All articles
CompliancePublished 9 March 2026 8 min

QEAA vs Non-Qualified EAA: A Decision Framework for Issuers

QEAA and non-qualified EAA are not two flavours of the same product — they carry different legal weight, different issuer obligations, and very different costs. Here is how to choose.

Citește acest articol în română

eIDAS 2.0 defines two tiers of Electronic Attestations of Attributes, and the choice between them is the first decision any organisation planning to issue credentials into the EUDI Wallet ecosystem has to make. Get it wrong and you either overpay for legal weight nobody asked for, or ship a credential relying parties won't trust for the use case you had in mind.

What actually distinguishes the two tiers

The technical format is often identical — both can be SD-JWT VC or mdoc, both flow through OpenID4VCI and OpenID4VP, both are verified the same way by a relying party. The difference is legal and organisational, not cryptographic.

  • Legal effect: a QEAA benefits from a legal presumption of accuracy of the attested attributes and of the identity of the entity to which the attribute relates — comparable to the standing of a qualified electronic signature. A non-qualified EAA has full evidential value under the Regulation but no such presumption; if challenged, its accuracy must be demonstrated rather than assumed.
  • Issuer status: a QEAA can only be issued by a Qualified Trust Service Provider (QTSP), supervised and listed by a national supervisory body and appearing on the EU Trust List. A non-qualified EAA can be issued by any organisation capable of meeting the technical interoperability requirements.
  • Supervision: QTSPs undergo mandatory conformity assessment by an accredited conformity assessment body, then periodic audits, with liability rules attached to false attestations. Non-qualified issuers register in the national trust framework but are not subject to the same audit cadence.
  • Portability of trust: relying parties across the EU are obligated to trust a QEAA automatically once its issuer is on the Trust List. A non-qualified EAA's trust depends on the relying party's own policy toward that specific issuer.

Issuer requirements in practice

Becoming a QTSP is a multi-month, capital-intensive process: an accredited conformity assessment covering the trust service practice statement, key management (typically an HSM-backed certificate authority chain), physical and organisational security controls, and business continuity arrangements, followed by supervisory body approval and Trust List inclusion. Ongoing obligations include annual audits, incident reporting, and liability exposure for incorrect attestations.

Issuing non-qualified EAAs requires none of that. The organisation registers as an issuer within the applicable national attestation scheme, implements an OpenID4VCI-compliant issuance endpoint, manages its own signing keys to a reasonable security standard, and publishes its credential schemas. There is no external conformity assessment body in the loop and no statutory liability regime beyond general contract and tort law.

Cost comparison

  1. QTSP set-up: typically a six-figure investment once you count conformity assessment fees, HSM infrastructure, security certification, legal drafting of the trust service practice statement, and staff for ongoing audit compliance.
  2. QTSP running cost: annual audits, supervisory body fees, and a compliance function that does not scale down even if issuance volume is low.
  3. Non-qualified issuance via own infrastructure: lower entry cost, but still requires building and maintaining an OpenID4VCI issuer, key management, revocation status service, and wallet-compatibility testing across ecosystems.
  4. Non-qualified issuance via an intermediary platform: the lowest entry cost — a platform such as Arkadiz operates the issuance infrastructure and national scheme registration, and the issuing organisation integrates against a single API.

When non-qualified is enough

For the majority of B2B use cases, a non-qualified EAA is the correct answer, not a compromise.

  • The relying party already has an independent relationship with the issuer and can assess its credibility directly — a retailer verifying its own loyalty-tier attestation, for instance.
  • The attribute is low-stakes if wrong: a discount eligibility flag, a newsletter subscription status, a conference-ticket entitlement.
  • Speed to market matters more than maximal legal certainty, and the organisation wants to pilot before committing capital to a QTSP build-out.
  • The attribute changes often enough that a heavyweight qualified-issuance process would be operationally disproportionate.
Ask what happens if the attestation is wrong and nobody notices for a month. If the answer is a minor inconvenience, you almost certainly do not need QEAA-level legal weight.

When qualified is worth the investment

A QEAA earns its cost when the attribute carries legal or financial consequence that a court or regulator might later scrutinise: proof of professional qualification required for regulated activity, attestations used in cross-border public procurement, or claims where the issuer needs the attestation itself, not just the underlying fact, to be presumed accurate. In these cases the legal presumption shifts the burden of proof in the issuer's favour, which is precisely the protection worth paying for.

A decision framework

  1. Identify the consequence of the attribute being wrong or disputed — financial, legal, reputational, or negligible.
  2. Check whether relying parties in your target sector already have a trust relationship with you independent of the wallet ecosystem.
  3. Estimate issuance volume and how often the underlying fact changes — high-churn attributes favour lightweight, non-qualified issuance.
  4. Model the QTSP build cost against projected volume and the value each attestation unlocks; if the unit economics don't clear a QTSP investment, start non-qualified.
  5. Revisit the decision once volume or legal exposure grows — nothing prevents an issuer from starting non-qualified and pursuing QTSP status later for a specific credential line.

Most organisations exploring EAA issuance for the first time land on non-qualified attestations issued through a platform, because it lets them validate demand and integration cost before any qualified-status investment. Arkadiz is built for exactly that entry point: non-qualified EAA issuance without operating trust-service infrastructure, with a clear upgrade path if a future use case genuinely needs qualified status.

Frequently asked questions

Can the same organisation issue both QEAA and non-qualified EAA?

Yes. An organisation with QTSP status for one credential line can still issue non-qualified EAAs for other attributes that do not need the legal presumption, and vice versa an organisation can add QTSP status later for a specific use case.

Do relying parties have to accept non-qualified EAAs?

No. Relying parties are obligated to accept QEAAs from any Trust-Listed QTSP, but acceptance of a non-qualified EAA depends on the relying party's own trust policy toward that specific issuer.

Is the technical integration different for QEAA versus non-qualified EAA?

Largely no — both typically use the same credential formats and protocols (SD-JWT VC or mdoc over OpenID4VCI/OpenID4VP). The difference is in issuer status, supervision, and legal effect, not in the wire format.

Talk to the Arkadiz team

One integration for EUDI Wallet verification and non-qualified EAA issuance across Member States.

Contact the team

Continue reading