eIDAS and ISMS together
ISO 27001 does not cover eIDAS directly, but provides the frame for PKI management, access control, logging, supplier management and incident response that eIDAS implementations need. Map Annex A controls to wallet, QES and QTSP processes in your SoA.
Evidence for audits
Show certificate lifecycle, key ceremonies (or cloud HSM configuration), access reviews on signing platforms and incident registration for trust service abuse or outage. Certification bodies sample operation — not policy alone.
One register
Combine eIDAS vendors, trust services and security vendors in one tiering model. Tag what is eIDAS-specific versus general ISO controls to avoid duplicate documentation.
Checklist
- Inventory eID, QES and QTSP use
- Map vendors and trust list status
- Link to ISMS, GDPR and risk register
- Plan DPIA where wallet or identity data
- Test fallback and incident scenarios
Practical next step
For eIDAS 2.0 ISO 27001, ISO Ready links identity, trust and security measures in one ISMS — with actions, evidence and vendors toward audit. Run the readiness scan on iso-ready.nl.
More on eIDAS 2.0
- Eidas2 Compliance
- Iso 27001 Certificering
- Isms Opzetten
- Qualified Trust Services Eidas2
- Iso 27701 Privacy Management
- Dora Compliance