News

What Is a QEAA? Qualified Electronic Attestations of Attributes Explained

Moca Network
August 26, 2026

A Qualified Electronic Attestation of Attributes (QEAA) is a digital statement about a person's characteristics, issued by a qualified trust service provider under eIDAS 2.0, that carries legal recognition across every EU member state. It is the credential type that turns the EU Digital Identity Wallet from a container into a functioning trust layer.

Through August 2026, providers began clearing the certifications required to issue them. That is the quiet milestone behind the wallet rollout: a wallet with no qualified attestations to hold is an empty wallet, and the supply side is now switching on.

Key takeaways

  • A QEAA is a legally recognised attestation of an attribute, issued by a qualified trust service provider (QTSP) and supervised at national level.
  • It sits above an ordinary EAA, which anyone may issue and which carries no presumption of legal effect.
  • Attributes are discrete claims: age band, professional qualification, residency, account status, company role.
  • Cross-border recognition is automatic; a QEAA issued in one member state must be accepted in all others.
  • Public services and large private organisations face EU Digital Identity Wallet acceptance obligations by the end of 2026.

PID, EAA and QEAA: the three credential tiers

The eIDAS 2.0 framework defines three distinct objects, and they are routinely confused.

CredentialWhat it assertsWho issues itLegal effect
PID (Person Identification Data)Core identity: name, date of birth, national identifierMember state or a body it mandatesFoundational identity, recognised across the EU
QEAAA specific attribute, verified and issued under supervisionA qualified trust service providerLegally recognised in all member states, with a presumption of accuracy
EAAA specific attributeAny partyValid where the relying party chooses to accept it; no automatic legal effect

The practical difference between the last two rows is the reason QTSP status matters. An EAA asserting "this user is a licensed pharmacist" requires the relying party to make its own judgement about the issuer's competence and honesty. A QEAA asserting the same thing arrives with a supervised issuer, an audited process and a legal presumption behind it. For regulated relying parties, that difference decides whether the credential is usable at all.

What becoming a QTSP requires

Qualified status is not a self-declaration. A provider must demonstrate, to a national supervisory body, that it meets requirements across:

  1. Identity proofing. Documented, auditable procedures for establishing the attribute being attested, at the assurance level the attestation claims.
  2. Cryptographic controls. Qualified signature or seal creation devices, key management, and revocation infrastructure.
  3. Operational security. Incident handling, continuity, logging and retention aligned with the supervisory framework.
  4. Conformity assessment. Independent audit by an accredited body, repeated on a defined cycle.
  5. Liability and insurance. Financial capacity to stand behind the legal effect the attestation carries.

The cycle is long and the audit burden is continuous. That is precisely why the certifications granted through 2026 matter: each one adds a supply-side node capable of issuing credentials that every relying party in the EU is obliged to recognise.

Why attribute-level credentials change the data model

Most identity systems in production today are document-centric. A relying party wants to know one thing, whether a user is over eighteen, whether a professional licence is current, whether a company officer has signing authority, and to learn it, the party collects a document containing dozens of unrelated facts.

Attestations are attribute-centric. The claim is the unit. A relying party receives exactly the assertion it needs, from a supervised issuer, with nothing attached.

This has three consequences worth stating plainly:

  • Data minimisation becomes the default rather than an aspiration. The relying party cannot over-collect, because there is nothing extra in the credential to collect.
  • Retention obligations shrink. A verified assertion with a known issuer and expiry is a materially smaller liability than a stored copy of an identity document.
  • Selective disclosure becomes possible. Combined with zero-knowledge proofs, a holder can prove a predicate over an attribute, that a hidden date of birth is before a threshold, without disclosing the attribute itself.

The December 2026 deadline is a supply-side problem

Acceptance obligations arriving at the end of 2026 are usually discussed as a relying-party problem: what must organisations accept, and by when. The harder constraint is on the other side. A wallet is only as useful as the attestations available to fill it, and every attestation requires an issuer willing and certified to stand behind it.

For any organisation that already performs verification as part of its normal operations, a bank onboarding customers, a marketplace validating sellers, a platform confirming professional status, that verification is a latent asset. It has been treated as a cost centre because its output was consumed once and discarded.

AIR Identity is designed around that asset. A partner that has already verified a user can issue a reusable credential; other partners confirm the attribute through a zero-knowledge proof without receiving the underlying data. The verification is performed once and creates value repeatedly, rather than being repeated by every party that needs the same fact.

For fintech and payment organisations in particular, where verification cost per user is already high and rising, the shift from single-use to reusable is a direct change to unit economics.

Frequently asked questions

What does QEAA stand for?

QEAA stands for Qualified Electronic Attestation of Attributes. It is a credential defined under the EU's revised eIDAS regulation, commonly referred to as eIDAS 2.0, which established the legal framework for the EU Digital Identity Wallet.

What is the difference between an EAA and a QEAA?

Both attest to an attribute. An EAA may be issued by any party and carries no automatic legal effect, so each relying party decides whether to trust the issuer. A QEAA is issued by a supervised qualified trust service provider, is subject to independent conformity assessment, and must be recognised across all EU member states.

Who can issue a QEAA?

Only a qualified trust service provider that has been granted qualified status by a national supervisory body, following independent conformity assessment against the eIDAS 2.0 requirements for identity proofing, cryptographic controls, operational security and liability.

What attributes can a QEAA contain?

Any verifiable characteristic of a person or organisation. Common examples include age or age band, residency, professional qualification or licence, educational credential, company role and signing authority, and account or membership status.

When must organisations accept the EU Digital Identity Wallet?

Acceptance obligations for public services and large private organisations arrive at the end of 2026 under eIDAS 2.0, extending electronic identification requirements beyond government services into the private sector. Organisations should be planning acceptance now rather than treating the deadline as a future project.

Related reading

More from AIR: AIR Identity, fintech and payments, or browse the full AIR blog.

Already performing verification your users have to repeat elsewhere? See how AIR Identity turns a completed verification into a reusable credential, or read the developer documentation.

Stay updated on AIR launches
Product updates, partner launches, and research across digital identity, fintech, and loyalty. Unsubscribe anytime.
By subscribing, you agree to our Privacy Policy and consent to receive updates.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
In this article
Blog

Read more articles

Lorem ipsum dolor sit amet, consectetur adipiscing elit.
View all
News
Proof of Human: Why Bot Detection Moved to the Login Layer in 2026
Governments are now procuring technology to block automated agentic AI at sign-in. Proof of human has become an authentication requirement, not a research topic.
News
Age Assurance Accuracy Standards: The 2026 Benchmarks Explained
Age assurance now has measurable accuracy targets: a 10% under-18 false-positive ceiling for 16-17 year olds and 3% for 13-15. What the benchmarks mean for platforms.
News
Government Digital Credentials in 2026: Birth Records, ID Cards and Wallets
The first US digital birth credential, a new European biometric ID card and a merged national identity app all landed in one week. What state issuance means for platforms.