EU alignment
Roles and terms: eIDAS 2.0 ↔ Tamga
The EU's eIDAS 2.0 regulation and the EUDI wallet architecture define a fixed set of roles. Tamga fills each of them with a named service or participant. Today, in the signed-list phase, Tamga holds several roles that belong to the state provisionally, on behalf of the national authority — and hands each of them over when the state joins.
The map
Gold chip: who holds the role today. Blue chip: who holds it once the state joins. Dashed box: a slot kept empty on purpose.
Trust and registration
Trusted List Scheme Operator
Trusted lists
trust.tamga.network
TodayTamga, provisionally, on behalf of the national authorityWhen the state joinsNational authorityRegistrar
Participant register
TodayTamga, as stand-inWhen the state joinsState registrarRegistration Certificate Provider
Registration certificates
TodayTamga, as stand-inWhen the state joinsStateAccess CA · National Root CA
TR National Root CA (provisional)
TodayTamga, as provisional operatorWhen the state joinsState root or a qualified trust service provider
Providers
PID Provider
Empty slot
TodayNobodyWhen the state joinsState(provisional) identity attestation
Tamga identity service
id.tamga.network
TodayTamga, with remote identity verificationWhen the state joinsTaken over by the PID Provider(Q)EAA / PuB-EAA Provider
Institution (issuer)
issuer.tamga.network
TodayUniversities, a ticketing company (levels I1–I2)When the state joinsAlso public bodies (PUB)Authentic Source
The institution's own system
TodayThe institution (e.g. student information system)When the state joinsAlso public registersWallet Provider
Wallet provider
wallet.tamga.network
TodayTamgaWhen the state joinsTamga and certified third parties
Use
EUDI Wallet · Holder
Tamga Wallet and its user
TodayStudents, graduatesWhen the state joinsCitizensRelying Party
Verifying organisation
TodayEmployers, career centresWhen the state joinsSameIntermediary
Tamga Verify (hosted verifier)
verify.tamga.network
TodayTamgaWhen the state joinsSame
Not yet filled — and the governance roles
Supervisory body
TodayNone yetWhen the state joinsNational supervisory bodyConformity assessment body (CAB)
TodaySelf-declaration + public conformance test vectorsWhen the state joinsIndependent assessment bodiesScheme owner · Accreditation body
TodayTamga, as founding stand-inWhen the state joinsCouncil · national accreditation bodyLedger node operator
TodayNone — signed lists, no ledger yetWhen the state joinsAt least two independent institutions (Hyperledger Besu)
Every role in one table
| EU term | In Tamga | Today | When the state joins | Does | Limit |
|---|---|---|---|---|---|
| Trusted List Scheme Operator | Trusted liststrust.tamga.network | Tamga, provisionally, on behalf of the national authority | National authority | Compiles, signs and publishes the national trusted list | No personal data in the list; nothing is deleted — every version is kept |
| Registrar | Participant register | Tamga, as stand-in | State registrar | Registers institutions, verifiers and wallet providers | Registers, does not license — legal authority sits outside the network |
| Registration Certificate Provider | Registration certificates | Tamga, as stand-in | State | Issues one certificate per use (at most 12 months), taken only from the signed list entry | None for a participant without an official identifier (tax or trade register number) |
| Access CA · National Root CA | TR National Root CA (provisional) | Tamga, as provisional operator | State root or a qualified trust service provider | Roots the X.509 certificates of institutions, including verifiers' access certificates | The root identifier stays the same at hand-over |
| PID Provider | Empty slot | Nobody | State | Provides person identification data at the highest assurance level | Tamga cannot fill this slot |
| (provisional) identity attestation | Tamga identity serviceid.tamga.network | Tamga, with remote identity verification | Taken over by the PID Provider | Issues an identity attestation after identity proofing | Keeps no images or selfies; the national ID number appears only in this credential type |
| (Q)EAA / PuB-EAA Provider | Institution (issuer)issuer.tamga.network | Universities, a ticketing company (levels I1–I2) | Also public bodies (PUB) | Issues the credential types it is authorised for | Authorised per credential type; the signing key belongs to the institution |
| Authentic Source | The institution's own system | The institution (e.g. student information system) | Also public registers | Holds the original of the information | Tamga keeps no copy of it |
| Wallet Provider | Wallet providerwallet.tamga.network | Tamga | Tamga and certified third parties | Signs the wallet unit attestation (WUA): the app is genuine and its keys sit in device hardware | In the pilot, no credentials for wallets whose keys are software-only |
| EUDI Wallet · Holder | Tamga Wallet and its user | Students, graduates | Citizens | Holds credentials and decides what to show to whom | Every presentation needs the PIN or biometrics |
| Relying Party | Verifying organisation | Employers, career centres | Same | Asks for fields within its registered scope | Cannot ask for fields outside its scope — the wallet shows the scope and warns |
| Intermediary | Tamga Verify (hosted verifier)verify.tamga.network | Tamga | Same | Requests and verifies on behalf of a verifying organisation | The result goes only to that organisation, and only once |
Objects: the same things, two vocabularies
| EU term | In Tamga | Note |
|---|---|---|
| LoTL · Trusted List | lotl.jws · tl-tr.jws | ETSI TS 119 612 model, at trust.tamga.network |
| (Q)EAA | Credential types — urn:tamga:<domain>:<Type>:<major> | Catalogue at schemas.tamga.network |
| PID | — (empty slot) | Provisional: the identity attestation from the Tamga identity service |
| WUA | WUA (same name) | Signed by the wallet provider |
| Status List | Revocation lists | IETF Token Status List, at status.tamga.network |
| WRPAC · WRPRC | Access certificate · registration certificate | ETSI TS 119 475 registration certificate |
| LoA Low · Substantial · High | T1 · T2 · T3 (+ T0 anonymous) | One-to-one; the level is a precondition of the credential type, not a field in it |
| — | I1 · I2 · I3 · PUB | Tamga's institution levels: registered · contracted · accredited · public body |
One rule across every role
Tamga holds no signing key in any service it hosts. Even where the issuing service runs at Tamga, the credential key belongs to the institution; the one pilot exception is listed openly on the known shortcuts page. →