This document is an excerpt from the EUR-Lex website
Document 32015R1502
Commission Implementing Regulation (EU) 2015/1502 of 8 September 2015 on setting out minimum technical specifications and procedures for assurance levels for electronic identification means pursuant to Article 8(3) of Regulation (EU) No 910/2014 of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market (Text with EEA relevance)
Commission Implementing Regulation (EU) 2015/1502 of 8 September 2015 on setting out minimum technical specifications and procedures for assurance levels for electronic identification means pursuant to Article 8(3) of Regulation (EU) No 910/2014 of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market (Text with EEA relevance)
Commission Implementing Regulation (EU) 2015/1502 of 8 September 2015 on setting out minimum technical specifications and procedures for assurance levels for electronic identification means pursuant to Article 8(3) of Regulation (EU) No 910/2014 of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market (Text with EEA relevance)
OJ L 235, 9.9.2015, p. 7–20
(BG, ES, CS, DA, DE, ET, EL, EN, FR, HR, IT, LV, LT, HU, MT, NL, PL, PT, RO, SK, SL, FI, SV)
In force: This act has been changed. Current consolidated version: 11/07/2022
9.9.2015 |
EN |
Official Journal of the European Union |
L 235/7 |
COMMISSION IMPLEMENTING REGULATION (EU) 2015/1502
of 8 September 2015
on setting out minimum technical specifications and procedures for assurance levels for electronic identification means pursuant to Article 8(3) of Regulation (EU) No 910/2014 of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market
(Text with EEA relevance)
THE EUROPEAN COMMISSION,
Having regard to the Treaty on the Functioning of the European Union,
Having regard to Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC (1), and in particular Article 8(3) thereof,
Whereas:
(1) |
Article 8 of Regulation (EU) No 910/2014 provides that an electronic identification scheme notified pursuant to Article 9(1) needs to specify assurance levels low, substantial and high for electronic identification means issued under that scheme. |
(2) |
Determining the minimum technical specifications, standards and procedures is essential in order to ensure common understanding of the details of the assurance levels and to ensure interoperability when mapping the national assurance levels of notified electronic identification schemes against the assurance levels under Article 8 as provided by Article 12(4)(b) of Regulation (EU) No 910/2014. |
(3) |
International standard ISO/IEC 29115 has been taken into account for the specifications and procedures set out in this implementing act as being the principle international standard available in the domain of assurance levels for electronic identification means. However, the content of Regulation (EU) No 910/2014 differs from that international standard, in particular in relation to identity proofing and verification requirements, as well as to the way in which the differences between Member State identity arrangements and the existing tools in the EU for the same purpose are taken into account. Therefore the Annex, while building on this international standard should not make reference to any specific content of ISO/IEC 29115. |
(4) |
This Regulation has been developed as an outcome based approach as being the most appropriate which is also reflected in the definitions used to specify the terms and concepts. They take into account the aim of Regulation (EU) No 910/2014 in relation to assurance levels of the electronic identification means. Therefore, the Large-Scale Pilot STORK, including specifications developed by it, and the definitions and concepts in ISO/IEC 29115 should be taken into the utmost account when establishing the specifications and procedures set out in this implementing act. |
(5) |
Depending on the context in which an aspect of evidence of identity needs to be verified, authoritative sources can take many forms, such as registries, documents, bodies inter alia. Authoritative sources may be different in the various Member States even in a similar context. |
(6) |
Requirements for identity proofing and verification should take into account different systems and practices, while ensuring sufficiently high assurance in order to establish the necessary trust. Therefore, acceptance of procedures used previously for a purpose other than the issuance of electronic identification means should be made conditional upon confirmation that those procedures fulfil the requirements foreseen for the corresponding assurance level. |
(7) |
Certain authentication factors such as shared secrets, physical devices and physical attributes are usually employed. However, the usage of a greater number of authentication factors, especially from different factor categories, should be encouraged to increase the security of the authentication process. |
(8) |
This Regulation should not affect representation rights of legal persons. However, the Annex should provide for requirements for the binding between the electronic identification means of natural and legal persons. |
(9) |
The importance of information security and service management systems should be recognised, as should be the importance of employing recognised methodologies and applying the principles embedded in standards such as the ISO/IEC 27000 and the ISO/IEC 20000 series. |
(10) |
Good practices in relation to assurance levels in the Member States should also be taken into account. |
(11) |
IT security certification based on international standards is an important tool for verifying the security compliance of products with the requirements of this implementing act. |
(12) |
The Committee referred to in Article 48 of Regulation (EU) No 910/2014 has not delivered an opinion within the time limit laid down by its chair, |
HAS ADOPTED THIS REGULATION:
Article 1
1. Assurance levels low, substantial and high for electronic identification means issued under a notified electronic identification scheme shall be determined with reference to the specifications and procedures set out in the Annex.
2. The specifications and procedures set out in the Annex shall be used to specify the assurance level of the electronic identification means issued under a notified electronic identification scheme by determining the reliability and quality of following elements:
(a) |
enrolment, as set out in section 2.1 of the Annex to this Regulation pursuant to Article 8(3)(a) of Regulation (EU) No 910/2014; |
(b) |
electronic identification means management, as set out in section 2.2 of the Annex to this Regulation pursuant to Article 8(3)(b) and (f) of Regulation (EU) No 910/2014; |
(c) |
authentication, as set out in section 2.3 of the Annex to this Regulation pursuant to Article 8(3)(c) of Regulation (EU) No 910/2014; |
(d) |
management and organisation, as set out in section 2.4 of the Annex to this Regulation pursuant to Article 8(3)(d) and (e) of Regulation (EU) No 910/2014. |
3. When the electronic identification means issued under a notified electronic identification scheme meets a requirement listed in a higher assurance level then it shall be presumed to fulfil the equivalent requirement of a lower assurance level.
4. Unless otherwise stated in the relevant part of the Annex, all elements listed in the Annex for a particular assurance level of the electronic identification means issued under a notified electronic identification scheme shall be met in order to match the claimed assurance level.
Article 2
This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
This Regulation shall be binding in its entirety and directly applicable in all Member States.
Done at Brussels, 8 September 2015.
For the Commission
The President
Jean-Claude JUNCKER
ANNEX
Technical specifications and procedures for assurance levels low, substantial and high for electronic identification means issued under a notified electronic identification scheme
1. Applicable definitions
For the purposes of this Annex, the following definitions shall apply:
(1) |
‘authoritative source’ means any source irrespective of its form that can be relied upon to provide accurate data, information and/or evidence that can be used to prove identity; |
(2) |
‘authentication factor’ means a factor confirmed as being bound to a person, which falls into any of the following categories:
|
(3) |
‘dynamic authentication’ means an electronic process using cryptography or other techniques to provide a means of creating on demand an electronic proof that the subject is in control or in possession of the identification data and which changes with each authentication between the subject and the system verifying the subject's identity; |
(4) |
‘information security management system’ means a set of processes and procedures designed to manage to acceptable levels risks related to information security. |
2. Technical specifications and procedures
The elements of technical specifications and procedures outlined in this Annex shall be used to determine how the requirements and criteria of Article 8 of Regulation (EU) No 910/2014 shall be applied for electronic identification means issued under an electronic identification scheme.
2.1. Enrolment
2.1.1.
Assurance level |
Elements needed |
||||||
Low |
|
||||||
Substantial |
Same as level low. |
||||||
High |
Same as level low. |
2.1.2.
Assurance level |
Elements needed |
||||||||||
Low |
|
||||||||||
Substantial |
Level low, plus one of the alternatives listed in points 1 to 4 has to be met:
|
||||||||||
High |
Requirements of either point 1 or 2 have to be met:
|
2.1.3.
Assurance level |
Elements Needed |
||||||
Low |
|
||||||
Substantial |
Level low, plus one of the alternatives listed in points 1 to 3 has to be met:
|
||||||
High |
Level substantial, plus one of the alternatives listed in points 1 to 3 has to be met:
|
2.1.4.
Where applicable, for binding between the electronic identification means of a natural person and the electronic identification means of a legal person (‘binding’) the following conditions apply:
(1) |
It shall be possible to suspend and/or revoke a binding. The life-cycle of a binding (e.g. activation, suspension, renewal, revocation) shall be administered according to nationally recognised procedures. |
(2) |
The natural person whose electronic identification means is bound to the electronic identification means of the legal person may delegate the exercise of the binding to another natural person on the basis of nationally recognised procedures. However, the delegating natural person shall remain accountable. |
(3) |
Binding shall be done in the following manner:
|
2.2. Electronic identification means management
2.2.1.
Assurance level |
Elements needed |
||||
Low |
|
||||
Substantial |
|
||||
High |
Level substantial, plus:
|
2.2.2.
Assurance level |
Elements needed |
Low |
After issuance, the electronic identification means is delivered via a mechanism by which it can be assumed to reach only the intended person. |
Substantial |
After issuance, the electronic identification means is delivered via a mechanism by which it can be assumed that it is delivered only into the possession of the person to whom it belongs. |
High |
The activation process verifies that the electronic identification means was delivered only into the possession of the person to whom it belongs. |
2.2.3.
Assurance level |
Elements needed |
||||||
Low |
|
||||||
Substantial |
Same as level low. |
||||||
High |
Same as level low. |
2.2.4.
Assurance level |
Elements needed |
Low |
Taking into account the risks of a change in the person identification data, renewal or replacement needs to meet the same assurance requirements as initial identity proofing and verification or is based on a valid electronic identification means of the same, or higher, assurance level. |
Substantial |
Same as level low. |
High |
Level low, plus: Where renewal or replacement is based on a valid electronic identification means, the identity data is verified with an authoritative source. |
2.3. Authentication
This section focuses on the threats associated with the use of the authentication mechanism and lists the requirements for each assurance level. In this section controls shall be understood to be commensurate to the risks at the given level.
2.3.1.
The following table sets out the requirements per assurance level with respect to the authentication mechanism, through which the natural or legal person uses the electronic identification means to confirm its identity to a relying party.
Assurance level |
Elements needed |
||||||
Low |
|
||||||
Substantial |
Level low, plus:
|
||||||
High |
Level substantial, plus: The authentication mechanism implements security controls for the verification of the electronic identification means, so that it is highly unlikely that activities such as guessing, eavesdropping, replay or manipulation of communication by an attacker with high attack potential can subvert the authentication mechanisms. |
2.4. Management and organisation
All participants providing a service related to electronic identification in a cross-border context (‘providers’) shall have in place documented information security management practices, policies, approaches to risk management, and other recognised controls so as to provide assurance to the appropriate governance bodies for electronic identification schemes in the respective Member States that effective practices are in place. Throughout section 2.4, all requirements/elements shall be understood as commensurate to the risks at the given level.
2.4.1.
Assurance level |
Elements needed |
||||||||||
Low |
|
||||||||||
Substantial |
Same as level low. |
||||||||||
High |
Same as level low. |
2.4.2.
Assurance level |
Elements needed |
||||||
Low |
|
||||||
Substantial |
Same as level low. |
||||||
High |
Same as level low. |
2.4.3.
Assurance level |
Elements needed |
Low |
There is an effective information security management system for the management and control of information security risks. |
Substantial |
Level low, plus: The information security management system adheres to proven standards or principles for the management and control of information security risks. |
High |
Same as level substantial. |
2.4.4.
Assurance level |
Elements needed |
||||
Low |
|
||||
Substantial |
Same as level low. |
||||
High |
Same as level low. |
2.4.5.
The following table represents the requirements with respect to facilities and staff and subcontractors, if applicable, who undertake duties covered by this Regulation. Compliance with each of the requirements shall be proportionate to the level of risk associated with the assurance level provided.
Assurance level |
Elements needed |
||||||||
Low |
|
||||||||
Substantial |
Same as level low. |
||||||||
High |
Same as level low. |
2.4.6.
Assurance level |
Elements needed |
||||||||||
Low |
|
||||||||||
Substantial |
Same as level low, plus: Sensitive cryptographic material, if used for issuing electronic identification means and authentication is protected from tampering |
||||||||||
High |
Same as level substantial. |
2.4.7.
Assurance level |
Elements needed |
||||
Low |
The existence of periodical internal audits scoped to include all parts relevant to the supply of the provided services to ensure compliance with relevant policy. |
||||
Substantial |
The existence of periodical independent internal or external audits scoped to include all parts relevant to the supply of the provided services to ensure compliance with relevant policy. |
||||
High |
|
(1) Regulation (EC) No 765/2008 of the European Parliament and of the Council of 9 July 2008 setting out the requirements for accreditation and market surveillance relating to the marketing of products and repealing Regulation (EEC) No 339/93 (OJ L 218, 13.8.2008, p. 30).