TamgaNetwork

EU alignment

Roles and terms: eIDAS 2.0 ↔ Tamga

The EU's eIDAS 2.0 regulation and the EUDI wallet architecture define a fixed set of roles. Tamga fills each of them with a named service or participant. Today, in the signed-list phase, Tamga holds several roles that belong to the state provisionally, on behalf of the national authority — and hands each of them over when the state joins.

The map

Gold chip: who holds the role today. Blue chip: who holds it once the state joins. Dashed box: a slot kept empty on purpose.

Trust and registration

  • Trusted List Scheme Operator

    Trusted lists

    trust.tamga.network

    TodayTamga, provisionally, on behalf of the national authorityWhen the state joinsNational authority
  • Registrar

    Participant register

    TodayTamga, as stand-inWhen the state joinsState registrar
  • Registration Certificate Provider

    Registration certificates

    TodayTamga, as stand-inWhen the state joinsState
  • Access CA · National Root CA

    TR National Root CA (provisional)

    TodayTamga, as provisional operatorWhen the state joinsState root or a qualified trust service provider

Providers

  • PID Provider

    Empty slot

    TodayNobodyWhen the state joinsState
  • (provisional) identity attestation

    Tamga identity service

    id.tamga.network

    TodayTamga, with remote identity verificationWhen the state joinsTaken over by the PID Provider
  • (Q)EAA / PuB-EAA Provider

    Institution (issuer)

    issuer.tamga.network

    TodayUniversities, a ticketing company (levels I1–I2)When the state joinsAlso public bodies (PUB)
  • Authentic Source

    The institution's own system

    TodayThe institution (e.g. student information system)When the state joinsAlso public registers
  • Wallet Provider

    Wallet provider

    wallet.tamga.network

    TodayTamgaWhen the state joinsTamga and certified third parties

Use

  • EUDI Wallet · Holder

    Tamga Wallet and its user

    TodayStudents, graduatesWhen the state joinsCitizens
  • Relying Party

    Verifying organisation

    TodayEmployers, career centresWhen the state joinsSame
  • Intermediary

    Tamga Verify (hosted verifier)

    verify.tamga.network

    TodayTamgaWhen the state joinsSame

Not yet filled — and the governance roles

  • Supervisory body

    TodayNone yetWhen the state joinsNational supervisory body
  • Conformity assessment body (CAB)

    TodaySelf-declaration + public conformance test vectorsWhen the state joinsIndependent assessment bodies
  • Scheme owner · Accreditation body

    TodayTamga, as founding stand-inWhen the state joinsCouncil · national accreditation body
  • Ledger node operator

    TodayNone — signed lists, no ledger yetWhen the state joinsAt least two independent institutions (Hyperledger Besu)

Every role in one table

EU termIn TamgaTodayWhen the state joinsDoesLimit
Trusted List Scheme OperatorTrusted liststrust.tamga.networkTamga, provisionally, on behalf of the national authorityNational authorityCompiles, signs and publishes the national trusted listNo personal data in the list; nothing is deleted — every version is kept
RegistrarParticipant registerTamga, as stand-inState registrarRegisters institutions, verifiers and wallet providersRegisters, does not license — legal authority sits outside the network
Registration Certificate ProviderRegistration certificatesTamga, as stand-inStateIssues one certificate per use (at most 12 months), taken only from the signed list entryNone for a participant without an official identifier (tax or trade register number)
Access CA · National Root CATR National Root CA (provisional)Tamga, as provisional operatorState root or a qualified trust service providerRoots the X.509 certificates of institutions, including verifiers' access certificatesThe root identifier stays the same at hand-over
PID ProviderEmpty slotNobodyStateProvides person identification data at the highest assurance levelTamga cannot fill this slot
(provisional) identity attestationTamga identity serviceid.tamga.networkTamga, with remote identity verificationTaken over by the PID ProviderIssues an identity attestation after identity proofingKeeps no images or selfies; the national ID number appears only in this credential type
(Q)EAA / PuB-EAA ProviderInstitution (issuer)issuer.tamga.networkUniversities, a ticketing company (levels I1–I2)Also public bodies (PUB)Issues the credential types it is authorised forAuthorised per credential type; the signing key belongs to the institution
Authentic SourceThe institution's own systemThe institution (e.g. student information system)Also public registersHolds the original of the informationTamga keeps no copy of it
Wallet ProviderWallet providerwallet.tamga.networkTamgaTamga and certified third partiesSigns the wallet unit attestation (WUA): the app is genuine and its keys sit in device hardwareIn the pilot, no credentials for wallets whose keys are software-only
EUDI Wallet · HolderTamga Wallet and its userStudents, graduatesCitizensHolds credentials and decides what to show to whomEvery presentation needs the PIN or biometrics
Relying PartyVerifying organisationEmployers, career centresSameAsks for fields within its registered scopeCannot ask for fields outside its scope — the wallet shows the scope and warns
IntermediaryTamga Verify (hosted verifier)verify.tamga.networkTamgaSameRequests and verifies on behalf of a verifying organisationThe result goes only to that organisation, and only once

Objects: the same things, two vocabularies

EU termIn TamgaNote
LoTL · Trusted Listlotl.jws · tl-tr.jwsETSI TS 119 612 model, at trust.tamga.network
(Q)EAACredential types — urn:tamga:<domain>:<Type>:<major>Catalogue at schemas.tamga.network
PID— (empty slot)Provisional: the identity attestation from the Tamga identity service
WUAWUA (same name)Signed by the wallet provider
Status ListRevocation listsIETF Token Status List, at status.tamga.network
WRPAC · WRPRCAccess certificate · registration certificateETSI TS 119 475 registration certificate
LoA Low · Substantial · HighT1 · T2 · T3 (+ T0 anonymous)One-to-one; the level is a precondition of the credential type, not a field in it
—I1 · I2 · I3 · PUBTamga's institution levels: registered · contracted · accredited · public body

One rule across every role

Tamga holds no signing key in any service it hosts. Even where the issuing service runs at Tamga, the credential key belongs to the institution; the one pilot exception is listed openly on the known shortcuts page. →

Read further