Aller au contenu principal
Version 0.1Brouillon

Certification and accreditation

Overview

This page covers two distinct questions:

  1. What certifications does LuxID hold? - The accreditations, standards alignments and regulatory statuses that LuxID has achieved or is pursuing, and how Partners can obtain evidence of these.
  2. What certifications does my organisation need? - LuxID does not certify Partners, but regulated sectors impose their own obligations. This page describes what LuxID expects from Partners by integration type and which sectors carry additional requirements.

LuxID platform certifications

ISO 27001 - information security management

LuxID is pursuing ISO 27001 certification for its information security management system (ISMS).

ISO 27001 (ISO/IEC 27001:2022 (opens in a new tab)) provides the internationally recognised framework for systematic management of information security risk. Certification requires an independent third-party audit and annual surveillance reviews.

Until certification is formally issued, LuxID operates its security programme against ISO 27001 Annex A controls, and Partners may request a summary controls assessment upon signing the LuxID Agreement.

Evidence available to Partners:

  • Certification letter once issued (under NDA)
  • Summary ISMS scope statement
  • Penetration test executive summary (annual, conducted by an independent party)

ETSI EN 319 401 - trust service provider policy

LuxID's operational security policies are aligned with ETSI EN 319 401 v2.3.1 (opens in a new tab), the European standard for General Policy Requirements for Trust Service Providers (TSPs).

This standard is relevant because:

  • It establishes baseline security requirements for entities operating trust services in the European framework
  • It is referenced in the eIDAS supervisory body requirements for qualified trust service providers
  • Partners in regulated sectors that require their identity providers to meet TSP-level security will find ETSI EN 319 401 the applicable baseline

LuxID is not currently a Qualified Trust Service Provider (QTSP) under eIDAS Regulation (EU) 910/2014 Article 20 (opens in a new tab).

eIDAS supervision and notified scheme status

eIDAS Regulation (EU) 910/2014 Chapter II (opens in a new tab) establishes a notification procedure for national electronic identification schemes. Luxembourg's notified eID scheme is managed separately from LuxID.

LuxID's assurance levels are aligned with Commission Implementing Regulation (EU) 2015/1502 (opens in a new tab) (technical specifications for assurance levels), which allows LuxID authentication events to be meaningfully compared with notified scheme authentication events. However, LuxID itself is not a notified scheme and does not carry the legal presumption that attaches to notified schemes under Article 7.

attention

For Partners with a legal requirement to accept only notified eID schemes, LuxID alone does not satisfy that requirement. A cross-border eIDAS-node integration - where LuxID would serve as the relying party interface while the user authenticates via a notified scheme - is on the LuxID roadmap but not yet available. Contact LuxID to discuss interim options.

GDPR - DPO appointment and CNPD registration

LuxID (operated by POST Luxembourg) has appointed a Data Protection Officer (DPO) as required by GDPR Article 37 (opens in a new tab) for organisations whose core activities involve large-scale processing of personal data. The DPO can be reached at privacy@post.lu.

LuxID's processing activities are registered with the Luxembourg CNPD (Commission nationale pour la protection des données), the competent supervisory authority under GDPR for Luxembourg-established controllers.

Partners may verify CNPD registration details or obtain the DPO contact by writing to LuxID.

NIS2 compliance status

POST Luxembourg, as the operator of LuxID, is assessing its classification and obligations under Directive (EU) 2022/2555 (opens in a new tab) (NIS2), which has been transposed in Luxembourg.

NIS2 obligations relevant to Partners include:

  • Partners in regulated sectors (banking, energy, transport, healthcare) are themselves likely to be NIS2 entities and must assess LuxID as a third-party ICT dependency in their own supply chain risk management.
  • LuxID will provide Partners with the documentation they need to satisfy NIS2 third-party due diligence, including security summaries and contractual commitments on incident notification timelines.

ISO 29115 - entity authentication assurance framework

LuxID's assurance level design is informed by ISO/IEC 29115:2013 (opens in a new tab) (Entity Authentication Assurance Framework), which provides a framework for authentication assurance levels independent of any single national implementation. ISO 29115 and the eIDAS Implementing Regulation (EU) 2015/1502 are broadly aligned at Levels 2, 3 and 4 / Low, Substantial and High respectively.

Partners whose own sector standards reference ISO 29115 (for example, some healthcare and financial frameworks) will find LuxID's assurance model maps cleanly to those frameworks.

Obtaining evidence of certifications

Partners requiring formal evidence of LuxID's security posture - for their own regulatory audits, procurement processes or risk committees - should contact LuxID with the specific evidence required. Evidence is provided under NDA and may include:

  • ISO 27001 certification letter (once issued)
  • Penetration test executive summaries
  • GDPR Article 30 Record of Processing Activities extract (summary level)
  • Completed vendor security questionnaires (CAIQ, SIG Lite or equivalent upon request)
  • Availability and incident statistics for the preceding 12 months

Partner certification expectations

LuxID does not certify Partners and does not operate a formal accreditation programme for Partner applications. The LuxID Agreement establishes contractual security and privacy obligations; compliance with those obligations is the Partner's responsibility.

However, Partners in regulated sectors carry their own certification and compliance obligations that may affect how they integrate with LuxID. This section summarises the most common situations.

Standard integration

For a standard LuxID integration - a commercial website or application using OIDC or SAML to authenticate users - LuxID's minimum security expectations are:

  • HTTPS enforced on all redirect URIs and API endpoints
  • PKCE used for all public (browser and native) clients
  • Client secrets stored securely and never exposed in client-side code
  • Redirect URIs registered with LuxID and kept current
  • Claims not retained beyond the stated purpose and retention period in the Partner's privacy notice
  • A valid privacy notice published describing the LuxID integration

These are contractual requirements, not certification requirements. The Organization self-certifies compliance by signing the LuxID Agreement; its Partners (the technical API-access units created under it) operate under that compliance posture.

See Protect your Application for the full technical baseline.

Financial services Partners

Financial services Partners (banks, payment institutions, e-money institutions, investment firms) operating in Luxembourg are subject to regulation by the CSSF (Commission de Surveillance du Secteur Financier). Relevant frameworks include:

DORA - Regulation (EU) 2022/2554 (opens in a new tab) (Digital Operational Resilience Act) requires financial entities to manage ICT third-party risk, including identity providers. LuxID maps to DORA Article 28 third-party dependency requirements. See SLA and support for DORA-relevant SLA commitments and contract documentation.

CSSF circular requirements - CSSF circulars on outsourcing and ICT risk (notably CSSF Circular 22/806) require financial institutions to document dependencies on external service providers including identity services. LuxID can provide the documentation required for CSSF outsourcing notifications upon request.

Healthcare Partners

Healthcare Partners in Luxembourg may interact with national health data infrastructure. Relevant considerations:

  • Health data processed through a LuxID integration is controller-side data at the Partner; LuxID does not process health data as part of authentication.
  • Partners handling health records must assess whether the assurance level required for accessing those records is Low, Substantial or High, and configure LuxID accordingly. Clinical access to patient records will typically require at minimum Substantial assurance.
  • Luxembourg's health data infrastructure (DSP - Dossier de Soins Partagé) may have its own integration requirements separate from LuxID.

Telecom Partners

Telecom Partners (operators offering subscriber services) may be subject to ILR (Institut Luxembourgeois de Régulation) obligations. LuxID's OTP delivery uses SMS infrastructure; Partners should not rely on LuxID for any ILR-regulated communication obligations. LuxID OTPs are authentication signals, not regulated electronic communications.

Public-sector adjacent Partners

Partners providing services to public administrations - without being public administrations themselves - may be required by their public-sector customers to demonstrate that authentication meets specific assurance levels, including eIDAS Substantial. LuxID's Substantial assurance level is aligned with the technical specifications of Commission Implementing Regulation (EU) 2015/1502 (opens in a new tab).

For Partners whose public-sector customers specifically require a notified identity scheme, see the eIDAS notified-scheme discussion earlier on this page - LuxID is not a notified scheme, and the eIDAS-node integration that would bridge to notified schemes is roadmap-only.


High-assurance integrations

LuxID Verified - identity proofing

LuxID Verified provides identity proofing integrated with LuxTrust. Partners integrating LuxID Verified are enabling an identity-proofing workflow (eIDAS Substantial) that verifies the user's real-world identity, not merely authenticates a credential. Identity proofing via LuxID Verified reaches Substantial; High authentication assurance is reached only via LuxTrust used as the authentication method (auth_level 9).

Additional due diligence requirements apply for Partners wishing to use LuxID Verified:

  • The Partner must demonstrate a legitimate use case for identity proofing (for example, financial onboarding, regulated professional access, age-restricted services requiring identity confirmation)
  • The Partner's privacy notice must specifically describe the identity verification step and the data retained from that verification
  • The Partner must not use LuxID Verified identity attributes beyond the stated purpose in the LuxID Agreement

See LuxID Verified - Identity Verification for the technical integration guide.

LuxID Pro - enterprise federation

LuxID Pro enables organisations to federate their corporate identity provider with LuxID, allowing employees to authenticate to LuxID Partners using their corporate credentials. For Partners accepting LuxID Pro authentication from corporate IdPs:

  • The corporate IdP must serve assertions over TLS 1.2 or later
  • SAML assertions from the corporate IdP must be signed with a current signing key
  • Encryption suites must meet current ETSI or NIST recommendations - specifically, RC4, DES, 3DES and SHA-1 in signing paths are not acceptable
  • The Partner should understand that the assurance level reported for a LuxID Pro authentication reflects the authentication strength of the corporate IdP, as mapped by LuxID per the federation agreement

Mise à jour le 2026-05-22