eIDAS maturity · Protection and management of citizens’ digital identities
Your digital identity management, mapped against eIDAS and turned into a costed action plan.
10 themes, a 5-level scale. And the action that moves each level to the next.
The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.
eIDAS maturity · Protection and management of citizens’ digital identities
10 themes, 5-level scale.
Nordhavn Industries
53 / 100
They measure their maturity with Datamensio
An example
This could be your situation.
Take one company as an example: three sites, three spreadsheets, no shared answer.
Nobody can consolidate.
Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.
Three weeks, a single base.
One Regulation (EU) No 910/2014 (eIDAS), revised by Regulation (EU) 2024/1183 (eIDAS 2) assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.
Two costs avoided before being committed.
A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.
What it saved them
- 3sites measured on the same base, instead of three questionnaires to reconcile
- 2duplicate actions caught before the spend
- 1committee report, with no manual rework
These figures are an example. They could be yours.
The standard imposes processes. Datamensio says where you stand.
01
The framework is already written
Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.
02
The score lands the same day
Online, by self-assessment link or in interview. Theme by theme, comparable over time.
03
The gap becomes a costed plan
Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.
04
Progress can be demonstrated
Campaign after campaign, against your target and against your own past. That is what your board asks for.
The maturity scale
One level, the next, and the action that links the two.
It is this mechanism (one level, a higher level, and the action that connects them) that turns an observation into a trajectory.
Is the assurance level required for access to each online service defined and applied?
- N1
No classification of online services by assurance level. The identification means chosen depends on the project and its integrator.
- N2
Some online services are classified in a reference document, but the classification is not carried through into projects and coexists with legacy practices.
- N3
Each online service is mapped to a low, substantial or high level, based on documented analysis. The classification is applied at go live, with occasional exceptions.
- N4
The classification systematically drives the identity provider’s configuration. Gaps are detected automatically and logged, exceptions approved at the appropriate management level.
- N5
The classification is reviewed periodically in line with usage changes, incidents and regulatory developments, with a history of revisions and a measure of the effect on journey completion rates.
Action to move from L2 to L3
Complete the mapping of online services with the required assurance level and its rationale, make it a blocking criterion in architecture reviews, and check its application at the quarterly digital committee.
« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »

Director, CCI 94CCI Île-de-France
« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »

Maja SucekChief Operating Officer, Interreg Danube
Rarely on its own
Frameworks combine. Put several together to cover your business, or have the AI write yours.
Take your first measurementon eIDAS.
What this framework covers
Regulation (EU) No 910/2014, known as eIDAS, organises the mutual recognition of electronic identification means between Member States and governs five families of trust services: electronic signature, electronic seal, timestamp, electronic registered delivery service, and website authentication certificate. It defines three levels of assurance for identification (low, substantial, high) and separates qualified trust service providers from non-qualified ones, the former being supervised and listed on national trusted lists. For a public administration or a company exposing online services to citizens, eIDAS determines who can access what, at what level of proof, and what legal value results from it.
In practice, this topic is hard to govern because it cuts across several departments. IT owns identity federation, legal owns evidential value, the customer service department owns the enrolment journey, security owns authentication. The same practical questions keep coming up: what assurance level does each of your online services actually require, and what analysis backs that requirement? Do your user journeys accept identification means notified by other Member States, or only your own? Are your signatures advanced, qualified, or simply electronic in the broadest sense, and can you tell them apart across your workflows?
The revision that came into force in 2024 changes the scale of the topic. Regulation (EU) 2024/1183 requires every Member State to offer at least one European Digital Identity Wallet, and obliges a wide range of public and private actors to accept it for user authentication. It introduces electronic attestation of attributes, which allows proof of a qualification, an age, or a professional status without disclosing the rest of one’s identity. The most common confusion is reducing eIDAS to electronic signature. The identification component, long overlooked, is now central and concerns the access journeys themselves.
A compliance audit asks a binary question: does the service meet the requirement, yes or no. A maturity assessment asks a different question: at what level of control does the practice sit, and what specific action moves it to the next level. Between an organisation that accepts a cross-border identification means case by case and one that has built it into its authentication baseline, the gap is not a compliance gap, it is a maturity gap. The assessment makes it visible, theme by theme, and costs the effort required.
Within Datamensio, this framework is ready to use and fully editable. The AI adjusts the themes, rephrases the questions in your organisation’s vocabulary and refines the levels using the CMMI method. It can also build a custom version from your own documents: authentication policy, mapping of online services, digital identity doctrine. The resulting framework remains yours, ready to publish across your business units or entities.
Reference standard: Regulation (EU) No 910/2014 (eIDAS), revised by Regulation (EU) 2024/1183 (eIDAS 2)
The themes assessed
Digital identity governance
Formalised doctrine, appointed owner, coordination between IT, security, legal and business teams, arbitration of assurance levels, dedicated budget.
Electronic identification and levels of assurance
Classification of online services by low, substantial or high level, justification of the choice, compliance with Implementing Regulation 2015/1502, periodic review.
Enrolment and identity verification
Remote and in-person verification procedures, accepted proof of identity, detection of document fraud, traceability of enrolment.
Authentication and lifecycle management
Multi-factor authentication mechanisms, access rights management, suspension, revocation and renewal of credentials, management of delegations and mandates.
Cross-border interoperability
Acceptance of identification means notified by other Member States, connection to the eIDAS node, attribute mapping, handling of matching failures.
European Digital Identity Wallet
Preparation for wallet acceptance, electronic attestations of attributes, user consent management, registration of relying parties.
Trust services
Use of signature, seal, timestamp, electronic registered delivery and website authentication certificates, choice between qualified and non-qualified, checking trusted lists.
Evidential value and retention
Signature policy, validation and revalidation of signatures over time, archiving with evidential value, ability to produce evidence in case of dispute.
Data protection and minimisation
Coordination with GDPR, minimisation of attributes transmitted, information to data subjects, retention periods, handling of rights requests.
Monitoring, incidents and improvement
Tracking indicators, logging, detection and notification of incidents and breaches, regular testing of journeys, lessons learned and doctrine updates.
A short version of the framework is available for the online self-assessment.
Frequently asked questions
Is eIDAS certifiable?
The regulation does not certify organisations that use trust services. It provides for qualification of trust service providers, granted after audit by a conformity assessment body and listing on the national trusted list. The Datamensio assessment measures the maturity of your practices and prepares for these discussions, it does not grant any qualification.
What is the difference between this assessment and a compliance audit?
An audit concludes with a gap or compliance finding against a given requirement. The assessment places each practice on a progressive scale and indicates the action that moves it to the next level. The two are complementary: the assessment builds the trajectory, the audit validates the outcome.
How long does the assessment take?
The short version can be completed in a single working session. The full version, in collaborative mode, runs over one to two weeks: most of the time goes into gathering input from IT, legal and business teams. Timing depends on contributor availability.
Can the framework be adapted to our context?
Yes. Questions, levels and themes can be edited, and you can add your own. The AI rephrases the content in your organisation’s vocabulary or builds a custom version from your internal documents. The published framework remains under your control.
Does the assessment cover the eIDAS 2 revision and the European wallet?
Yes, one theme specifically addresses preparation for accepting the European Digital Identity Wallet and electronic attestations of attributes. The questions distinguish what belongs to the existing baseline from what relates to compliance with Regulation (EU) 2024/1183.
Do respondents need technical expertise?
The questions focus on management practices, not protocol configurations. A digital project manager or an internal auditor can answer most of them. Collaborative mode allows technical questions to be assigned to a named contact.
How can several entities be compared with each other?
The same framework is rolled out to each business unit or entity, and results are compared theme by theme. A cross-entity roadmap then consolidates the action plans without duplicating shared workstreams, such as connecting to the eIDAS node.
Where is the data hosted?
In France, with OVH, backed up with Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European providers.





