References¶
This page provides an overview of the standards and technical specifications (STS) relevant to the FCAF. It includes both the STS covered by tests and the STS that define the tests themselves.
The syntax follows that used for the EUDI Wallet Architecture and Reference Framework (ARF). The Version column records the specification version used for conformance assessment. A hyphen indicates that no specific version is pinned.
| Item reference | Version | Standard name/details |
|---|---|---|
| [ECCG ACM] | v2.0 | ECCG ACM: European Cybersecurity Certification Group Sub-group on Cryptography; Agreed Cryptographic Mechanisms. |
| [CIR 2024/2979 amended] | (EU) 2026/1731 | Commission Implementing Regulation (EU) 2026/1731, amending Commission Implementing Regulation (EU) 2024/2979 as regards applicable standards and specifications. |
| [CIR 2024/2982 amended] | (EU) 2026/1731 | Commission Implementing Regulation (EU) 2026/1731, amending Commission Implementing Regulation (EU) 2024/2982 as regards applicable standards and specifications. |
| [ETSI TS 119 472-1] | v1.2.1 | ETSI TS 119 472-1: Profiles for Electronic Attestations of Attributes; Part 1: General requirements. |
| [ETSI TS 119 472-2] | v1.2.1 | ETSI TS 119 472-2: Profiles for Electronic Attestations of Attributes; Part 2: Profiles for EAA/PID presentation. |
| [ETSI TS 119 472-3] | v1.1.1 | ETSI TS 119 472-3: Profiles for Electronic Attestations of Attributes; Part 3: Profiles for EAA/PID issuance. |
| [ETSI TS 119 475] | v1.2.1 | ETSI TS 119 475: Electronic Signatures and Trust Infrastructures (ESI); Relying party attributes supporting EUDI Wallet user's authorization decisions. |
| [ETSI TS 119 612] | v2.4.1 | ETSI TS 119 612: Electronic Signatures and Infrastructures (ESI); Trusted Lists. |
| [IETF draft-attestation-based-client-auth] | draft 07 | IETF draft-attestation-based-client-auth: OAuth 2.0 Attestation-Based Client Authentication. |
| [ISO/IEC 18013-5] | 2021 (ed1) | ISO/IEC 18013-5, Personal identification - ISO-compliant driving licence - Part 5: Mobile driving licence (mDL) application. |
| [ISO/IEC TS 18013-6] | 2025 (ed2) | ISO/IEC 18013-6, Personal identification - ISO-compliant driving licence - Part 6: mDL test methods. |
| [ISO/IEC 18013-7] | 2025 (ed2) | ISO/IEC 18013-7, Personal identification - ISO-compliant driving licence - Part 7: Mobile driving licence (mDL) add-on functions. |
| [ISO 3166-1:2020] | 2020 | ISO 3166-1:2020, Codes for the representation of names of countries and their subdivisions - Part 1: Country code. |
| [ISO 3166-2:2020] | 2020 | ISO 3166-2:2020, Codes for the representation of names of countries and their subdivisions - Part 2: Country subdivision code. |
| [ISO/IEC 3166-1] | - | ISO 3166-1, Codes for the representation of names of countries and their subdivisions - Part 1: Country code. |
| [ISO 8601-1:2019] | 2019 | ISO 8601-1:2019, Date and time - Representations for information interchange - Part 1: Basic rules. |
| [ISO/IEC 5218:2004] | 2004 | ISO/IEC 5218:2004, Information technology - Codes for the representation of human sexes. |
| [OpenID4VP] | 1.0 (errata set 1) | Terbu, O. et al., OpenID for Verifiable Presentations, OpenID Foundation. |
| [OpenID4VCI] | 1.0 (errata set 1) | Lodderstedt, T. et al., OpenID for Verifiable Credential Issuance, OpenID Foundation. |
| [HAIP] | 1.0 | OpenID4VC High Assurance Interoperability Profile, OpenID Foundation. |
| [SD-JWT VC] | draft-16 | SD-JWT-based Verifiable Credentials (SD-JWT VC). Available at https://datatracker.ietf.org/doc/draft-ietf-oauth-sd-jwt-vc/. |
| [Token Status List] | draft-20 | Token Status List, IETF OAuth Working Group. |
| [DCQL] | - | Digital Credentials Query Language (DCQL), defined in [OpenID4VP]. |
| [RFC3339] | - | RFC 3339: Date and Time on the Internet: Timestamps. |
| [RFC5280] | - | RFC 5280: Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile. |
| [RFC5322] | - | RFC 5322: Internet Message Format. |
| [RFC6749] | - | RFC 6749: The OAuth 2.0 Authorization Framework. |
| [RFC7049] | - | RFC 7049: Concise Binary Object Representation (CBOR). |
| [RFC7515] | - | RFC 7515: JSON Web Signature (JWS). |
| [RFC7516] | - | RFC 7516: JSON Web Encryption (JWE). |
| [RFC7518] | - | RFC 7518: JSON Web Algorithms (JWA). |
| [RFC7519] | - | RFC 7519: JSON Web Token (JWT). |
| [RFC7800] | - | RFC 7800: Proof-of-Possession Key Semantics for JSON Web Tokens (JWTs). |
| [RFC8414] | - | RFC 8414: OAuth 2.0 Authorization Server Metadata. |
| [RFC8610] | - | RFC 8610: Concise Data Definition Language (CDDL). |
| [RFC8943] | - | RFC 8943: Concise Binary Object Representation (CBOR) Tags for Date. |
| [RFC8949] | - | RFC 8949: Concise Binary Object Representation (CBOR). |
| [RFC9101] | - | RFC 9101: The OAuth 2.0 Authorization Framework: JWT-Secured Authorization Request (JAR). |
| [RFC9126] | - | RFC 9126: OAuth 2.0 Pushed Authorization Requests. |
| [RFC9700] | - | RFC 9700: Best Current Practice for OAuth 2.0 Security. |
| [RFC9901] | - | RFC 9901: Selective Disclosure for JSON Web Tokens (SD-JWT). |
| [PID rulebook] | - | PID rulebook. |