What Is a QEAA? Qualified Electronic Attestations of Attributes Explained
A Qualified Electronic Attestation of Attributes (QEAA) is a digital statement about a person's characteristics, issued by a qualified trust service provider under eIDAS 2.0, that carries legal recognition across every EU member state. It is the credential type that turns the EU Digital Identity Wallet from a container into a functioning trust layer.
Through August 2026, providers began clearing the certifications required to issue them. That is the quiet milestone behind the wallet rollout: a wallet with no qualified attestations to hold is an empty wallet, and the supply side is now switching on.
Key takeaways
- A QEAA is a legally recognised attestation of an attribute, issued by a qualified trust service provider (QTSP) and supervised at national level.
- It sits above an ordinary EAA, which anyone may issue and which carries no presumption of legal effect.
- Attributes are discrete claims: age band, professional qualification, residency, account status, company role.
- Cross-border recognition is automatic; a QEAA issued in one member state must be accepted in all others.
- Public services and large private organisations face EU Digital Identity Wallet acceptance obligations by the end of 2026.
PID, EAA and QEAA: the three credential tiers
The eIDAS 2.0 framework defines three distinct objects, and they are routinely confused.
| Credential | What it asserts | Who issues it | Legal effect |
|---|---|---|---|
| PID (Person Identification Data) | Core identity: name, date of birth, national identifier | Member state or a body it mandates | Foundational identity, recognised across the EU |
| QEAA | A specific attribute, verified and issued under supervision | A qualified trust service provider | Legally recognised in all member states, with a presumption of accuracy |
| EAA | A specific attribute | Any party | Valid where the relying party chooses to accept it; no automatic legal effect |
The practical difference between the last two rows is the reason QTSP status matters. An EAA asserting "this user is a licensed pharmacist" requires the relying party to make its own judgement about the issuer's competence and honesty. A QEAA asserting the same thing arrives with a supervised issuer, an audited process and a legal presumption behind it. For regulated relying parties, that difference decides whether the credential is usable at all.
What becoming a QTSP requires
Qualified status is not a self-declaration. A provider must demonstrate, to a national supervisory body, that it meets requirements across:
- Identity proofing. Documented, auditable procedures for establishing the attribute being attested, at the assurance level the attestation claims.
- Cryptographic controls. Qualified signature or seal creation devices, key management, and revocation infrastructure.
- Operational security. Incident handling, continuity, logging and retention aligned with the supervisory framework.
- Conformity assessment. Independent audit by an accredited body, repeated on a defined cycle.
- Liability and insurance. Financial capacity to stand behind the legal effect the attestation carries.
The cycle is long and the audit burden is continuous. That is precisely why the certifications granted through 2026 matter: each one adds a supply-side node capable of issuing credentials that every relying party in the EU is obliged to recognise.
Why attribute-level credentials change the data model
Most identity systems in production today are document-centric. A relying party wants to know one thing, whether a user is over eighteen, whether a professional licence is current, whether a company officer has signing authority, and to learn it, the party collects a document containing dozens of unrelated facts.
Attestations are attribute-centric. The claim is the unit. A relying party receives exactly the assertion it needs, from a supervised issuer, with nothing attached.
This has three consequences worth stating plainly:
- Data minimisation becomes the default rather than an aspiration. The relying party cannot over-collect, because there is nothing extra in the credential to collect.
- Retention obligations shrink. A verified assertion with a known issuer and expiry is a materially smaller liability than a stored copy of an identity document.
- Selective disclosure becomes possible. Combined with zero-knowledge proofs, a holder can prove a predicate over an attribute, that a hidden date of birth is before a threshold, without disclosing the attribute itself.
The December 2026 deadline is a supply-side problem
Acceptance obligations arriving at the end of 2026 are usually discussed as a relying-party problem: what must organisations accept, and by when. The harder constraint is on the other side. A wallet is only as useful as the attestations available to fill it, and every attestation requires an issuer willing and certified to stand behind it.
For any organisation that already performs verification as part of its normal operations, a bank onboarding customers, a marketplace validating sellers, a platform confirming professional status, that verification is a latent asset. It has been treated as a cost centre because its output was consumed once and discarded.
AIR Identity is designed around that asset. A partner that has already verified a user can issue a reusable credential; other partners confirm the attribute through a zero-knowledge proof without receiving the underlying data. The verification is performed once and creates value repeatedly, rather than being repeated by every party that needs the same fact.
For fintech and payment organisations in particular, where verification cost per user is already high and rising, the shift from single-use to reusable is a direct change to unit economics.
Frequently asked questions
What does QEAA stand for?
QEAA stands for Qualified Electronic Attestation of Attributes. It is a credential defined under the EU's revised eIDAS regulation, commonly referred to as eIDAS 2.0, which established the legal framework for the EU Digital Identity Wallet.
What is the difference between an EAA and a QEAA?
Both attest to an attribute. An EAA may be issued by any party and carries no automatic legal effect, so each relying party decides whether to trust the issuer. A QEAA is issued by a supervised qualified trust service provider, is subject to independent conformity assessment, and must be recognised across all EU member states.
Who can issue a QEAA?
Only a qualified trust service provider that has been granted qualified status by a national supervisory body, following independent conformity assessment against the eIDAS 2.0 requirements for identity proofing, cryptographic controls, operational security and liability.
What attributes can a QEAA contain?
Any verifiable characteristic of a person or organisation. Common examples include age or age band, residency, professional qualification or licence, educational credential, company role and signing authority, and account or membership status.
When must organisations accept the EU Digital Identity Wallet?
Acceptance obligations for public services and large private organisations arrive at the end of 2026 under eIDAS 2.0, extending electronic identification requirements beyond government services into the private sector. Organisations should be planning acceptance now rather than treating the deadline as a future project.
Related reading
- Government digital credentials in 2026
- Under-16 social media bans: the 2026 age verification map
- Reusable KYC in emerging markets
More from AIR: AIR Identity, fintech and payments, or browse the full AIR blog.
Already performing verification your users have to repeat elsewhere? See how AIR Identity turns a completed verification into a reusable credential, or read the developer documentation.




.png)