Okay, then, yeah, I am happy to be able to continue. Maybe just a short introduction to myself.
So, I'm Franziska Granc, I'm a Principal Consultant at Nimbus Technology Consultancy. We are a small consultancy based in Berlin, but working internationally on the topics of digital identities and trust services for many years now. And one of our activities is being part of ETSI and actively participating in ETSI. And recently, the European Commission has mandated ETSI to produce all the necessary standards and technical specifications for the European Digital Identity Wallet. And I'm the project leader of this project, which is why today I'll be kind of presenting you with an ETSI head on.
And just giving you like a very high level overview over the standards that are currently being developed. And maybe also like a motivation either to join ETSI, join standardization work yourself, or at least know where to look for if you're an implementer. And if you want to know how to build your solutions that you just know what to refer to.
So, yeah, this is something that you have probably seen multiple times over the conference days. It's just beforehand, like a very, very small introduction.
So, of course, you know, the European Union plans to introduce this European Digital Identity Wallet. All member states are obliged to provide such wallets by the end of the year. And it should be a safe, reliable and private means for digital identifications, mainly for natural persons. And every member state needs to provide at least one of such wallets. And it's also supposed to be able to store, share and sign important digital documents.
And the reason why I highlighted some words is because exactly those requirements that this wallet needs to be fulfilled, need to be enabled in a technical way. And in order to do so, and in order to do so interoperable throughout whole Europe, we need to define common standards. Then standardization, how and generally it works. This is also, again, just a very simple overview of how different standardization organizations are separated.
So, of course, every state has their own national standardization organizations. In Germany, for example, we have the BSI writing the technical reports. We have the DIN defining national standards. And then on European level, we have the two main recognized standardization organizations that are also relevant for the European Digital Identity Wallet.
It's ETSI, which I will be talking about today. And then we have CEN as well, which is focusing also more on the identity and biometric things. Then we have recognized international organizations. They should all be known to you, for example, ISO or the ITU. And then very interestingly and growing over the last years, we call them market-driven standardization organizations, such as W3C or the IETF. Or then the OpenID Foundation, which happened to be quite an important player now also in the EIDAS ecosystem. Or the Cloud Signature Consortium, for example.
They are also very strongly aligned with ETSI, for example, defining standards and APIs for digital signatures globally. So this is more or less how it's separated. So we have the officially recognized ones, but then the market-driven ones are playing a bigger role in the last sort of years. And then another introduction and how it's built up the ecosystem, just so you know what the relevance is also of these standards that I'm about to show you.
Is that, of course, the European Commission regulates things, they publish laws. And then in these laws, they give requirements in the EIDAS context, I would say, even more technical than usual. So they do really, this time went into quite a lot of detail on how to technically build the ecosystem.
But still, it needs supportive stakeholders, supportive organizations to build the foundation. So, of course, on top, we have the regulation and including the commission implementing regulations that go even more into detail for member states, how to implement the different requirements. Then we have the architecture and reference framework, which is just a guidance document. So there's no mandatory usage of it. Member states and implementers, you can use it. It's a very valuable document. It's been updated by the commissions on a regular basis. But it has in itself no legal value.
Then we have the recognized standardization organizations, ETSI and CEN. ETSI, now, as I said, been mandated to produce the standards. And those standards are directly referenced in the law. So that means that what we produce at ETSI is then referenced in the implementing regulations. And for you as an implementer, as a member state, as a verifier, becomes law to adhere to these standards.
And then, of course, now, as we are using, as you might know, the OpenID protocol or the W3C credential formats in the regulation. Also, internationally recognized standardization organizations are becoming more relevant as they're specifically referenced in the law.
Then, just like a short introductory slide, I'm not going to go into every bullet point. But just so you keep in mind, ETSI's been, of course, established for many, many years now. They're an official European standardization organization, officially recognized by the European Union, but working on a global context. So everyone can join ETSI. Everyone can participate in ETSI. The standards that ETSI is producing are available free of charge to everyone. So it's really like a collaborative approach to produce standards that can potentially not just in the European Union, but also beyond be used.
And as you can see, there's over 900 member organizations worldwide from a total 60 different countries and five continents. So it's really like a huge organization trying to define technical standards. And then within ETSI, which is obviously like in general for telecommunication and IT infrastructure standardization organization, we have this working group or technical committee. It's called ESI, which is the working group that is producing all the standards related to signatures and identification. It has been established already in 1999.
So also, again, the work of TCESI has been going on for many years now. And under EIDAS 1, so EIDAS 2014, ETSI already received the mandate from the commission to produce all the necessary standards, especially for trust services.
And now, as I said, they're also being mandated to produce the standards for the UDI wallet. So here you can see just the overview of what has been done so far. I think it's always also important to keep that in mind because a lot of stakeholders might have joined the ecosystem or the bubble, how I like to call it, once the EIDAS was revised already. But since we had this regulation in place since 2014, so over 10 years, we already have a huge set of standards ready. So if you want to be a trust service provider or a qualified trust service provider, everything is already standardized.
So you can already know how to start the process. The CAPs know exactly how they have to evaluate and how they have to do the audits. So everything is already set in place. The same for, of course, digital signatures. And now with digital identity, like the new layer on top, so to say, this is also in the responsibility of ESI. So it basically covers a whole set of standards for implementers, for auditors, and for any technical service providers who want to join the EIDAS ecosystem. Coming to the specialist taskforce, that's what it's called internally.
We call it the UDI Wallet Standards Project. It's a specialist taskforce that is funded by the European Commission. They have done like a gap analysis to really identify what standards do we have already today, which of these need to be updated, and what standards are completely still missing that we need in order to make this new ecosystem successful. So they mandated us to produce over 50 European standards and technical specifications for the UDI ecosystem, building on what is already there.
And the work has started, of course, already last year, even before the project officially kicked off, because as I said, ETSI is mission-driven, so to say, to produce the standards to make them available free of charge. So even before this mandate, ETSI already started working on updating their standards according to the new framework. What is part of this project is, so we have separated the group in several different work packages. I just highlighted here the ones that are most important or most interesting for you.
So the first one is, of course, wallets and privacy, where we really define specific standards around the UDI wallet ecosystem. So not just regarding the wallet itself, but also for attestation providers, for the issuance and the different formats for attestations, for the registration of relying parties. We have a specific technical specification on zero knowledge proof. So everything basically that is new in the ecosystem and that needs to still be standardized is being done in this work package.
So there we have in total 16 standards and technical specifications that are being developed at the moment. Then we have the certificates, which is mainly those standards that have been already produced for the EIDAS trust services. So there we're just doing some adaptions according to the EIDAS framework.
Then, as I mentioned before in the panel discussion, we have the electronic registered delivery service that is currently already being updated. And where we just have to see how it's going to develop with the commission and what role this specific trust service is going to play in the EIDAS ecosystem. And whether then we can use those standards maybe later on also for the business wallet communication channel that I mentioned before. Signature standards are also being updated and adapted to EIDAS.
And then one of the most important standards, the one that are being produced under the trust framework. There we already have a few standards that have been already published. So we have the foundational standards for trust service providers or if you want to become one. We have the standards for conformity assessment bodies. So if you're a trust service provider and you need to choose your auditor, the auditor also needs to apply to certain standards that are being defined. We have the standards for the trusted lists.
I don't know if you have seen it, but the European trusted list dashboard has been updated now already to the new trust services under EIDAS. And the standards on how to update this trusted list. So how the member states should provide their list to the European commission is based on a standard that is produced within this project. And then we have another work package on new technologies where it's more just about like EAA validation and how to do EAA with EIDAS signatures. This is just like a bit of a messy overview, but of the different milestones and timelines.
As I mentioned, the project started in November already technically. But in January, we had our like formal kickoff of the project and then already had our first milestone achieved, which is the publication of the first batch. I will show you in a minute the most important standards that you can find now available already. And now we are basically working on what is new or what still needs a bit further updates.
Of course, we are closely following also the development of the implementing regulations of the commission. We are like in constant exchange with them to make sure that also what we produce is then ready to be referenced in the law. And so now we are currently preparing for our next milestone, which will be also the publication of the stable drafts. That can then also be shared within the TCESI group and with the European commission for commentary. Talking too much, sorry. And maybe the most interesting for you also the next milestones will be then the official ENAP process.
This is something that I haven't explained yet. But how standardization works is that we usually start with a technical specification. And in some cases, the European ETSI will develop a European norm, which will then make it an official recognized European standard. That is then referenced in law or referenced by implementers, by guidelines. So it's like a whole procedure of starting drafting documents, sometimes as a technical specifications. And in many cases, then going through like official ENAP process. That's what it's called when it's being like shared with all the member states.
And then, yeah, they can give their feedback and then we can at the end have like a formal European norm that can be used. But as I said, this is like a project that is going on until October 2027. Here you can see like most of the standards, not all of them, but that are directly relevant to the EIDAS ecosystem. So you can, of course, see here in the middle, the European digital identity wallet and everything that is supposed to be in the wallet. And then here you can see the specific standards that have been produced.
Some of them, like, for example, the ETSI policy 319-401 is the general policy for qualified trust service providers. Has already been updated because as you might know, qualified trust service providers also fall now under NIS 2. So there was a huge mapping done with the NIS 2 and DORA regulation to really update it accordingly. A very important specification that is also currently being developed as a European norm is the one on identity proofing, which is also relevant in AML context, for example.
Then we have already a technical specifications for the electronic attestations of attributes for the registration of the relying parties. And these are all technical specifications that are already published. You will find a link at my last slide that you can already have a look at today and that you can implement and consider when you're building your solutions. Or you can join ETSI, you can join the committee and then work on the standards also yourself.
Yeah, and then here are some useful links where you can find just generally all the latest published standards and technical specifications where you can download them. We have a dedicated web page also for our SDF project where you can see all the deliverables that we are working on.
And then, as I said, we also do public events that we have two coming up now. And the first one will be a dedicated workshop in Tallinn. It will be like a joint week with the Trust Services Forum and CA Day. And then we will have a joint workshop together with CEN. They are also producing some standards for the UDI wallet. That will happen in Sofia Antipolis. It's close to Nice, which is the headquarter of ETSI.
So, yeah, if you're interested, feel free to join. And yeah, thank you for your attention. We're going to do questions or? Thank you very much, Franziska. And we have a final question for today. How can you ID? Where's my question? Start on January the 2nd of 27, when there are so many standardizations still ongoing. How can I ID the? How can the ID start?
Yeah, I mean, it's a good question. And we don't even have all the implementing regulations yet. But as I said, that last slide that I showed you with the overview of the public technical specifications, it's already very valuable and thorough. So I think with this set of standards, you're really good to go and start doing it. But of course, yeah, it's still a process. The same with how we're waiting still for some implementing regulations. They're also not published yet. You have to work with what you have.
And I think that the TCESI has already over the last year done a huge and tremendous work in updating a lot of existing standards. So I think from this side, we are quite far ahead already. Perfect. Thank you.