentiGate signatures embed trusted signing time but do not include a Qualified Timestamp — that is a separate eIDAS Article 41 service.

Gustav Poola · 9 min read Read...
Cybersecurity

What's the Difference Between Digital Signature and Electronic Signature?

Electronic signature is the legal term — any data attached to other data to sign, under eIDAS Article 3(10). Digital signature is the technical term — a cryptographic primitive using public-key cryptography. Every digital signature is an electronic signature; not every electronic signature is a digital signature. eIDAS adds three legal tiers on top: SES, AdES, QES.

Mairi Kutberg · 11 min read Read...
Cybersecurity

What Is Know Your Agent (KYA) and Why Should You Care?

Know Your Agent (KYA) is the emerging identity-verification paradigm for AI agents — analogous to Know Your Customer (KYC) for humans. The components are agent authentication, decentralised identifiers, verifiable credentials, and an agent capability and permission record. NIST launched its AI Agent Standards Initiative in February 2026; industry standards (Anthropic MCP, Google A2A, W3C DIDs) are converging through 2026-2027.

Gustav Poola · 12 min read Read...
Cybersecurity

Do You Really Have to Verify Your Age Every Time Online?

No, not every time — if your platform is wired to consume a wallet-based age attribute under the EUDI Wallet framework. The DSA requires age-appropriate design under Article 28, Member States are layering harder mandates (France SREN, UK Online Safety Act), and the EUDI Wallet age attribute lands as the EU-wide compliance answer through 2026 pilots.

Mairi Kutberg · 9 min read Read...
Healthcare

Do Medical Devices Need Both CRA and MDR Identity Controls?

Medical devices regulated under MDR 2017/745 are currently exempt from the CRA's product requirements. The exemption is incomplete — wearables, companion apps, standalone software, and components sold separately may still fall under CRA. The December 2025 European Commission proposal would remove the exemption entirely. CRA Article 14 vulnerability reporting starts 11 September 2026.

Gustav Poola · 9 min read Read...
Cybersecurity

How Do You Know If a Website Is Really Who They Say They Are?

The padlock in your browser tells you the connection is encrypted. It does not tell you who runs the website. eIDAS Article 45 defines a separate primitive for that — the Qualified Website Authentication Certificate (QWAC). The Implementing Act was adopted on 17 December 2025; major browsers still do not display QWACs in a user-friendly UI.

Gustav Poola · 13 min read Read...
Healthcare

What Does NIS2 Actually Require for Hospital Staff Identity?

Yes — Annex I of Directive (EU) 2022/2555 lists healthcare as an essential entity sector. Commission Implementing Regulation (EU) 2024/2690 sets the technical requirements. Hospital staff identity proofing is implicit in Article 21(2)(i) access control and explicit in the Implementing Regulation's identity management language. The audit-defensible answer is upstream chip-anchored proofing.

Mairi Kutberg · 9 min read Read...
Cybersecurity

Can You Use the Same Digital Identity Everywhere?

Yes, in three specific cases that work today — and one that still doesn't. A global digital identity works inside an EUDI Wallet across EU services, across a federation (OIDC, eduGAIN, eIDAS cross-border), and across multiple documents linked into one cryptographic anchor (Unified Digital Identity). It still does not work for unfederated non-EU platforms without a shared trust framework.

Gustav Poola · 10 min read Read...
Healthcare

EHDS Patient Summary 2026: Who Verifies the Patient at the Border?

The EHDS Regulation (EU) 2025/327 applies from 26 March 2026; cross-border Patient Summary and ePrescription exchange goes live across Member States by 26 March 2029. MyHealth@EU specifies the data exchange. The identity verification of the patient at the point of care is delegated to the receiving healthcare professional under national rules.

Mairi Kutberg · 10 min read Read...
Cybersecurity

What Is a Zero-Knowledge Proof — and Why Should You Care?

Zero-knowledge proofs are real technology in production today — privacy crypto, blockchain scaling, and selective disclosure of verifiable credentials. RFC 9901 standardised SD-JWT in November 2025; the EUDI Wallet ARF points toward BBS+ as the everlasting-privacy target. The bit ZKPs do not replace is identity proofing itself.

Gustav Poola · 9 min read Read...
Education

University Identity Stack 2027: Where Should You Actually Start?

Universities have eighteen months to put a defensible identity stack in production. AI Act high-risk lands 2 August 2026; EUDI Wallet 6 December 2026; AMLR cross-border identity 10 July 2027. The cheapest place to start is admission.

Mairi Kutberg · 12 min read Read...
Education

EBSI Verifiable Diplomas 2026: How Is the Holder Actually Bound?

W3C published Verifiable Credentials 2.0 in May 2025; EBSI uses did:ebsi for legal entities and did:key plus DPoP for natural persons. The spec proves the wallet holds a key. It does not prove who holds the wallet. That gap is what 2026 has to close.

Gustav Poola · 12 min read Read...
Education

Remote Proctoring 2026: Can Deepfakes Beat Selfie ID Verification?

Remote proctoring becomes high-risk under Annex III of the EU AI Act on 2 August 2026 — twice over. Deepfake attacks on selfie+ID verification are now industrial. The exam stage needs a different identity primitive than the webcam.

Mairi Kutberg · 12 min read Read...
Education

Diploma Mills 2026: Where Does Cryptographic Verification Hold?

The diploma mill industry runs at roughly $7B/year. EBSI Verifiable Diplomas cryptographically bind a credential to a holder identifier — but the holder identifier itself is still proofed locally. The chain holds at the issuer; it breaks at the person.

Gustav Poola · 11 min read Read...
Education

FAFSA Fraud 2026: How Did $1B+ Almost Reach Ghost Students?

On 26 April 2026 the US Department of Education launched real-time identity fraud detection inside the FAFSA. California community colleges flagged 31% of 2024 applications as fraudulent. The architectural answer is upstream proofing, not downstream cleanup.

Mairi Kutberg · 13 min read Read...
Education

International Student Identity 2026: Where Does It Break?

6.9 million students study cross-border each year (UNESCO 2024). EUDI covers 27 EU states, eduGAIN is web-only with gaps. The biometric passport is the only universal primitive.

Gustav Poola · 13 min read Read...
Healthcare

EHDS Cross-Border Records: Who Verified the Doctor?

EHDS applies from March 2027. Patient summaries and ePrescriptions go cross-border by default. But health professional identity is still verified country by country.

Mairi Kutberg · 11 min read Read...
Cybersecurity

CER Directive 2026: Identity Rules for Critical Entities

Member States must designate critical entities in 11 sectors by 17.07.2026. CER Articles 13-14 demand personnel security and background checks — including externals.

Gustav Poola · 13 min read Read...
Cybersecurity

OT Remote Access 2026: The Third-Party Identity Gap

NERC CIP-003-9 and NIS2 Article 21 both require identity-bound OT vendor access in 2026. Cross-border technician identity is the gap neither framework solves.

Mairi Kutberg · 13 min read Read...
Defense

EU Defence Tenders 2026: Do EDIP and EDF Need QES?

Most EU defence tender submissions accept AdES, not QES. EDIP and EDF proposals sign via EU Login on the F&T Portal. Here's what each call really requires.

Gustav Poola · 12 min read Read...
Cybersecurity

CRA Signed SBOMs: Why the eSeal Is the Emerging Trust Anchor

The EU Cyber Resilience Act makes signed SBOMs mandatory by December 2027. The emerging legal trust anchor is the qualified electronic seal (eSeal) under eIDAS 2.

Mairi Kutberg · 9 min read Read...
Cybersecurity

NIS2 Article 21: Identity Evidence Auditors Ask For in 2026

Belgium's 18 April 2026 NIS2 deadline has passed. Article 21 is now an evidence chain, not a checklist. Where most entities' identity proofing falls short.

Gustav Poola · 10 min read Read...
Insurance

DORA Register 2026: What the 31 March Deadline Revealed

The DORA Register deadline closed three weeks ago. Only 6.5% of firms passed all 116 data quality checks in the 2024 dry-run. The gap is the identity chain.

Mairi Kutberg · 9 min read Read...
Cybersecurity

Phishing-Resistant MFA vs Passport Chip: NIST AAL2 in 2026

Passkeys and passport chips are both phishing-resistant — but they answer different questions. NIST SP 800-63B-4 has AAL and IAL as independent axes.

Gustav Poola · 8 min read Read...
Insurance

Cyber Insurance 2026: Identity Proofing Is the New MFA

Cyber insurance premiums hit $23bn in 2026. 41% of applications are denied on first submission. The underwriting line has moved below MFA into identity proofing.

Mairi Kutberg · 9 min read Read...
Cybersecurity

NIS2 Supplier Identity Register: What Auditors Check in 2026

Belgium's first binding NIS2 deadline is today. Article 21(2)(d) requires supply chain security — and what auditors open first is the supplier register.

Gustav Poola · 9 min read Read...
Cybersecurity

EU AMLR 2027: Your KYC Stack Needs a Non-EU Identity Layer

The EU AMLR applies 10 July 2027, demanding verifiable identity for every customer. The EUDI Wallet covers 27 EU countries — your non-EU customers need another path.

Mairi Kutberg · 9 min read Read...
Cybersecurity

Post-Quantum eIDAS Signatures: 7 Questions for Your TSP

NIST finalised post-quantum signature standards in 2024. EU set national PQC strategies by 2026. Most eIDAS signatures still use RSA. Seven questions for your TSP.

Gustav Poola · 12 min read Read...
Logistics

Why Electronic Bill of Lading Adoption Is Stuck at 11%

eBL platforms are interoperable. DCSA carriers are technically ready. So why is adoption stuck at 11%? The missing layer is digital identity of the parties.

Mairi Kutberg · 12 min read Read...
Cybersecurity

AI Agent Signing Authority: Can a Non-Human Sign Contracts?

AI agents order, approve, and sign across enterprise systems. But only a legal or natural person can hold signing authority — most companies cannot prove the chain.

Gustav Poola · 11 min read Read...
Cybersecurity

Non-Human Identity: Who Verified the Human Behind It?

18.1 million API keys exposed in 2025. Machine identities outnumber humans 100:1. NHI industry secures machines — but humans who created them are unverified.

Mairi Kutberg · 11 min read Read...
Cybersecurity

Zero Trust Starts With Knowing Who — Not What You Verify

96% of organisations favour Zero Trust. 84% had identity breaches anyway. The problem: 'never trust, always verify' fails when you can't verify who someone is.

Gustav Poola · 10 min read Read...
Logistics

How to Verify Non-EU Driver Identity for eCMR Signing

Non-EU drivers carry a material share of EU freight but have no European digital identity. Three methods to verify them — and which one actually works at scale.

Mairi Kutberg · 13 min read Read...
Cybersecurity

Passkeys Solve Authentication — Not Identity. Here's Why.

15 billion accounts are passkey-enabled. But passkeys prove you have a device, not who you are. For cross-border and high-risk scenarios, that gap matters.

Gustav Poola · 10 min read Read...
Cybersecurity

Deepfakes Can Fool Any Camera. They Can't Fool a Passport Chip.

Deepfake fraud attempts surged 2,137% since 2022. Synthetic identities cost $20–40B. But one piece of hardware remains immune — and it's already in your pocket.

Mairi Kutberg · 10 min read Read...
Logistics

eFTI Article 5: Identity Verification for Freight Platforms

From July 2027, every eFTI platform must verify the identity of every business user. Here is what Article 5 actually requires — and why most platforms are not ready.

Gustav Poola · 11 min read Read...
Logistics

eFTI 2027 Compliance Checklist: 10 Steps for Freight Ops

From July 2027, EU authorities must accept digital freight data. Here's a step-by-step checklist to get your logistics operation ready — starting now.

Gustav Poola · 9 min read Read...
Logistics

Is Sign-on-Glass a Valid eCMR Signature? Barely.

Many drivers 'sign' eCMR by scribbling on a tablet. Under eIDAS, that's the weakest form of electronic signature — and it may not hold up when it matters.

Mairi Kutberg · 6 min read Read...
Logistics

Which Countries Accept eCMR? The Complete 2026 List

39 countries have ratified the eCMR protocol. Here's the full list, the EU countries still missing, and what it means for your cross-border freight.

Gustav Poola · 8 min read Read...
Logistics

What Is eCMR? A Plain-Language Guide for Freight Companies

Everything you need to know about the electronic consignment note: what it is, how it works, who needs it, and what's changing in 2026–2027.

Mairi Kutberg · 11 min read Read...
Cybersecurity

AI Agents Need Identity: Who's Behind the Machine?

40% of enterprise apps feature AI agents by end-2026 (Gartner). Only 23% of organisations have a formal identity strategy. Missing layer: human verification.

Gustav Poola · 11 min read Read...
Logistics

The EUDI Wallet Covers 27 Countries. What About the Other 153?

The EUDI Wallet is a milestone for Europe — but it leaves non-EU partners, suppliers, and workers without a digital identity. That gap affects your business.

Mairi Kutberg · 8 min read Read...
Logistics

Paper CMR vs eCMR: The Real Cost of Not Going Digital

Processing a paper CMR takes 23 minutes; an eCMR takes 9. Real cost: €6.23 vs €1.69 per document. Here are the hard numbers backed by independent research.

Gustav Poola · 9 min read Read...
Logistics

AdES vs QES: Which eSignature Level Does Logistics Need?

eCMR and eFTI require digital signatures — but not the most expensive kind. A practical guide to choosing between AdES and QES for freight documents.

Mairi Kutberg · 8 min read Read...
Logistics

Cargo Theft in Europe: €2.5M Stolen Every Day (2026 Data)

€2.7 billion stolen in three years. 634 incidents in a single month. Average loss per major incident: €878,525. A data briefing on Europe's cargo crime crisis.

Mairi Kutberg · 10 min read Read...
Logistics

Digital Identity in European Freight: eCMR, eFTI, Cross-Border

Everything logistics leaders need to know about digital identity for freight — from eFTI compliance and signature levels to the non-EU identity gap.

Gustav Poola · 10 min read Read...