In-depth analysis for professionals navigating digital identity, eIDAS compliance, and electronic signatures across logistics, insurance, healthcare and beyond.
58 articles
The signature carries the burden of proof — but the burden falls back on whoever relied on it if the evidence chain behind the signature isn't complete. Under eIDAS Article 25(2), Qualified Electronic Signatures presume authenticity unless the challenger rebuts it. For Advanced signatures, the party asserting the signature has to demonstrate identity binding, integrity, and time — and courts have been consistent since 2020 that thin proofing evidence loses the case.
Strictly speaking, digital signatures don't encrypt anything — they use asymmetric cryptography to sign a hash of the data. The signer's private key transforms the hash into a signature; the corresponding public key verifies it. In 2026 production: RSA-PSS with SHA-256 (RFC 8017), ECDSA over P-256 or P-384 (RFC 6979), and Ed25519 (RFC 8032). ETSI TS 119 312 sets which cryptographic suites are acceptable for AdES, and the post-quantum migration is starting to reshape the algorithm shortlist through 2030.
Three things stacked in the right order under eIDAS Article 25: non-discrimination in principle for any electronic signature, equivalence to a handwritten signature only for Qualified Electronic Signatures under Article 25(2), and successful validation under the Article 32 procedure. The gap that costs cases in court is between 'the signature exists' and 'the signature validates against Article 32 requirements' — and the identity-proofing under the signing certificate is where most legal-validity claims quietly break.
A digital certificate is a signed statement about a public key and its holder's identity, issued by a Certificate Authority. A digital signature is a cryptographic operation produced by the corresponding private key over document data. The certificate proves who the signer is; the signature proves the document is intact and was signed by that signer. Different objects, complementary purposes, and the confusion between them is where most eIDAS audit findings actually land.
Yes — and the proof requirement scales with the legal tier. Simple Electronic Signatures need no formal proofing. Advanced Electronic Signatures (AdES) under eIDAS Article 26 must be uniquely linked to a verifiably identified signer. Qualified Electronic Signatures require identity proofing by a Qualified Trust Service Provider before certificate issuance. The gap most platforms hit is between having a certificate and the certificate being bound to a globally verifiable person.
Through a structured five-stage validation chain defined by ETSI EN 319 102-1 — confirm the signature matches the document hash, resolve the signing certificate back to a trusted root, validate the certificate was not revoked at the signing moment, check the cryptographic algorithm policy was acceptable at the signing moment, and verify the signing time itself. The trust roots resolve against the EU Trusted List under eIDAS Article 22. Each stage produces a distinct verification result; a failure at any stage tells the verifier what specifically broke.
The Health Data Access Body (HDAB) in each Member State is the gatekeeper. Designated by 26 March 2027 under Article 36 of the European Health Data Space Regulation, the HDAB verifies the researcher's identity, affiliation, ethics approval, and proposed processing scope at the data permit application step — and only then issues access to the Secure Processing Environment where the underlying patient data sits. The chain terminates at the researcher's identity record; the strength of every downstream control depends on the strength of that record.
Through three overlapping credential schemas — the doctor's national professional certificate (issued by the home medical register), an extended EU Professional Card under Directive 2005/36/EC (planned, not yet operational for physicians), and a Person Identification Data attestation in their EUDI Wallet under Regulation (EU) 2024/1183 (provisioned by 6 December 2026). None of the three yet covers the full cross-border scope alone. The deployment question for digital health platforms in 2026 is which schema to read first and which to fall back to.
39 countries accept eCMR. eFTI becomes mandatory in July 2027. Yet the data model underneath still records signers as plain text — and most digitisation puts the proof in the platform, not the record. That architecture choice decides who owns the truth.
The doctor is verified at the home Member State, asserted across the eHDSI network through a federation of National Contact Points for eHealth, and re-validated at the dispensing Member State's contact point. The cryptographic chain terminates at the home country's national medical register. EHDS 2025 harmonises the exchange format and adds the European Health Data Access Body layer, but the identity-proofing of the doctor still sits with the home Member State's trust framework and its credentialing body.
The collaboration boundary becomes a delegation interface. Under the EU AI Act Article 14 human-oversight obligation and emerging Know Your Agent (KYA) frameworks, the agent's authority chain must terminate at a verifiably-identified human delegator — and every handoff back to that human must re-verify the human at the moment of decision. The handoff is not a chat exchange; it is an identity-bound control transfer, and the engineering question is whose identity is on each side of the boundary.
A digital ID is the verifiable credential that proves who you are — issued by a trust framework like eIDAS, a passport chip, or a national eID scheme. A digital wallet is the user-controlled container that holds those credentials and presents them to verifiers under selective disclosure. The wallet does not produce identity; it carries identity that has to be issued at the proofing layer first.
A digital signature is verifiable while its underlying certificate is valid — typically one to three years. After expiry, the signature is still cryptographically intact, but extra evidence is needed to verify it. Long-term validation (LTV) under PAdES-LTA, XAdES-A and CAdES-LTA, anchored by a Qualified Timestamp from a QTSP, extends verifiability indefinitely. IdentiGate signatures embed trusted signing time but do not include a Qualified Timestamp — that is a separate eIDAS Article 41 service.
Electronic signature is the legal term — any data attached to other data to sign, under eIDAS Article 3(10). Digital signature is the technical term — a cryptographic primitive using public-key cryptography. Every digital signature is an electronic signature; not every electronic signature is a digital signature. eIDAS adds three legal tiers on top: SES, AdES, QES.
Know Your Agent (KYA) is the emerging identity-verification paradigm for AI agents — analogous to Know Your Customer (KYC) for humans. The components are agent authentication, decentralised identifiers, verifiable credentials, and an agent capability and permission record. NIST launched its AI Agent Standards Initiative in February 2026; industry standards (Anthropic MCP, Google A2A, W3C DIDs) are converging through 2026-2027.
No, not every time — if your platform is wired to consume a wallet-based age attribute under the EUDI Wallet framework. The DSA requires age-appropriate design under Article 28, Member States are layering harder mandates (France SREN, UK Online Safety Act), and the EUDI Wallet age attribute lands as the EU-wide compliance answer through 2026 pilots.
Medical devices regulated under MDR 2017/745 are currently exempt from the CRA's product requirements. The exemption is incomplete — wearables, companion apps, standalone software, and components sold separately may still fall under CRA. The December 2025 European Commission proposal would remove the exemption entirely. CRA Article 14 vulnerability reporting starts 11 September 2026.
The padlock in your browser tells you the connection is encrypted. It does not tell you who runs the website. eIDAS Article 45 defines a separate primitive for that — the Qualified Website Authentication Certificate (QWAC). The Implementing Act was adopted on 17 December 2025; major browsers still do not display QWACs in a user-friendly UI.
Yes — Annex I of Directive (EU) 2022/2555 lists healthcare as an essential entity sector. Commission Implementing Regulation (EU) 2024/2690 sets the technical requirements. Hospital staff identity proofing is implicit in Article 21(2)(i) access control and explicit in the Implementing Regulation's identity management language. The audit-defensible answer is upstream chip-anchored proofing.
Yes, in three specific cases that work today — and one that still doesn't. A global digital identity works inside an EUDI Wallet across EU services, across a federation (OIDC, eduGAIN, eIDAS cross-border), and across multiple documents linked into one cryptographic anchor (Unified Digital Identity). It still does not work for unfederated non-EU platforms without a shared trust framework.
The EHDS Regulation (EU) 2025/327 applies from 26 March 2026; cross-border Patient Summary and ePrescription exchange goes live across Member States by 26 March 2029. MyHealth@EU specifies the data exchange. The identity verification of the patient at the point of care is delegated to the receiving healthcare professional under national rules.
Zero-knowledge proofs are real technology in production today — privacy crypto, blockchain scaling, and selective disclosure of verifiable credentials. RFC 9901 standardised SD-JWT in November 2025; the EUDI Wallet ARF points toward BBS+ as the everlasting-privacy target. The bit ZKPs do not replace is identity proofing itself.
Universities have eighteen months to put a defensible identity stack in production. AI Act high-risk lands 2 August 2026; EUDI Wallet 6 December 2026; AMLR cross-border identity 10 July 2027. The cheapest place to start is admission.
W3C published Verifiable Credentials 2.0 in May 2025; EBSI uses did:ebsi for legal entities and did:key plus DPoP for natural persons. The spec proves the wallet holds a key. It does not prove who holds the wallet. That gap is what 2026 has to close.
Remote proctoring becomes high-risk under Annex III of the EU AI Act on 2 August 2026 — twice over. Deepfake attacks on selfie+ID verification are now industrial. The exam stage needs a different identity primitive than the webcam.
The diploma mill industry runs at roughly $7B/year. EBSI Verifiable Diplomas cryptographically bind a credential to a holder identifier — but the holder identifier itself is still proofed locally. The chain holds at the issuer; it breaks at the person.
On 26 April 2026 the US Department of Education launched real-time identity fraud detection inside the FAFSA. California community colleges flagged 31% of 2024 applications as fraudulent. The architectural answer is upstream proofing, not downstream cleanup.
6.9 million students study cross-border each year (UNESCO 2024). EUDI covers 27 EU states, eduGAIN is web-only with gaps. The biometric passport is the only universal primitive.
EHDS applies from March 2027. Patient summaries and ePrescriptions go cross-border by default. But health professional identity is still verified country by country.
Member States must designate critical entities in 11 sectors by 17.07.2026. CER Articles 13-14 demand personnel security and background checks — including externals.
NERC CIP-003-9 and NIS2 Article 21 both require identity-bound OT vendor access in 2026. Cross-border technician identity is the gap neither framework solves.
Most EU defence tender submissions accept AdES, not QES. EDIP and EDF proposals sign via EU Login on the F&T Portal. Here's what each call really requires.
The EU Cyber Resilience Act makes signed SBOMs mandatory by December 2027. The emerging legal trust anchor is the qualified electronic seal (eSeal) under eIDAS 2.
Belgium's 18 April 2026 NIS2 deadline has passed. Article 21 is now an evidence chain, not a checklist. Where most entities' identity proofing falls short.
The DORA Register deadline closed three weeks ago. Only 6.5% of firms passed all 116 data quality checks in the 2024 dry-run. The gap is the identity chain.
Passkeys and passport chips are both phishing-resistant — but they answer different questions. NIST SP 800-63B-4 has AAL and IAL as independent axes.
Cyber insurance premiums hit $23bn in 2026. 41% of applications are denied on first submission. The underwriting line has moved below MFA into identity proofing.
Belgium's first binding NIS2 deadline is today. Article 21(2)(d) requires supply chain security — and what auditors open first is the supplier register.
The EU AMLR applies 10 July 2027, demanding verifiable identity for every customer. The EUDI Wallet covers 27 EU countries — your non-EU customers need another path.
NIST finalised post-quantum signature standards in 2024. EU set national PQC strategies by 2026. Most eIDAS signatures still use RSA. Seven questions for your TSP.
eBL platforms are interoperable. DCSA carriers are technically ready. So why is adoption stuck at 11%? The missing layer is digital identity of the parties.
AI agents order, approve, and sign across enterprise systems. But only a legal or natural person can hold signing authority — most companies cannot prove the chain.
18.1 million API keys exposed in 2025. Machine identities outnumber humans 100:1. NHI industry secures machines — but humans who created them are unverified.
96% of organisations favour Zero Trust. 84% had identity breaches anyway. The problem: 'never trust, always verify' fails when you can't verify who someone is.
Non-EU drivers carry a material share of EU freight but have no European digital identity. Three methods to verify them — and which one actually works at scale.
15 billion accounts are passkey-enabled. But passkeys prove you have a device, not who you are. For cross-border and high-risk scenarios, that gap matters.
Deepfake fraud attempts surged 2,137% since 2022. Synthetic identities cost $20–40B. But one piece of hardware remains immune — and it's already in your pocket.
From July 2027, every eFTI platform must verify the identity of every business user. Here is what Article 5 actually requires — and why most platforms are not ready.
From July 2027, EU authorities must accept digital freight data. Here's a step-by-step checklist to get your logistics operation ready — starting now.
Many drivers 'sign' eCMR by scribbling on a tablet. Under eIDAS, that's the weakest form of electronic signature — and it may not hold up when it matters.
39 countries have ratified the eCMR protocol. Here's the full list, the EU countries still missing, and what it means for your cross-border freight.
Everything you need to know about the electronic consignment note: what it is, how it works, who needs it, and what's changing in 2026–2027.
40% of enterprise apps feature AI agents by end-2026 (Gartner). Only 23% of organisations have a formal identity strategy. Missing layer: human verification.
The EUDI Wallet is a milestone for Europe — but it leaves non-EU partners, suppliers, and workers without a digital identity. That gap affects your business.
Processing a paper CMR takes 23 minutes; an eCMR takes 9. Real cost: €6.23 vs €1.69 per document. Here are the hard numbers backed by independent research.
eCMR and eFTI require digital signatures — but not the most expensive kind. A practical guide to choosing between AdES and QES for freight documents.
€2.7 billion stolen in three years. 634 incidents in a single month. Average loss per major incident: €878,525. A data briefing on Europe's cargo crime crisis.
Everything logistics leaders need to know about digital identity for freight — from eFTI compliance and signature levels to the non-EU identity gap.