What is MIE qualification?
The qualification of Electronic Identification Means (MIE) is a conformity assessment and certification process governed by the European eIDAS regulation (Regulation No. 910/2014).
It aims to guarantee the security, reliability, and cross-border interoperability of devices or systems used for electronic identification, such as:
- Electronic ID cards
- Digital identity mobile applications
- Strong authentication systems
This qualification is essential to attest to one of the three assurance levels (low, substantial, or high) required for using MIE in public or private services across the European Union, thereby ensuring mutual trust in the digital identity of citizens and businesses.
What are the key stakes of MIE qualification?
- Regulatory and Legal Compliance: An imperative for operating within the European Union in compliance with the eIDAS regulation. It provides formal validation by an authorized third-party body (such as LSTI) that the solution achieves the required assurance level.
- Increased Trust and Security: A rigorous validation of your solution's robustness against fraud, identity theft, and cyberattacks.
- Access to the European Single Market: Cross-border recognition of the identification means across all 27 Member States, facilitating access to public and private online services for all European users.
- Competitive Advantage: A strong market differentiator by offering a trusted solution qualified at the European level.
- Interoperability and Simplification: A guarantee that the MIE can natively integrate with other European digital systems and infrastructures (such as FranceConnect or France Identité).
How does the MIE assessment work?
The assessment specifications for these MIEs, as well as their presumption of reliability, were determined by ANSSI in its security requirements framework (v1.2). This process applies to any company providing an electronic identification service or product.
The evaluation conducted by LSTI certifies compliance with:
- The specifications set out by Decree No. 2022-1004 (in accordance with paragraph III of Article L.102 of the CPCE).
- The requirements of the ANSSI framework for the chosen level (substantial or high, in accordance with paragraph IV of Article L. 102 of the CPCE).
Period of validity
Your questions about MIE qualification
-
What is the impact of moving towards the eIDAS v2 regulation and European Digital Identity Wallets (EUDI Wallet)?
The revision of the European framework under eIDAS v2 introduces European Digital Identity Wallets (EUDI Wallets). The current assessment work carried out by LSTI based on version 1.2 of the ANSSI framework constitutes an essential technical and organizational foundation, greatly facilitating the future transition and compliance of your systems with these new European identification standards. -
What happens in the event of a major technical or functional modification to the solution during the 2-year validity period?
Any substantial modification to the technical architecture, cryptographic components, or enrolment processes of the qualified identification means must be immediately notified to ANSSI. The state authority may then require a targeted complementary assessment by LSTI to verify that the changes do not alter the initially assigned assurance level (substantial or high). -
How does the assessment of an MIE coordinate with the use of third-party providers, for example, for Remote Identity Verification (PVID)?
If your solution relies on an external subcontractor for a key step in the lifecycle—such as a Remote Identity Verification Provider (PVID) for enrolment—the latter should ideally be qualified or certified according to the corresponding ANSSI framework. Otherwise, the scope of the audit conducted by LSTI will need to extend to verifying compliance with the requirements passed down to this third-party partner.
Why Choose LSTI?

Recognized expertise
With more than twenty years of experience, LSTI supports more than 300 organizations in France and across Europe as a certification body and leading assessment center, operating in the fields of cybersecurity, digital trust, and information security.

Specialized Auditors
Our audit teams are composed of experienced professionals who are well-versed in ANSSI’s cybersecurity standards, information security management practices, and European digital trust frameworks. Their approach ensures rigorous, balanced assessments that are tailored to each organization’s operational context.

Independent Third Party and Dedicated Support
Accredited by ANSSI, LSTI ensures impartiality, transparency, and consistency throughout the entire process: preparation, audits, monitoring, and renewals. A dedicated point of contact ensures continuity and clarity throughout the certification process.




