The eIDAS 2 layer

Electronic attestation of attributes

The eIDAS 2 machinery for attested facts — definitions, legal effects, qualified attestations, authentic sources, and why mandates are on the minimum list.

An electronic attestation of attributes is "an attestation in electronic form that allows attributes to be authenticated" — the eIDAS 2 mechanism for carrying verified facts about a person or organisation, including powers and mandates to represent. Qualified attestations, and attestations from public-sector authentic sources, carry the same legal effect as paper. This is the machinery the digital EU power of attorney is expected to ride on.

Who this page is for

Anyone who needs the attestation layer straight before reasoning about mandates: trust service providers, wallet integrators, relying parties, and readers of our wallet mapping.

The definitions, from the instrument

Regulation (EU) 2024/1183 inserts these definitions into Regulation (EU) No 910/2014:

Legal effects — Section 9, Articles 45b–45f

The attestation rules sit in a dedicated section inserted into Regulation 910/2014:

Why this matters for mandates

Two provisions put organisational authority squarely inside this machinery. The recitals name "powers and mandates to represent or act on behalf of natural or legal persons" among the attestations whose issuers should be considered trust service providers of EAAs [Regulation (EU) 2024/1183 (eIDAS 2), recital 55]. And Annex VI's minimum list of attributes that must be verifiable against authentic sources includes, as point 9, "Powers and mandates to represent natural or legal persons" [Regulation (EU) 2024/1183 (eIDAS 2), Annex VI, point 9].

Company law then meets this halfway: the digital EU power of attorney "should meet the requirements on electronic attestation of attributes set in Regulation (EU) 2024/1183" and the wallet's technical specifications [Directive (EU) 2025/25, recital 27]. One machinery, two instruments — the attestation layer carries, the company-law layer decides what the carried thing legally is.

What an attestation does not do

An attestation authenticates attributes — it proves a fact was attested by an issuer at a point in time. It does not, by itself, make an action lawful: scope, joint-representation rules and revocation still bite at the moment of reliance, which is why valid token ≠ allowed action is a page on this site. Relying parties remain responsible for authenticating and validating what is presented to them [Regulation (EU) 2024/1183 (eIDAS 2), Art. 5b(9)].

Sources

  1. Law Regulation (EU) 2024/1183 of the European Parliament and of the Council of 11 April 2024 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework (OJ L, 2024/1183, 30.4.2024). http://data.europa.eu/eli/reg/2024/1183/oj. Retrieved 2026-08-27.
  2. Law Directive (EU) 2025/25 of the European Parliament and of the Council of 19 December 2024 amending Directives 2009/102/EC and (EU) 2017/1132 as regards further expanding and upgrading the use of digital tools and processes in company law (OJ L, 2025/25, 10.1.2025). http://data.europa.eu/eli/dir/2025/25/oj. Retrieved 2026-08-27.

Cite this page

Rob Prime, “Electronic attestation of attributes”, EUDIPOA, published 2026-08-27, last verified against its sources 2026-08-27, https://eudipoa.com/eidas/attestation-of-attributes.

Better still, cite the instruments themselves — the Sources list below gives each one’s ELI, the EU’s permanent identifier for legislation. This page is a guide to the law, not the law.

Changelog

  • 2026-08-27First published, written against the full text of Regulation (EU) 2024/1183 fetched from EUR-Lex on 2026-08-27.