In early 2026, SpearIT was invited to serve as rapporteur for the Management and Organization (topic 3) of the European peer review of Sverige-id, Sweden's new government-issued electronic identification scheme, supporting their notification at Level of Assurance "High", the highest tier recognised under the eIDAS Regulation.
Under the eIDAS Regulation (Regulation (EU) No 910/2014), a citizen's national electronic identity (eID) can be used to prove who they are when accessing online services both at the national and cross-border levels. Before a country's eID can be trusted and accepted in this way, it must pass a rigorous, collaborative check by experts from other Member States. This process is known as a peer review, and it is the mechanism that builds mutual trust between countries.
SpearIT led the assessment of the topics pertaining to the management and organization of the eID scheme, reviewing Sweden's documentation against each requirement of the Regulatino, raising targeted questions with the Swedish delegation, coordinating questions from other Member States and drafting the topic's conclusions.
This evaluation examined the institutional provisions behind the technology, asking whether the organisations operating the scheme are properly constituted, adequately resourced and able to meet their obligations and liabilities. It looked at what the scheme publishes to users and relying parties, how information security is managed and risk is treated, how records are kept, whether staff are competent and facilities adequately protected, which technical and cryptographic controls safeguard the most sensitive assets, and how continuity, independent audit and supervision keep all of this in place over time.
For Sverige-id, this meant examining a layered governance model. The Swedish Police Authority acts as issuer, while the Agency for Digital Government (Digg) acts as scheme owner and supervisor: it audits and approves issuers against the Swedish Trust Framework, binds them to ongoing compliance through a licence agreement, and maintains oversight through annual audit reporting and event-driven inspections.
Sweden has long taken a scheme-based approach to electronic identification. The Swedish eID scheme (Svensk e-legitimation) allows multiple public and private issuers to provide eID means within a common national framework, promoting user choice and reducing dependence on any single provider.
The scheme was notified under the eIDAS Regulation in 2021 with Freja+, and BankID was added in 2024, both at assurance level Substantial.
Sverige-id extends this scheme with its first government-issued eID means, developed and issued by the Swedish Police Authority on a mandate from the Swedish Government, notified at assurance level High. The rationale is threefold:
For Swedish citizens, Sverige-id is tied to the national identity card and used through a mobile app. Digg has approved it at the highest level of the Swedish Trust Framework, and public issuance is planned from 1 December 2026, when the new legislation is expected to enter into force.
The outcome of this collaboration was the cross-border acceptance of the Sverige-id under LoA High and more specifically:
For more information about Sverige-id, visit: https://www.elegitimation.se/