What is the ETSI TS 119 461 standard?
Designated as the technical reference for the "high" level of assurance under the eIDAS V2 Regulation, it is now the European standard for remote identification, harmonising practices beyond legacy national frameworks such as France's PVID.
- A structured 5-step process: initiation, attribute/evidence collection, validation, binding to the applicant, and issuance of the proof.
- The collection of certified identity attributes for natural and legal persons.
- The use of authoritative evidence: digital identity documents, notified eID schemes, or qualified electronic signatures.
- Rigorous validation of document authenticity through cryptographic checks and validity databases.
- Secure biometric binding: facial comparison to ensure that the applicant is indeed the legitimate holder of the document.
- Liveness detection: active defense against presentation attacks (masks, photos) and injection attacks (Deepfakes).
What is at Stake in ETSI TS 119 461 Certification?
Under the eIDAS V2 Regulation, certification has become the linchpin of the European trust ecosystem.
Mitigating Impersonation Risks in Real Time
The primary challenge is countering increasingly sophisticated impersonation threats. The standard mandates specific countermeasures against AI-driven video injection attacks, ensuring maximum security during onboarding.
Ensuring Immediate European Interoperability
By aligning with ETSI TS 119 461, organisations benefit from automatic recognition of their verification processes across all Member States. It facilitates cross-border expansion by offering assurance equivalent to physical presence, in accordance with the current requirements of the European eIDAS V2 Regulation.
Operational Readiness for the EUDI Wallet
Compliance with this standard is now required for activating European Digital Identity Wallets and for issuing qualified attributes. It enables organisations to meet regulatory obligations already in force.
Retention of Evidence: Ensuring Process Auditability
A critical component of the ETSI TS 119 461 standard concerns the management of evidence generated during identification (Requirement 8.5.2). To ensure long-term reliability, the organisation must fulfill the following:
- Collection and retention: Gather and retain all process evidence in compliance with the GDPR.
- Comprehensive documentation: Archive the sources used (document number, issuer) and the entire process, including video sequences in the case of remote identification.
- Security and Integrity: Store this data in a tamper-proof manner to guarantee its confidentiality and authenticity.
- Re-verification: Ensure the ability to search, retrieve, and re-verify the identity outcome in the event of a dispute or audit.
- Lifecycle: Observe retention periods (typically the duration of the contract plus several years) prior to secure deletion.
Evidence Preservation: Ensuring the Auditability of the Process
A critical aspect of the ETSI TS 119461 standard concerns the management of evidence generated during identification (requirement 8.5.2). To ensure long-term reliability, the organization must:
- Collection and Retention: Collect and retain all evidence of the process in compliance with the GDPR.
- Comprehensive Documentation: Document the sources used (document number, issuer) and the entire process, including video footage in the case of remote identification.
- Security and Integrity: Store this data in a tamper-proof manner to ensure its confidentiality and authenticity.
- Verification: Ensure the ability to search for, retrieve, and verify the identity verification result in the event of a dispute or audit.
- Lifecycle: Comply with retention periods (generally the duration of the contract plus several years) before securely deleting the data.
Who is ETSI TS 119 461 Certification For?
This certification is essential for key players in the digital trust chain:
- Trust Service Providers (TSPs): for issuing qualified signature or seal certificates under eIDAS V2.
- Identity Proofing Service Providers (IPSPs): specialised providers (KYC/KYB) delivering certified identity verification solutions.
- Banks and financial institutions: to secure customer onboarding and comply with current AML directives.
- High-security sectors: telecommunications, healthcare, and paperless public services.
How to Become ETSI TS 119 461 Certified?
The organisation must fully integrate the standard's requirements into its operational workflow.
Key Steps for Implementing ETSI TS 119 461 Certification
- Define the identity proofing context: Identify the required attributes according to the eIDAS V2 framework and select the use cases (automated with NFC, assisted remote, or physical presence).
- Implement an updated risk analysis: The provider must assess current cyber threats (particularly those related to generative AI) and document infrastructure and data protection measures.
- Qualify technologies and teams:
- Technical: Use Presentation Attack Detection (PAD) solutions compliant with ISO/IEC 30107-3.
- Human: Train agents on emerging fraud methods and ensure their competence in morphological verification.
- Ensure digital evidence compliance: Establish secure archiving of verification process evidence to enable control audits and meet eIDAS V2 traceability requirements.
Technical Evaluations: Laboratory Testing
The standard imposes strict requirements on the technical reliability of solutions. Biometric performance tests are not conducted directly by the certification body but must be performed by a specialised biometrics laboratory:
- Presentation Attack Detection (PAD): PAD measures must be laboratory-tested in accordance with ISO/IEC 30107-3 to guarantee resistance against physical fraud (masks, photos).
- Injection Attack Detection (IAD): The evaluation must confirm that the system is protected against the injection of spoofed video streams or Deepfakes directly into the transmission channel.
- Evaluation reports: The results of these tests, specifically FAR (False Acceptance Rate) and APCER (Attack Presentation Classification Error Rate) metrics, serve as technical evidence during the audit conducted by LSTI.
How Does the TS 119 461 Certification Process Work?
Duration and Cycle of ETSI TS 119 461 Certification
ETSI TS 119 461 certification operates on a two-year trust cycle. This duration is precisely aligned with the regulatory audit cycles mandated by eIDAS for qualified trust services, thereby ensuring complete consistency with your European compliance strategy. The issued certificate attests to the reliability of your identity verification processes at a given point in time, but its maintenance is conditional upon continuous surveillance. This cyclical approach ensures that your digital identity systems remain resilient against the constant evolution of cyber threats.
Execution of the ETSI TS 119 461 Conformity Audit
As a Conformity Assessment Body (CAB), LSTI carries out the evaluation of your services using a rigorous methodology aligned with the highest security requirements of the ETSI TS 119 461 standard. The audit takes place across several key stages:
- Phase 1: Strategic Document Review
Our auditors perform an in-depth analysis of the theoretical compliance of your services. This step relies on reviewing your Identity Proofing Practice Statement (IPPS) and your internal security policies. The goal is to validate that each operational process is documented in accordance with the standard's requirements before moving on to the testing phase.
- Phase 2: Operational Performance Audit
This stage consists of a field verification to validate the real-world effectiveness of your technical and human measures. It specifically includes:
- Evaluation of biometric binding: Verification of facial comparison algorithm effectiveness and the robustness of the link between the applicant and their identity.
- Review of laboratory reports (PAD & IAD): For technical presentation attack detection (PAD) and injection attack detection (IAD) testing, LSTI relies on the detailed evaluation reports you will have previously commissioned from a specialized biometrics laboratory.
- Oversight of manual procedures: Verification of the rigour of controls performed by your identity verification agents and the adequacy of their training relative to fraud risks.
- Verification of evidence retention: Audit of the secure archiving and integrity of data collected during identity verification (Requirement 8.5.2).
Upon successful completion of the audit, LSTI issues a conformity attestation enabling the use of your services for qualified provisions under eIDAS 2.0. This two-year trust cycle includes annual surveillance to ensure that your security controls adapt to emerging threats in the European market.
Your questions about ETSI TS 119 461 Certification
-
What is the identity proofing process according to the 119 461 standard?
Identity proofing is defined as a process to verify, with a required degree of reliability, that the identity claimed by an applicant is accurate. This mechanism is essential for the enrolment of subjects or subscribers with a Trust Service Provider (TSP), whether managed internally or via a specialized Identity Proofing Service Provider (IPSP) acting as a subcontractor. -
How does ETSI 119 461 impact remote identity verification?
The standard provides a rigorous framework for "remote identity proofing". It defines specific requirements for automated processes, whether attended or unattended, by imposing strict countermeasures against identity theft. The major impact lies in the obligation to implement Presentation Attack Detection (PAD) and Injection Attack Detection (IAD) measures, thereby guaranteeing a level of trust equivalent to physical presence. -
What are the benefits of ETSI 119 461 certification for businesses?
ETSI 119 461 certification offers businesses strategic regulatory compliance by directly meeting the requirements of the eIDAS V2 Regulation for issuing qualified certificates and attributes. It guarantees indispensable European interoperability, as certified services enjoy recognition across all Member States, thus facilitating cross-border expansion and integration into the upcoming EUDI Wallet.
Furthermore, this process strengthens partner and client trust, as the evaluation conducted by LSTI as an independent third party attests to the robustness of enrolment methods against fraud and impersonation attempts. Finally, it provides a major competitive advantage by converting a technical security constraint into a genuine hallmark of reliability and quality for end-users within the Single Market.
-
What is the connection between ETSI 119 461, eIDAS 2.0, and the EUDI Wallet?
ETSI 119 461 is designated as the technical reference for the "high" level of assurance provided for by the eIDAS 2.0 Regulation. It constitutes the indispensable foundation for the secure activation of European Digital Identity Wallets (EUDI Wallets) and for issuing Person Identification Data (PID). It ensures that the identity linked to the Wallet has been verified according to the most stringent security standards of the European Union. -
What are the main elements or requirements of ETSI 119 461?
The ETSI TS 119 461 standard enforces a trust cycle structured around five key steps: initiation, collection, validation, biometric binding, and outcome issuance. To ensure high reliability (Baseline LoIP), it requires the use of authoritative evidence such as official identity documents or recognized eID means. Technical security relies on Presentation Attack Detection (PAD) and Injection Attack Detection (IAD) testing, which must be performed by a specialized biometrics laboratory. Lastly, the secure and tamper-proof archiving of the entire process is mandatory to ensure auditability and compliance with eIDAS V2 traceability requirements. -
What is the ETSI 119 461 specification and why is it important?
It is the European technical specification defining the policy and security requirements for trust service components providing identity proofing. It is crucial because it establishes the first harmonised framework enabling high trust and reliability in electronic transactions within the European internal market. Without this standard, the mutual recognition of digital identities across Europe under eIDAS V2 would not be technically feasible. -
What are the five fundamental steps of the identification cycle according to ETSI TS 119 461?
To ensure optimal security, the five fundamental steps of the identification cycle break down into successive, complementary tasks. These begin with service initiation, followed by the collection of attributes and identity evidence. Next come the validation of these elements, the secure technical link with the applicant—referred to as binding—and finally the issuance of the official identity proofing outcome.
-
What does the "Baseline LoIP" level of TS 119 461 mean in practice?
The Baseline LoIP level corresponds to a high degree of trust achieved through compliance with general best practice requirements for the identification process. This tier is specifically designed to protect services against common impersonation attacks while ensuring compatibility with current European trust policies. -
What types of documents are recognized as authoritative evidence?
The standard recognizes four major categories of evidence to validate identity attributes: physical identity documents (passports, ID cards), digital documents (such as eMRTD), electronic identification (eID) means, and digital signatures backed by a certificate. Each piece of evidence must be issued by an authoritative source and validated according to strict security criteria. -
What is the connection between 119 461 and the eIDAS Regulation?
ETSI TS 119 461 was developed to support the requirements of Article 24.1 of the eIDAS Regulation regarding identity verification for issuing qualified certificates. In particular, it enables the demonstration of equivalence between remote identification methods and physical presence, thereby facilitating cross-border recognition of trust services. -
Why choose video over a photo selfie?
To comply with the remote Baseline LoIP level, video capture is necessary as it is the only method capable of ensuring robust liveness detection against injection fraud attempts. -
Can the process be fully automated?
The process can be fully automated provided it relies on electronic identity documents allowing for NFC chip reading and a highly secure facial biometric comparison, all certified according to the corresponding ISO standards. This automation requires the use of a digital identity document and facial biometrics to ensure the binding to the applicant without direct human intervention. -
Does the certification cover legal persons (KYB)?
The certification includes legal persons (KYB processes), since the standard defines specific requirements to validate the identity of legal representatives as well as the validity of entity registration documents. Specifically, the process requires demonstrating the real-world existence of the legal person and confirming that the service request results from a voluntary act carried out on its behalf by a duly authorized individual. -
What is the difference between ETSI 119 461 and PVID?
ETSI 119 461 is a harmonised European standard, whereas PVID is a French national framework; eIDAS V2 now favours the ETSI standard for interoperability.
Why Choose LSTI?

Recognized expertise

Specialized Auditors

Independent Third Party and Dedicated Support
Find out more
Discover our news




