EDIH, EEN, Interreg: the platform for European programmes.Find out more

eIDAS maturity · Protection and management of citizens’ digital identities

Your digital identity management, mapped against eIDAS and turned into a costed action plan.

10 themes, a 5-level scale. And the action that moves each level to the next.

The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.

eIDAS maturity · Protection and management of citizens’ digital identities

Digital identity governanceN1 → N5
Electronic identification and levels of assuranceN1 → N5
Enrolment and identity verificationN1 → N5
Authentication and lifecycle managementN1 → N5

10 themes, 5-level scale.

Nordhavn Industries

53 / 100

Digital identity governance6484
Electronic identification and levels of assurance5379
Enrolment and identity verification6182
Authentication and lifecycle management3773
IAIndustrialised: your interview notes are enough, the AI fills in the audit.

They measure their maturity with Datamensio

  • CNES
  • Docaposte
  • ANITI
  • Pôle SCS
  • Cetim
  • Cap'Tronic

An example

This could be your situation.

Take one company as an example: three sites, three spreadsheets, no shared answer.

01

Nobody can consolidate.

Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.

02

Three weeks, a single base.

One Regulation (EU) No 910/2014 (eIDAS), revised by Regulation (EU) 2024/1183 (eIDAS 2) assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.

03

Two costs avoided before being committed.

A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.

What it saved them

  • 3sites measured on the same base, instead of three questionnaires to reconcile
  • 2duplicate actions caught before the spend
  • 1committee report, with no manual rework

These figures are an example. They could be yours.

The standard imposes processes. Datamensio says where you stand.

01

The framework is already written

Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.

02

The score lands the same day

Online, by self-assessment link or in interview. Theme by theme, comparable over time.

03

The gap becomes a costed plan

Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.

04

Progress can be demonstrated

Campaign after campaign, against your target and against your own past. That is what your board asks for.

The maturity scale

One level, the next, and the action that links the two.

It is this mechanism (one level, a higher level, and the action that connects them) that turns an observation into a trajectory.

Is the assurance level required for access to each online service defined and applied?

  1. N1

    No classification of online services by assurance level. The identification means chosen depends on the project and its integrator.

  2. N2

    Some online services are classified in a reference document, but the classification is not carried through into projects and coexists with legacy practices.

  3. N3

    Each online service is mapped to a low, substantial or high level, based on documented analysis. The classification is applied at go live, with occasional exceptions.

  4. N4

    The classification systematically drives the identity provider’s configuration. Gaps are detected automatically and logged, exceptions approved at the appropriate management level.

  5. N5

    The classification is reviewed periodically in line with usage changes, incidents and regulatory developments, with a history of revisions and a measure of the effect on journey completion rates.

Action to move from L2 to L3

Complete the mapping of online services with the required assurance level and its rationale, make it a blocking criterion in architecture reviews, and check its application at the quarterly digital committee.

« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »
Chambre de commerce et d'industrie

Director, CCI 94CCI Île-de-France

« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »
Interreg Danube Region

Maja SucekChief Operating Officer, Interreg Danube

Take your first measurementon eIDAS.

What this framework covers

Regulation (EU) No 910/2014, known as eIDAS, organises the mutual recognition of electronic identification means between Member States and governs five families of trust services: electronic signature, electronic seal, timestamp, electronic registered delivery service, and website authentication certificate. It defines three levels of assurance for identification (low, substantial, high) and separates qualified trust service providers from non-qualified ones, the former being supervised and listed on national trusted lists. For a public administration or a company exposing online services to citizens, eIDAS determines who can access what, at what level of proof, and what legal value results from it.

In practice, this topic is hard to govern because it cuts across several departments. IT owns identity federation, legal owns evidential value, the customer service department owns the enrolment journey, security owns authentication. The same practical questions keep coming up: what assurance level does each of your online services actually require, and what analysis backs that requirement? Do your user journeys accept identification means notified by other Member States, or only your own? Are your signatures advanced, qualified, or simply electronic in the broadest sense, and can you tell them apart across your workflows?

The revision that came into force in 2024 changes the scale of the topic. Regulation (EU) 2024/1183 requires every Member State to offer at least one European Digital Identity Wallet, and obliges a wide range of public and private actors to accept it for user authentication. It introduces electronic attestation of attributes, which allows proof of a qualification, an age, or a professional status without disclosing the rest of one’s identity. The most common confusion is reducing eIDAS to electronic signature. The identification component, long overlooked, is now central and concerns the access journeys themselves.

A compliance audit asks a binary question: does the service meet the requirement, yes or no. A maturity assessment asks a different question: at what level of control does the practice sit, and what specific action moves it to the next level. Between an organisation that accepts a cross-border identification means case by case and one that has built it into its authentication baseline, the gap is not a compliance gap, it is a maturity gap. The assessment makes it visible, theme by theme, and costs the effort required.

Within Datamensio, this framework is ready to use and fully editable. The AI adjusts the themes, rephrases the questions in your organisation’s vocabulary and refines the levels using the CMMI method. It can also build a custom version from your own documents: authentication policy, mapping of online services, digital identity doctrine. The resulting framework remains yours, ready to publish across your business units or entities.

Reference standard: Regulation (EU) No 910/2014 (eIDAS), revised by Regulation (EU) 2024/1183 (eIDAS 2)

The themes assessed

  • Digital identity governance

    Formalised doctrine, appointed owner, coordination between IT, security, legal and business teams, arbitration of assurance levels, dedicated budget.

  • Electronic identification and levels of assurance

    Classification of online services by low, substantial or high level, justification of the choice, compliance with Implementing Regulation 2015/1502, periodic review.

  • Enrolment and identity verification

    Remote and in-person verification procedures, accepted proof of identity, detection of document fraud, traceability of enrolment.

  • Authentication and lifecycle management

    Multi-factor authentication mechanisms, access rights management, suspension, revocation and renewal of credentials, management of delegations and mandates.

  • Cross-border interoperability

    Acceptance of identification means notified by other Member States, connection to the eIDAS node, attribute mapping, handling of matching failures.

  • European Digital Identity Wallet

    Preparation for wallet acceptance, electronic attestations of attributes, user consent management, registration of relying parties.

  • Trust services

    Use of signature, seal, timestamp, electronic registered delivery and website authentication certificates, choice between qualified and non-qualified, checking trusted lists.

  • Evidential value and retention

    Signature policy, validation and revalidation of signatures over time, archiving with evidential value, ability to produce evidence in case of dispute.

  • Data protection and minimisation

    Coordination with GDPR, minimisation of attributes transmitted, information to data subjects, retention periods, handling of rights requests.

  • Monitoring, incidents and improvement

    Tracking indicators, logging, detection and notification of incidents and breaches, regular testing of journeys, lessons learned and doctrine updates.

A short version of the framework is available for the online self-assessment.

Frequently asked questions

Is eIDAS certifiable?

The regulation does not certify organisations that use trust services. It provides for qualification of trust service providers, granted after audit by a conformity assessment body and listing on the national trusted list. The Datamensio assessment measures the maturity of your practices and prepares for these discussions, it does not grant any qualification.

What is the difference between this assessment and a compliance audit?

An audit concludes with a gap or compliance finding against a given requirement. The assessment places each practice on a progressive scale and indicates the action that moves it to the next level. The two are complementary: the assessment builds the trajectory, the audit validates the outcome.

How long does the assessment take?

The short version can be completed in a single working session. The full version, in collaborative mode, runs over one to two weeks: most of the time goes into gathering input from IT, legal and business teams. Timing depends on contributor availability.

Can the framework be adapted to our context?

Yes. Questions, levels and themes can be edited, and you can add your own. The AI rephrases the content in your organisation’s vocabulary or builds a custom version from your internal documents. The published framework remains under your control.

Does the assessment cover the eIDAS 2 revision and the European wallet?

Yes, one theme specifically addresses preparation for accepting the European Digital Identity Wallet and electronic attestations of attributes. The questions distinguish what belongs to the existing baseline from what relates to compliance with Regulation (EU) 2024/1183.

Do respondents need technical expertise?

The questions focus on management practices, not protocol configurations. A digital project manager or an internal auditor can answer most of them. Collaborative mode allows technical questions to be assigned to a named contact.

How can several entities be compared with each other?

The same framework is rolled out to each business unit or entity, and results are compared theme by theme. A cross-entity roadmap then consolidates the action plans without duplicating shared workstreams, such as connecting to the eIDAS node.

Where is the data hosted?

In France, with OVH, backed up with Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European providers.

Take your first measurementon eIDAS.