Index
The best content in your inbox
ETSI (European Telecommunications Standards Institute) is an independent institution that creates regulatory frameworks to secure and standardize the European technological landscape. As part of this work, the ETSI TS 119 461 standard details the technical requirements for identity verification applied to trusted digital services, outlining how to securely validate identities remotely. This regulation is a top priority for the banking and financial industry, where strengthening digital security is non-negotiable. It lays the technological foundation for combating fraud and meeting legal requirements for anti-money laundering (AML).
The latest version of the specification, ETSI TS 119 461 v2.1.1, introduced critical updates that significantly improve and strengthen identity verification processes against new threats. This article analyzes these updates. We will explain exactly what this regulation governs, the deadlines for its adoption, and how companies can ensure operational continuity and regulatory compliance.
Discover how to adapt your identification processes to ETSI
Talk to an expertWhat Is ETSI TS 119 461? Technical Standard for Identity
The ETSI TS 119 461 standard is a technical specification document that defines the policy and security requirements that systems must meet to perform identity verification in a secure and standardized manner. This regulatory framework establishes the exact rules for reliably verifying that a natural or legal person is who they claim to be before issuing a digital certificate, opening a bank account, or authorizing the signing of binding contracts.
This standard comprehensively regulates the various methods of identity verification, categorizing them and establishing strict criteria for each:
- In-person: Traditional physical verification in person.
- Remote: Use of digital technologies to validate identity without physical presence.
- Assisted: Onboarding processes involving a human agent in real time, such as video identification.
- Unattended: Fully automated workflows that rely on algorithms, facial biometrics, and artificial intelligence for validation without manual intervention.
The scope of the standard goes beyond simply listing permitted technologies. ETSI TS 119 461 specifies the maximum tolerable levels of false acceptance. It also establishes mandatory mechanisms to protect the integrity and confidentiality of the evidence collected (videos, images, metadata, and identity documents). Furthermore, it defines how these systems must be audited to ensure they are not vulnerable to fraud attempts. Among other aspects, the standard concisely specifies how identity evidence must be captured and validated, the use of biometrics and liveness detection controls, measures to prevent fraud and mitigate impersonation, as well as security, data protection, and access control requirements, always ensuring assurance levels aligned with eIDAS.
eIDAS 2 and ETSI
Far from operating in a vacuum, ETSI TS 119 461 serves as the technical backbone of the European Electronic Identification Regulation, known as eIDAS. From its very first version, this technical standard was designed with a clear purpose: to establish precise guidelines so that Qualified Trust Service Providers (QTSPs) could comply with the law.
These entities are the only ones legally authorized to issue qualified electronic signature certificates, time stamps, and other digital trust services. However, before issuing any certificate to a citizen, the QTSP has the non-negotiable obligation to securely verify the citizen’s identity, as mandated by Article 24 of the original eIDAS Regulation.
With the recent evolution of this regulatory framework toward eIDAS 2.0, the paradigm of the EU’s digital identity is undergoing an unprecedented transformation. The new European landscape demands a much more rigorous level of assurance in the face of emerging threats. Consequently, the ETSI standard has evolved to version v2.1.1 to align with these new requirements.
The update to the ETSI technical specification ensures that any technology provider or QTSP offering identity verification services complies with the new security standard required by eIDAS 2.0, preventing technical fragmentation and ensuring mutual recognition and cross-border interoperability.
Key changes in ETSI version v2.1.1 compared to v1.1.1
Version 2.1.1 of ETSI 119 461 introduces several updates aimed at improving identity verification processes and addressing the current needs of companies and technology sectors. These are the main changes affecting entities that use these services for customer onboarding and registration in highly regulated sectors, such as banking and financial services:
- Classification of Eligible Documents: Divides valid documents into two broad categories: physical (such as national ID cards or traditional passports) and digital (electronic IDs or biometric passports with chips).
- Types of validation methods: Classifies operational processes into manual (managed entirely by human operators), automatic (managed by systems and algorithms), and hybrid (a combination of manual and automated intervention).
- Cryptographic validation via NFC: Introduces stricter and more standardized guidelines for reading the chips embedded in identity documents, ensuring the secure extraction of data and the user’s original biometric information.
- Combating advanced fraud and deepfakes: Requires the implementation of advanced algorithms in verification systems capable of detecting generative artificial intelligence and synthetic media by analyzing visual inconsistencies, lighting anomalies, or audio asynchronies.
- Injection attack detection: Requires the inclusion of robust security and cryptographic mechanisms to block the use of mobile emulators or virtual cameras that attempt to manipulate the video stream by sending pre-recorded files to the server.
- New requirements for liveness detection: Tightens controls to ensure the user’s physical presence during onboarding, aligning with standards such as ISO/IEC 30107-3 and requiring proven, audited resistance to presentation attacks (such as masks or screens).
- Identity Reuse and Portability: Clarifies and regulates the security conditions under which it is possible to reuse a previous identity verification or rely on a trusted third party—a key advancement in reducing friction in the user experience.
All these technological enhancements establish version v2.1.1 as the definitive framework for addressing today’s enormous cybersecurity challenges. Thanks to this regulatory and comprehensive approach, financial institutions and corporations can fortify their onboarding processes against the most sophisticated fraud, ensuring strict legal compliance that immediately prepares them for integration with the new European digital identity environment.
The Role of the New ETSI v2.1.1 Standard in the Launch of the EUDI Wallet
The EUDI Wallet represents the European Commission’s flagship project and cornerstone initiative in the areas of digitalization and technological sovereignty. In practice, it consists of a mobile app, provided and supported by each member state, where European citizens can securely store their digital identity, manage verifiable credentials (such as driver’s licenses, university degrees, or medical prescriptions), and electronically sign documents with full legal validity across borders. However, for a user to legally download, configure, and link this wallet to their personal data, regulations require an initial onboarding process that ensures a high level of security. It is precisely at this critical activation point that the vital importance of ETSI TS 119 461 v2.1.1 lies, as it establishes non-negotiable technological guidelines to prevent any security breaches during identity creation.
At the technical and operational levels, the EUDI Wallet reference architecture requires that the issuance of Personal Identification Data be backed by the highest degree of legal and technical certainty. Version v2.1.1 of the standard thus becomes the mandatory operational framework that both Member States and private providers must comply with to certify that the registration process is fully legitimate. Therefore, aligning with this new update is not a simple optional improvement, but an indispensable requirement for any entity that aspires to issue credentials or provide services within the new ecosystem of European digital wallets.
Secure your digital identity processes with the maximum assurance provided by Tecalis’s High-Level ENS Certification
Learn about our certificationImplementation Deadlines: When Does the Change Become Mandatory?
One of the most significant aspects of the new version is its implementation timeline, designed to ensure a gradual and seamless transition. A strategic adoption period has been established to provide accreditation bodies, laboratories, and suppliers with the necessary time to implement and test the new requirements before they take full effect in August 2027. This ensures that organizations can fully prepare to comply with the specifications without facing immediate implementation obligations.
| Date | What it regulates | Who it affects | Is ETSI TS 119 461 V2.1.1 mandatory? |
|---|---|---|---|
| May 21, 2026 | Submission by existing QTSPs of a report demonstrating compliance with Article 24 (identity verification). | Only QTSPs that were already qualified before May 20, 2024. | No. The standard does not require the use of version v2.1.1. |
| August 19, 2027 | Entry into force of the Implementing Regulation making ETSI TS 119 461 v2.1.1 mandatory as the reference standard. | QTSPs and IPSPs. | Yes, as of this date. |
Qualified Trust Service Providers (QTSPs) have short-term reporting obligations to demonstrate the ongoing compliance of their verification processes. During this regulatory transition period, entities may continue to operate normally by relying on previous versions of the standard or on recognized national schemes. This flexibility ensures that organizations can plan their regulatory adaptation progressively, guaranteeing business continuity while aligning themselves consistently with future European requirements.
However, this leeway should not lead to complacency: companies that need to renew their accreditation as QTSPs will be required to pass the audit under the new v2.1.1. Platforms that do not update their technology in time will lose their legal qualification to operate qualified onboarding processes (QES) and will not be able to obtain certification for the new eIDAS 2.0 services.
Benefits of the New ETSI 119 461
Adapting to this technological and regulatory update represents a fundamental leap in quality for organizations. Beyond avoiding penalties or the loss of accreditations, implementing the new version offers strategic and immediate advantages for onboarding processes:
- Greater security and accuracy: It implements verification systems that are far more reliable and secure, drastically reducing human error and improving the accuracy of user identity authentication.
- Reduced fraud: It establishes more robust processes that detect and prevent state-of-the-art fraudulent activities, effectively blocking the use of deepfakes and AI-manipulated media to prevent synthetic fraud.
- Simplified regulatory compliance: As these specifications are closely aligned with regulations such as eIDAS 2.0, the GDPR, and the Sixth Anti-Money Laundering Directive (AMLD6), they facilitate legal compliance, reduce risks, build trust, and simplify audits. At the national level, this ensures that institutions are in direct and seamless compliance with the requirements of SEPBLAC and Law 10/2010 on the Prevention of Money Laundering and Terrorist Financing in Spain.
- Better user experience and higher conversion rates: NFC validation and the reuse of previously verified identities reduce registration friction. This streamlines onboarding, lowers the abandonment rate, and boosts customer acquisition.
- Scalability and European interoperability: A unified technical framework across the EU enables rapid cross-border expansion. Identification processes are valid in any EU market, facilitating entry into new countries without having to redesign the technology.
How to Prepare Your Company to Comply with ETSI?
Adapting to this new version should not be viewed as a mere administrative formality, but rather as a strategic opportunity to modernize the company’s infrastructure. The first essential step is to conduct an internal audit of registration workflows and involve the Compliance, Legal, and Operations teams from the outset. Identifying gaps between legacy systems and the new risk management requirements will allow the company to establish a clear roadmap, optimize the budget, and avoid rushed migrations that could jeopardize business continuity before regulatory deadlines expire.
At the implementation level, developing in-house solutions from scratch to pass such rigorous audits places an enormous strain on time and engineering resources. Therefore, the most efficient strategy involves evaluating and selecting technology partners that offer scalable platforms based on a “compliance by design” approach. Relying on providers that have already addressed this technical and regulatory complexity ensures agile deployment, reduces operating costs, and guarantees that the organization maintains uninterrupted customer acquisition while adhering to the highest European standards.
In this transformation landscape, having a reliable partner makes all the difference in leading the market**. Tecalis offers advanced tools—**such as anti-fraud biometric validation, NFC reading, and remote video identification—to optimize your verification methods and prepare your infrastructure for future regulations, such as the new ETSI requirements or AML regulations.
Frequently Asked Questions (FAQs)
- When does compliance with version v2.1.1 become mandatory? Version v2.1.1 will be strictly mandatory as of August 19, 2027, for Qualified Trust Service Providers (QTSPs) and Independent Payment Service Providers (IPSPs). However, starting in May 2026, existing QTSPs must already submit reports demonstrating the ongoing compliance of their identity verification processes.
- What are the main technological changes required by the new ETSI version? Among the most critical updates are the mandatory implementation of advanced controls against synthetic fraud, stricter liveness detection validations, and standardized guidelines for cryptographic reading of identity documents using NFC technology.
- Why is ETSI version v2.1.1 a key standard for the EUDI Wallet? Because it establishes the non-negotiable technological guidelines ensuring that the onboarding process for European digital wallets meets the high level of security required by the regulations.
- What happens if a platform does not adapt its technology to the requirements of the new ETSI TS 119 461 v2.1.1? Entities that do not update their technology in time will not be able to pass the new audits. As a result, they will lose their legal qualification to conduct qualified onboarding processes (QES) and will not be able to obtain certification to provide the new services under the eIDAS 2.0 framework.
Pass the most demanding audits by integrating an ETSI-compliant onboarding system
Contact our experts






