TL;DR: eIDAS 2.0 tightens security, harmonises cross-border trust rules, and introduces the European Digital Identity Wallet, according to Togggle, which argues that electronic trust services now need stronger cryptography, interoperability, and compliance discipline across the EU. For identity teams, the bigger issue is that trust-service governance increasingly overlaps with human identity, credential lifecycle, and regulated digital assurance.
NHIMG editorial — based on content published by Togggle: eIDAS 2 and the Future of Electronic Trust Services
By the numbers:
- Only 5.7% of organisations have full visibility into their service accounts.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools.
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security.
Questions worth separating out
Q: How should organisations prepare IAM programmes for eIDAS 2.0?
A: Start by treating electronic trust services as part of the identity governance model, not a separate compliance project.
Q: What breaks when trust-service assurance is fragmented across teams?
A: Fragmented ownership creates gaps between policy and execution.
Q: Why does the European Digital Identity Wallet matter to security teams?
A: Because it changes where identity data and credentials are stored and how they are verified.
Practitioner guidance
- Map trust services to identity governance owners Assign clear ownership for electronic identification, authentication, signatures, seals, and timestamp workflows so no control sits outside IAM and compliance oversight.
- Validate revocation and freshness checks Test that credential status, attribute freshness, and revocation signals are checked at acceptance time for every relying-party workflow.
- Standardise evidence for cross-border audits Create a single evidence model for assurance level mapping, validation logs, and retention so cross-border reviews can be answered consistently.
What's in the full article
Togggle's full article covers the regulatory and implementation detail this post intentionally leaves for the source:
- Specific discussion of how eIDAS 2.0 changes electronic identification and trust-service requirements across EU member states
- Practical examples of how the European Digital Identity Wallet may be used for identity storage and verification
- The article's own framing of security, interoperability, and legal simplification across the digital single market
- Additional context on emerging technologies such as distributed ledger approaches and advanced cryptography
👉 Read Togggle's analysis of eIDAS 2.0 and electronic trust services →
eIDAS 2.0 and electronic trust services: what changes for IAM teams?
Explore further
eIDAS 2.0 turns trust services into identity governance infrastructure. The regulation is not just about digital signatures or wallet convenience. It pulls verification, authentication, cryptography, and cross-border assurance into the same governance conversation, which is where IAM teams already operate. Practitioners should treat electronic trust services as a governed identity dependency, not a legal add-on.
A few things that frame the scale:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- 91.6% of secrets remain valid five days after the targeted organisation is notified, which shows how slowly remediation can lag governance intent.
A question worth separating out:
Q: Who is accountable when cross-border trust decisions fail?
A: Accountability sits with the organisation that accepted the trust decision without sufficient evidence. Under eIDAS 2.0, that means both the issuer and the relying party need clear ownership for validation, logging, and revocation handling. If the evidence chain is weak, the governance failure is shared, not abstract.
👉 Read our full editorial: eIDAS 2.0 changes electronic trust service governance in the EU