Preparation
This checklist structures eIDAS 2.0 readiness before wallet, QES or QTSP programmes. Use alongside ISO 27001 gap analysis — not as legal advice replacement.
Technology and processes
Check: vendor trust list, certificate lifecycle, logging on signing events, fallback processes, API security for wallet integration, and incident playbooks for identity abuse.
Organisation
Assign owner (CISO/DPO/product), update SoA and processing record, plan vendor review and management review decision on residual risk for new trust services.
Checklist
- Scope: wallet, QES, QTSP or customer?
- Trust list and contracts checked
- SoA + processing record updated
- Logging and key lifecycle documented
- Management review on residual risk
Practical next step
For eIDAS 2.0 implementation, ISO Ready links identity, trust and security measures in one ISMS — with actions, evidence and vendors toward audit. Run the readiness scan on iso-ready.nl.
More on eIDAS 2.0
- Eidas2 Compliance
- Eidas2 Compliance Iso 27001
- Iso Audit Checklist
- Audit Evidence Iso 27001
- Iso 27701 Privacy Management
- Dora Compliance