Citizen Certificate: Finnish eID Scheme Peer Review

Independent expertise for EU-mutual recognition under LoA High.

icon
Partner: Digital and Population Data Services Agency of Finland
icon
Service: eID Schemes Advisory
icon
Duration: 03/2024 - 06/2024

Project's Background

In 2024, SpearIT was invited to act as an independent peer reviewer of Finland’s national eID scheme, the Citizen Certificate, as the country prepared for EU-wide recognition at the highest level of assurance under the eIDAS Regulation. This assignment underscored not only the importance of rigorous, independent assessments in the European trust ecosystem but also SpearIT’s reputation as a specialist advisor trusted to evaluate complex digital identity infrastructures.


The Citizen Certificate has long been a cornerstone of Finland’s digital identity landscape, enabling secure authentication, digital signing, and access to eGovernment services. With Finland’s ambition to secure notification under eIDAS at LoA High, the scheme required a detailed assessment of its compliance with the Regulation, its Implementing Acts, and the relevant ETSI standards governing qualified trust services and assurance frameworks.


Our Contribution

SpearIT’s role was to bring an impartial, multidisciplinary lens to this process. Our experts examined the scheme’s organizational, procedural, and technical components, benchmarking them against the expectations for cross-border interoperability and trust. This included reviewing governance structures, operational security practices, technical assurance mechanisms, and user identity proofing processes, as well as the scheme’s alignment with European best practices. By doing so, we were able to validate the strengths of Finland’s approach while also identifying areas where refinements would further strengthen compliance and resilience.

The review process demanded both technical depth and regulatory fluency. SpearIT bridged these domains by applying its extensive experience with national eID notifications, trust service assurance, and conformity frameworks. Our contribution helped ensure that the Citizen Certificate was not only technically sound but also positioned to meet the expectations of European peers and regulators.


Project's Outcome

The outcome of this collaboration was a strengthened assurance framework for Finland’s national eID scheme, paving the way for its acceptance under eIDAS and reinforcing its interoperability with other Member States.


  • For Finnish citizens, this recognition means continued access to secure digital services with the added benefit of cross-border trust.
  • For Finland as a Member State, it affirms the maturity of its digital identity infrastructure and its commitment to the shared European vision of seamless and secure digital interactions.
  • For SpearIT, the project highlighted our expanding role in Europe’s digital identity ecosystem. Acting as an independent peer reviewer, we contributed subject-matter expertise that supported the integrity of the eIDAS recognition process itself. This reinforces our position as a trusted advisor to Member States, ensuring that the EU’s digital identity landscape evolves with both rigor and confidence.


For more information regarding the Citizen Certificate, visit: https://dvv.fi/en/citizen-certificate-on-id-card