Skip to main content
Glossary termPublished ineIDAS2

Strong user authentication

What does "Strong user authentication" mean under eIDAS 2?

An authentication based on the use of at least two authentication factors from different categories of either knowledge, something only the user knows, possession, something only the user possesses or inherence, something the user is, that are independent, in that the breach of one does not compromise the reliability of the others, and is designed in such a way as to protect the confidentiality of the authentication data

Defined in / by

Last updated: 23 August 2026.

Regulations

  • electronic Identification, Authentication and Trust Services (eIDAS2)

    eIDAS2 is Regulation (EU) 2024/1183, which amends Regulation (EU) No 910/2014. It contains no calendar deadline: wallet availability runs 24 months from the entry into force of five implementing acts, and private relying-party acceptance 36 months. Those acts entered into force on 24 December 2024, giving end-2026 and end-2027.

    Next
    Member States to provide at least one wallet (Art. 5a(1))

    Checked