Why QTSPs need certification against CEN/TS 18099 and ISO/IEC 19989-3 Written on

If you lead trust services, compliance, or procurement at a QTSP, injection attack detection is now something an auditor will check, not just something your proofing does. Under eIDAS 2.0 and ETSI TS 119 461, the identity proofing behind every qualified certificate has to resist injection attacks, and it has to hold an independent CEN/TS 18099 certification at the right level. For high-assurance proofing, that level is High. This post explains what the requirement covers, why an auditor asks for a certificate rather than a description, and how to check whether your own stack, and the suppliers inside it, can meet it.
In a Nutshell
- ETSI TS 119 461 pushes the certification requirement onto your technology stack, not just your written policy.
- The level is the point. CEN/TS 18099 to High is the bar for high-assurance proofing, referenced through the attack potential scale in ISO/IEC 19989-1 Annex F.
- A conformity assessment records a certificate against the standard, so that is the evidence to have ready, at the level your proofing requires.
- A few questions on a call confirm whether a supplier can produce that certificate, to what level, and how recently it was tested.
- Certification to High is rare in the market today, so it is worth checking your own stack now rather than at audit.
What does ETSI TS 119 461 require your stack to be certified against?
It is easy to treat eIDAS compliance as a policy exercise, a matter of documented procedures and a well-written practice statement. Remote identity proofing does not work that way. ETSI TS 119 461, the standard that spells out how a QTSP meets Article 24 of eIDAS 2.0, places its requirements on the components that do the proofing, the biometric capture, the liveness check, and the injection detection that sit inside your onboarding flow.
That distinction changes what you have to evidence. A procedure can be approved in a week, but a technology stack has to be tested against real attacks by an accredited laboratory, and the result has to be current. ETSI TS 119 461 names ISO/IEC 30107-3 for presentation attacks and CEN/TS 18099 for injection attacks as the references your detection is measured against, and it treats injection attack detection on both the face and the document capture path as an explicit requirement, not an optional extra.
The practical reading is simple. When ETSI TS 119 461 asks what your proofing resists, the answer cannot be a policy document. It has to be a certificate against the standard, covering the parts of the stack that face the attacker. For the full picture of how proofing sits inside eIDAS 2.0, our guide to remote identity proofing for QTSPs under eIDAS 2.0 sets out the whole territory.
What does certified to High mean under ISO/IEC 19989-1 Annex F?
High is a defined level of resistance, and it comes from the same place across the biometric security standards.
CEN/TS 18099 covers the detection of injection attacks, where fraudulent data is fed straight into the verification pipeline and bypasses the camera or sensor rather than being shown to it. Like the presentation attack world, injection detection is graded by how capable an attacker the system was shown to resist. That grading traces back to ISO/IEC 19989-1 Annex F, the normative annex on attack potential and resistance. Annex F scores an attack across factors such as elapsed time, expertise, knowledge of the system, window of opportunity, and equipment, then maps the total onto named tiers that run from basic, through enhanced basic and moderate, up to high.
A system shown to resist high attack potential has held up against an attacker with significant time, expert knowledge, and purpose-built equipment, not a casual fraudster with a phone. ETSI TS 119 461 ties its levels of identity proofing to the same scale, expecting its Baseline level to consider at least moderate attack potential and its Extended level to consider at least high. So for high-assurance proofing, certified to High is not the ambitious option, it is the level the standard points you to. The base standards question, how 30107-3 and 19989-3 relate, is covered in our explainer on ISO/IEC 19989-3 and ISO/IEC 30107.
What an auditor accepts as evidence
A conformity assessment turns on evidence, specifically on what an accredited third party has independently verified. That is the lens to bring to any position on CEN/TS 18099.
A description of what a product is built to do, whether phrased as built to, designed for, or aligned with the standard, is a normal and honest step while a product moves toward certification. What it does not give an assessor is an independent result to rely on, because no accredited laboratory has yet tested that product against the standard's attack instruments and issued a certificate.
A certification to CEN/TS 18099 at High is that independent result. An accredited laboratory ran the product against the standard's methodology, judged it against high attack potential, and issued a certificate that records the outcome. That is the form of evidence a conformity assessment is built to accept, and it reads the same way to your auditor, your regulator, and you.
The practical point for a buyer is simple. When you compare options, ask for the certificate and its level early, because that is what an assessment will come back to.
How to read a supplier's certification evidence
When a supplier says they meet CEN/TS 18099, ask to see the evidence and read it for four things. A complete certificate answers all four, and anything short of that leaves gaps worth knowing about.
First, who issued it. A certification names an accredited, independent laboratory. A result with no external body behind it is a self-assessment, which is a different kind of assurance to weigh.
Second, what level. A certification states the resistance level the product reached, and for high-assurance proofing you are looking for High, traced to the attack potential scale in ISO/IEC 19989-1 Annex F. A reference to 18099 with no level attached tells you the level still needs confirming.
Third, what was tested. Injection attacks target the document capture path as well as the face. A certificate should tell you which capture paths were in scope. A stack that certifies face injection detection but leaves the document route out has covered half the requirement.
Fourth, when. ETSI TS 119 461 requires the testing to be repeated at least every two years, so check the date. A certificate from three years ago describes a product that is two years behind the current attack techniques.
What questions should you ask a supplier?
You do not need to be a standards expert to confirm where a supplier stands. Four questions on a call will do it, and the useful signal is as much in how a supplier responds as in what they say.
Ask, "Are you certified to CEN/TS 18099, and to what level?" A clear answer names a level. Ask, "Which accredited laboratory issued the certificate?" A real answer names a lab and can produce the document. Ask, "Does the certification cover injection detection on document capture, or only the face?" This separates a full result from a partial one. Ask, "What is the date of the most recent evaluation?" This tells you whether the certificate is current against the two-year cycle.
A strong supplier welcomes these questions and answers each with a document. If the answers stay general, or point to a roadmap, that tells you where they are today.
Why so few suppliers hold what the standard requires
It is worth being honest about the market, because it explains why this test is worth running now. Certification to CEN/TS 18099 at High is hard to earn, and that is by design.
The standard is recent, the accredited testing capacity for injection attacks is still building out, and High demands resistance to an expensive, expert attacker rather than a common one. A vendor has to submit a real product to an independent lab, pass against a demanding attack set, and then do it again every two years to stay current. That investment has to be repeated for each platform a QTSP deploys on, since a result on one does not carry automatically to another.
The result is a field where alignment claims are common and certifications to High are rare. When most of the market can only offer alignment, the supplier who can show a certificate to High is not making a bigger claim, they are making a provable one.
How to check your own stack is compliant
Before your next conformity assessment, run a short self-check against the same test an auditor will apply. Walk your identity proofing stack through five questions and write down the evidence for each.
Start with scope, listing every component that touches biometric capture, liveness, and injection detection, and confirm each is covered by a certification rather than a supplier statement. Check the standard, whether you hold or your supplier can produce a certification to CEN/TS 18099, and to ISO/IEC 19989-3 on the presentation attack side. Check the level, whether it reaches High where your identity proofing requires it, referenced through ISO/IEC 19989-1 Annex F. Check both surfaces, so document capture is certified as well as the face. Finally check currency, whether the most recent evaluation falls inside the two-year window ETSI TS 119 461 sets, which lines up with the eIDAS Article 20 audit your QTSP undergoes at least every 24 months.
If every answer is a document, you are in a strong position. If any answer is a claim, that is the gap to close before the auditor finds it.
Where Youverse stands
Youverse is certified to ISO/IEC 30107-3 at Levels 1 and 2 for presentation attack detection, a tested result from an accredited evaluation that we state as a certified claim, and our face matching is NIST-recognized. On the standards this post is about, we are aligned with CEN/TS 18099 and ISO/IEC 19989-3 with certification in progress, and we are pursuing CEN/TS 18099 at High. Our injection attack detection, across both the face and the document capture path, is a capability aligned with 18099 today rather than a certified result, and we will describe it as certified only when the certificate is in hand. Because we carry that evaluation across our stack and re-run it on the two-year cycle, a QTSP that builds on Youverse inherits the testing rather than standing it up in-house, and where GDPR, CCPA, and PSD2 apply, the stack is built to support your compliance obligations rather than add to them.
If you want to know whether your proofing stack would satisfy a conformity assessment against these standards, the fastest way to find out is to walk it through these checks with a team that works to these standards every day. Book a meeting to check your compliance against CEN/TS 18099 and ISO/IEC 19989-3, and we will take your proofing stack through the same questions an auditor will.
FAQ
Is CEN/TS 18099 alignment enough for eIDAS 2.0?
For a conformity assessment, an auditor looks for a certification against the standard, evaluated by an accredited laboratory and held at the level your proofing requires. Alignment describes a product built to the standard and is a normal step on the way to that certification. What an assessment records is the certified result, so for high-assurance proofing that is the evidence to have in place. ETSI TS 119 461, which sets out how QTSPs meet Article 24 of eIDAS 2.0, points to CEN/TS 18099 for exactly this.
What is the difference between mapped to 18099 and certified to 18099 High?
Mapped or aligned means a product was built to the standard and is expected to perform well against it, assessed by the supplier. Certified to High means an accredited, independent laboratory tested the product against the standard's methodology, judged it against high attack potential as referenced in ISO/IEC 19989-1 Annex F, and issued a certificate. The difference is the stage of evidence, a description of intent versus an independently verified result an auditor can rely on.
Does my QTSP need to certify its own stack, or is a supplier's certification enough?
The requirement lands on the components in your proofing flow, so every biometric component you rely on has to be covered by a current certification. If you embed a supplier's technology, their certification can cover those components, provided it names the level, covers both the face and document capture paths, and applies to the platforms you deploy on. You still need to hold that evidence and keep it current for your own conformity assessment.
How do I evidence injection attack detection to an auditor?
Show a certificate from an accredited laboratory that names CEN/TS 18099, states the resistance level reached, covers injection detection on both the face and the document capture path, and carries a date inside the two-year window ETSI TS 119 461 sets. A description of your capability, however detailed, is a different kind of evidence to a certificate, so the certificate is what to have ready for the assessment.
