Member States and the European Commission must use, from August 19, 2026, common registers, catalogs, and mechanisms for electronic certificates that confirm official information about a person or an organization. The system is intended for cross-border verification of attributes such as qualifications, professional rights, licenses, or other data stored in public registers and will support the use of European digital identity wallets.
In short, an electronic certificate of attributes confirms verified information about a person or organization, such as a qualification, a license, a right, or an official quality. The Commission must publish a list of public bodies that issue such certificates or in whose name they are issued. A European catalog will describe the attributes, their significance, the data format, and the sources from which they can be verified. Member States must provide electronic points through which qualified providers can verify whether the requested information corresponds to the data in authentic registers. The stage from August 19 creates the common infrastructure but does not guarantee that every citizen will be able to immediately use all certificates in a national digital wallet.
An attribute is a characteristic, a right, or information associated with a natural or legal person. It can be a diploma, professional qualification, age, address, authorization, license, representative status of a company, or other verified information.
An electronic certificate allows the confirmation of this attribute in a digital format that can be presented and verified. The user does not always have to send the complete copy of the diploma, identity card, or certificate from which the information originates.
For example, a person could demonstrate that they hold a certain qualification without having to provide all the written data on their diploma. In another situation, they could demonstrate that they meet an age requirement without having to communicate the complete date of birth, if the service and technical implementation allow for this limited verification.
Certificates will be linked to the ecosystem of the European digital identity wallet. The wallet is designed to allow the user to request, receive, store, and present identities, documents, and electronic attributes.
The rules do not create a single wallet managed centrally by the Commission. Each Member State must provide or recognize solutions compliant with the European framework, and the use remains linked to services implemented at the national level.
From August 19, a stage applies regarding the infrastructure necessary for the recognition and verification of certificates. This includes the list of public providers, the catalog of attributes, the catalog of certification schemes, and the verification points connected to authentic sources.
Authentic sources are registers or official systems in which authorities keep basic information. These may include population, education, profession, company, license registers, or other records designated by national legislation.
Member States must notify the Commission of the public sector bodies that issue electronic certificates or in whose name they are issued. Notification allows users and services to verify whether the issuer is officially recognized.
The Commission must maintain and publish the list of these providers. Presence on the list shows that the body has been notified within the system, but does not mean that any digital claim using its name is authentic.
The authenticity of a certificate must be verified through signatures, seals, certificates, and other technical mechanisms. The system must also allow for the verification of the document's status, including whether it has been revoked.
Revocation may be necessary when the information is no longer valid, the user requests cancellation, the security of the document has been compromised, or legislation requires its withdrawal.
The revocation mechanism must be designed to reduce the possibility of unjustified tracking of the user. Validity verification should not turn into a system where the issuer automatically learns of every service to which the person has presented their certificate.
The European catalog of attributes will describe the information that can be certified. For each attribute, the name, significance, technical identifier, data type, and usage rules can be indicated.
A common name is important for interoperability. If states use incompatible terms and formats for the same qualification or authorization, a service from another country cannot automatically interpret the information.
The catalog does not automatically transform national qualifications into identical qualifications and does not change the rules of professional recognition. It helps information systems understand what information is presented and how it can be verified.
A second catalog will describe certification schemes. A scheme establishes how a certain type of certificate is issued, verified, updated, and governed.
The catalog may include information about the trust model, the responsibilities of participants, the standards used, and the successive versions of the scheme. Registration of schemes is voluntary, under the conditions of the regulation.
Member States must create mechanisms through which qualified trust service providers can verify attributes in authentic sources. Verification can take place directly or through designated intermediaries.
The verification point must be able to confirm whether the presented information corresponds to the data in the official register and identify the source used. Responses must be able to be processed electronically and provided in a timely manner.
Access to registers is not unlimited. States may impose control mechanisms to prevent illegal, excessive, or unrelated requests for the issuance of a certificate requested by the user.
General data protection rules continue to apply. A provider cannot verify any information about a person just because they have technical access to a verification point.
The user must be involved in the request and presentation of the certificate. The processed data must be limited to what is necessary for the specific service.
Qualified certificates are issued by providers that meet strict requirements of the European framework regarding trust services. They benefit from the legal effects and recognition provided by European legislation.
There are also certificates issued by public bodies or in their name, based on authentic registers. Member States must demonstrate that these bodies offer a level of reliability and trust comparable to the relevant requirements.
Technical rules include standards for security, issuer identification, protecting data integrity, and interoperability with digital wallets. These standards aim for a certificate issued in one country to be interpretable and verifiable in another.
The application from August 19 does not mean that any existing diploma, license, or certificate automatically becomes a European electronic certificate. The responsible authority must develop the service, connect the registers, and comply with technical specifications.
Availability will vary between states and between categories of attributes. Some registers are already digitized and interoperable, while others require technical and administrative changes.
Private services are also not obliged to immediately accept any certificate for any transaction. Acceptance obligations depend on the European framework of digital identity, the type of service, and the applicable timeline.
Certificates can reduce the number of document copies sent by email or repeatedly uploaded on platforms. They can allow for automatic verification and the disclosure of a smaller volume of data.
The benefit, however, depends on correct implementation. A poorly configured system could request more information than necessary or create risks of correlating the user's activities.
The stage from August 19 establishes the common tools through which states, providers, and services will be able to build the cross-border exchange of verified attributes. Widespread use will depend on the launch of wallets, the connection of registers, and the development of concrete services.
In short, an electronic certificate of attributes confirms verified information about a person or organization, such as a qualification, a license, a right, or an official quality. The Commission must publish a list of public bodies that issue such certificates or in whose name they are issued. A European catalog will describe the attributes, their significance, the data format, and the sources from which they can be verified. Member States must provide electronic points through which qualified providers can verify whether the requested information corresponds to the data in authentic registers. The stage from August 19 creates the common infrastructure but does not guarantee that every citizen will be able to immediately use all certificates in a national digital wallet.
An attribute is a characteristic, a right, or information associated with a natural or legal person. It can be a diploma, professional qualification, age, address, authorization, license, representative status of a company, or other verified information.
An electronic certificate allows the confirmation of this attribute in a digital format that can be presented and verified. The user does not always have to send the complete copy of the diploma, identity card, or certificate from which the information originates.
For example, a person could demonstrate that they hold a certain qualification without having to provide all the written data on their diploma. In another situation, they could demonstrate that they meet an age requirement without having to communicate the complete date of birth, if the service and technical implementation allow for this limited verification.
Certificates will be linked to the ecosystem of the European digital identity wallet. The wallet is designed to allow the user to request, receive, store, and present identities, documents, and electronic attributes.
The rules do not create a single wallet managed centrally by the Commission. Each Member State must provide or recognize solutions compliant with the European framework, and the use remains linked to services implemented at the national level.
From August 19, a stage applies regarding the infrastructure necessary for the recognition and verification of certificates. This includes the list of public providers, the catalog of attributes, the catalog of certification schemes, and the verification points connected to authentic sources.
Authentic sources are registers or official systems in which authorities keep basic information. These may include population, education, profession, company, license registers, or other records designated by national legislation.
Member States must notify the Commission of the public sector bodies that issue electronic certificates or in whose name they are issued. Notification allows users and services to verify whether the issuer is officially recognized.
The Commission must maintain and publish the list of these providers. Presence on the list shows that the body has been notified within the system, but does not mean that any digital claim using its name is authentic.
The authenticity of a certificate must be verified through signatures, seals, certificates, and other technical mechanisms. The system must also allow for the verification of the document's status, including whether it has been revoked.
Revocation may be necessary when the information is no longer valid, the user requests cancellation, the security of the document has been compromised, or legislation requires its withdrawal.
The revocation mechanism must be designed to reduce the possibility of unjustified tracking of the user. Validity verification should not turn into a system where the issuer automatically learns of every service to which the person has presented their certificate.
The European catalog of attributes will describe the information that can be certified. For each attribute, the name, significance, technical identifier, data type, and usage rules can be indicated.
A common name is important for interoperability. If states use incompatible terms and formats for the same qualification or authorization, a service from another country cannot automatically interpret the information.
The catalog does not automatically transform national qualifications into identical qualifications and does not change the rules of professional recognition. It helps information systems understand what information is presented and how it can be verified.
A second catalog will describe certification schemes. A scheme establishes how a certain type of certificate is issued, verified, updated, and governed.
The catalog may include information about the trust model, the responsibilities of participants, the standards used, and the successive versions of the scheme. Registration of schemes is voluntary, under the conditions of the regulation.
Member States must create mechanisms through which qualified trust service providers can verify attributes in authentic sources. Verification can take place directly or through designated intermediaries.
The verification point must be able to confirm whether the presented information corresponds to the data in the official register and identify the source used. Responses must be able to be processed electronically and provided in a timely manner.
Access to registers is not unlimited. States may impose control mechanisms to prevent illegal, excessive, or unrelated requests for the issuance of a certificate requested by the user.
General data protection rules continue to apply. A provider cannot verify any information about a person just because they have technical access to a verification point.
The user must be involved in the request and presentation of the certificate. The processed data must be limited to what is necessary for the specific service.
Qualified certificates are issued by providers that meet strict requirements of the European framework regarding trust services. They benefit from the legal effects and recognition provided by European legislation.
There are also certificates issued by public bodies or in their name, based on authentic registers. Member States must demonstrate that these bodies offer a level of reliability and trust comparable to the relevant requirements.
Technical rules include standards for security, issuer identification, protecting data integrity, and interoperability with digital wallets. These standards aim for a certificate issued in one country to be interpretable and verifiable in another.
The application from August 19 does not mean that any existing diploma, license, or certificate automatically becomes a European electronic certificate. The responsible authority must develop the service, connect the registers, and comply with technical specifications.
Availability will vary between states and between categories of attributes. Some registers are already digitized and interoperable, while others require technical and administrative changes.
Private services are also not obliged to immediately accept any certificate for any transaction. Acceptance obligations depend on the European framework of digital identity, the type of service, and the applicable timeline.
Certificates can reduce the number of document copies sent by email or repeatedly uploaded on platforms. They can allow for automatic verification and the disclosure of a smaller volume of data.
The benefit, however, depends on correct implementation. A poorly configured system could request more information than necessary or create risks of correlating the user's activities.
The stage from August 19 establishes the common tools through which states, providers, and services will be able to build the cross-border exchange of verified attributes. Widespread use will depend on the launch of wallets, the connection of registers, and the development of concrete services.
Latest News
11:59
Senator Petrișor Peiu accuses the government led by Ilie Bolojan of wasting public money by contracting private firms to draft a biodiversity strategy.
11:45
The Spanish government has decided to restore border controls with Italy, after the Italian authorities refused to abandon checks on travelers from Spain.
11:30
The Danube's flow at the entrance into the country is 1,400 m³/s, a historic low, and it will remain at this value until August 12.
11:25
IT News Review by Control F5 Software: EU considers it necessary to monitor high-risk AI systems
11:18
Trump denounces the appeals court's decision to suspend work on the White House, considering it a threat to national security.
See more news