Skip to main content

Level of Assurance

The eIDAS regulation defines three Levels of Assurance (LoA) for electronic identification: Low, Substantial and High. These describe how much confidence you can have that a person is who they claim to be, based on how their identity was verified and how the credential is protected.

  • Low. Basic identity binding, suitable for low-risk services.
  • Substantial. Identity verified against a reliable source, with at least one authentication factor protected against compromise. Suitable for most regulated services.
  • High. Identity verified face-to-face or equivalent, using a credential tied to a hardware device, resistant to forgery, theft and remote attacks. Required for the highest-stakes regulated workflows.

An eID scheme can be formally notified to the European Commission, meaning it has been assessed against eIDAS requirements and is mutually recognised across EU member states. Non-notified schemes may still achieve equivalent assurance levels but are not automatically accepted under cross-border eIDAS obligations.

Provider overview

ProviderLevel of AssuranceeIDAS notified
BankID NorwaySubstantial / HighYes
BankID SwedenSubstantialYes
Freja (Sweden)SubstantialYes
FTN / FI BankID (Finland)SubstantialYes
iDIN (Netherlands)SubstantialNo
itsme (Belgium)HighYes
MitID (Denmark)Low / Substantial / HighYes
Mobile-IDHighYes
Smart-ID (Baltics)HighYes
Entrust Identity Verification (Onfido)See note belowNo
MitID

High LoA is available with MitID but has very low uptake in practice. Most deployments use Substantial.

Entrust Identity Verification (Onfido)

Entrust Identity Verification is not a notified eID scheme and does not carry a fixed eIDAS LoA by itself. However, Entrust is ETSI EN 319 411-1 certified as an Identity Proofing Service Provider (IPSP), and a correctly configured workflow combining document verification, facial biometric checks and liveness detection can meet the requirements for Substantial LoA under eIDAS.

Whether a given Entrust IDV-based implementation qualifies as Substantial depends on the specific workflow used and the regulatory context in which it is deployed. If your use case requires a specific LoA claim, you should assess your workflow configuration against the relevant regulation, or get in touch with Scrive for guidance.