Trust Service Providers
Verifiable trust infrastructure for trust service providers
Trust service providers carry identity assurance into an ecosystem still under construction: EU Digital Identity Wallets legally due by December 2026, qualified attestations of attributes under implementing acts revised in July 2026, and recognition that must hold across every member state. Authentication infrastructure that operates across organisational boundaries is what makes that assurance travel.
Discuss trust service infrastructureTrust service providers face three converging mandates: the eIDAS 2.0 obligation on every member state to provide a wallet by 24 December 2026, qualified attestations of attributes governed by implementing acts adopted in July 2025 and amended in July 2026, and cross-border recognition resting on certification schemes that are still being settled. Each demands that identity assurance survives the boundary between the party that issued it and the party relying on it. The architectural approach proven in Swiss healthcare applies directly to attestation issuance, relying party authentication, and certificate lifecycle operations.
Regulatory drivers
eIDAS 2.0 and the EUDI Wallet
Regulation (EU) 2024/1183 obliges every member state to provide at least one European Digital Identity Wallet, with the deadline falling 24 months after the first implementing acts entered into force on 24 December 2024.
Wallet deadline 24 December 2026: eIDAS Article 5a(1) plus 24 months
Qualified attestations of attributes
Commission Implementing Regulation 2025/1569 sets the requirements for qualified and public sector attestations of attributes, citing ETSI EN 319 401, and was amended by CIR 2026/1735 in July 2026 for attestation verification standards.
QEAA requirements adopted 29 July 2025, CIR 2025/1569
Certification and cross-border recognition
Wallet certification runs through conformity assessment bodies designated by member states, with national schemes applying where no EU scheme is in place. ENISA put a draft candidate EU scheme to public review in April 2026, and it is not yet adopted.
ENISA candidate certification scheme in public review, not adopted (April 2026)
Solution overview
Verifiable trust infrastructure for trust service providers means every attestation, signature, and relying party request carries cryptographic proof of origin, integrity, and authorisation. Decentralized Key Management puts the certificate authority function at the edge: each organisation holds its own key history, and any counterparty verifies it directly. X.509 and JWT bridges are designed to keep that identity layer interoperable with the certificate infrastructure already deployed.
See how it works →Proven at scale
Healthcare proved the architecture at scale. HIN operates Switzerland's health information network, where SEAL handles over 800,000 verified deliveries per month and the Verimesh gateway and central CA run in production, with the first customers migrated and using them. The same gateway and certificate authority architecture applies to trust service operations: organisational boundary trust, certificate lifecycle integrity, and cryptographic evidence of what was issued, to whom, and under which key.
Swiss healthcare and the European trust services market share one requirement: assurance issued by one organisation must be verifiable by another that shares no infrastructure with it. HIN operates that boundary every day, at national scale.
How to engage
Work with Vereign directly
For organisations that want to scope and deploy trust infrastructure with Vereign's engineering and advisory team. Ideal for first movers and organisations with in-house technical capacity.
Explore services →Work through a partner
For organisations that prefer to work with a consultancy already trained on Vereign's trust infrastructure. Partners provide sector expertise alongside deployment capability.
See the partner programme →Team voices
Trust service providers are being asked to guarantee identity across borders while the framework underneath them is still being written. We designed this architecture so the trust root stays with the organisation that owns it, and the assurance still travels across every boundary it has to cross.
Scope an authentication infrastructure deployment for trust service operations
Whether you are preparing to issue attestations into the wallet ecosystem or planning how your assurance holds up across borders, we can help you define the right trust architecture for your organisation.