Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› When should organisations require an additional authentication step…
Authentication, Authorisation & Trust

When should organisations require an additional authentication step after an EUDI credential has been verified?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 30, 2026 Domain: Authentication, Authorisation & Trust

An additional step is justified when the verified credential does not fully match the risk of the transaction, the regulatory context, or the sensitivity of the account action. A credential can prove one attribute or status, yet still leave enough residual risk that step-up authentication is sensible. The decision should be based on context, not on a fixed wallet integration rule.

When step-up authentication is justified after EUDI verification

EUDI verification can answer a narrow question, such as whether a credential is valid, whether an attribute is trusted, or whether the holder meets a policy condition. It does not automatically resolve the full transaction risk. Step-up is justified when the action carries more exposure than the credential assurance level covers, especially for payments, account changes, legal commitments, or access to sensitive records.

What the verified credential does, and does not, prove

The key distinction is between identity assurance and transaction assurance. An EUDI credential may confirm a person’s status, age, role, or entitlement, yet still leave open questions about intent, session integrity, device compromise, delegation, or whether the current action is unusually risky. That is why context matters more than a fixed rule tied to wallet integration.

A practical way to think about it is: if the credential answer is sufficient for the policy question, no extra step is needed; if the action introduces materially higher downside, a second factor or a separate re-authentication step can reduce the chance that a valid but misused credential carries the transaction too far.

Where organisations should draw the step-up line

Step-up makes the most sense when the requested action changes the blast radius. That includes adding a beneficiary, changing bank details, resetting recovery channels, approving regulated transactions, granting new privileges, or releasing data that would be hard to undo once exposed. The stronger the downstream consequence, the more reasonable it is to ask for fresh proof of control.

The other trigger is mismatch. If the credential was issued for a low-friction use case but is now being used for a high-risk action, the original verification may be genuine yet still insufficient. For example, a verified wallet presentation may be enough to prove an attribute, but not enough to approve a sensitive account action without an additional authentication check.

For this reason, organisations should define step-up around transaction class, account sensitivity, and regulatory obligation, not around whether an EUDI wallet was involved. The wallet is an input to the assurance decision, not the decision itself.

Risk and Threat Considerations

Without step-up, a valid credential can be overtrusted. The main risk is not that the credential is fake, but that it is correct for one purpose and too weak for another, or that a compromised session can reuse it beyond the original intent. That creates a gap between proof of credential validity and proof of safe authorisation for the specific action.

Failure mechanism: An attacker, or a legitimate user operating from a compromised device or hijacked session, can present a valid verified credential and then push through a higher-risk action that should have required a stronger or fresher check.

Impact: The organisation may approve transactions, disclosures, or privilege changes that exceed the assurance level actually obtained, increasing fraud, account takeover, and compliance exposure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesEUDI assurance decisions depend on authenticator strength and transaction risk.
Recommendation — Map transaction sensitivity to the required assurance level before accepting the credential alone.
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)Step-up after verification is an authentication-strength decision for higher-risk actions.
IA-5 — Authenticator ManagementAdditional steps often depend on how authenticators are issued, reused, and protected.
Recommendation — Require stronger authentication before allowing sensitive account actions. Enforce authenticator lifecycle controls so step-up mechanisms remain trustworthy.
ISO/IEC 27001:2022A.5.15 — Access controlRisk-based step-up is an access control decision tied to protected actions.
A.8.5 — Secure authenticationExtra authentication after EUDI verification is a secure authentication design choice.
Recommendation — Apply access rules that scale with the sensitivity of the requested operation. Use stronger authentication when the initial credential assurance is insufficient for the action.

Practitioner Guidance

What to prioritise: Classify actions by consequence, not by channel. High-impact account changes, regulated disclosures, and privilege grants should have their own step-up policy even when the credential itself is trustworthy.

What to verify: Check that the step-up trigger is tied to the action, the risk tier, and the assurance level of the credential presentation. If those three do not line up, the policy is too coarse.

Decision rule: If the action is reversible, low sensitivity, and within the verified credential’s intended scope, keep the flow simple. If the action changes financial, legal, privacy, or access posture, require an additional authentication step before completion.

Practitioner takeaway: Treat EUDI verification as one control signal, not the whole control decision. Step-up is justified whenever the transaction’s risk, sensitivity, or regulatory weight is higher than the assurance that verification alone provides.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org