| EAA-4.2.1.2-01 | EAA type component must indicate the type of the EAA | shall | | | Not auto-tested yet |
| EAA-4.2.1.2-02 | An EAA must incorporate the EAA type | shall | | | Not auto-tested yet |
| EAA-4.2.1.2-03 | EAA type incorporation, value, and placement is profile-specific | shall | | | Not auto-tested yet |
| EAA-4.2.1.3-01 | EAA must include context components when components have URL names | shall | | | Not auto-tested yet |
| EAA-4.2.1.3-02 | EAA context must reference a URL-to-alias map document | shall | | | Not auto-tested yet |
| EAA-4.2.1.3-03 | EAA context incorporation, value, and placement is profile-specific | shall | | | Not auto-tested yet |
| EAA-4.2.1.4-01 | EAA schema must allow verification of contents and structure | shall | | | Not auto-tested yet |
| EAA-4.2.1.4-02 | EAA may incorporate references for retrieving the EAA schema | may | | | Not auto-tested yet |
| EAA-4.2.1.4-03 | Each schema reference must include a type identifier and URI | shall | | | Not auto-tested yet |
| EAA-4.2.1.4-04 | Schema-reference sequence incorporation and placement is profile-specific | shall | | | Not auto-tested yet |
| EAA-4.2.10-01 | Attributes evidence must contain the proof material the issuer relied on | shall | | | Not auto-tested yet |
| EAA-4.2.10-02 | An EAA may incorporate the attributes evidence | may | | | Not auto-tested yet |
| EAA-4.2.10-03 | Attributes evidence must be a sequence of one or more evidence items | shall | | | Not auto-tested yet |
| EAA-4.2.10-04 | Each evidence item must carry a type URI, verifier id, data, and optional id | shall | | | Not auto-tested yet |
| EAA-4.2.10-05 | Attributes evidence incorporation and placement is profile-specific | shall | | | Not auto-tested yet |
| EAA-4.2.11.1-01 | EAA status service must contain enough detail to query the EAA's validity | shall | | | Not auto-tested yet |
| EAA-4.2.11.1-02 | An EAA may incorporate the EAA status service | may | | | Not auto-tested yet |
| EAA-4.2.11.1-03 | shortLived and status service are mutually exclusive | shall | | | Auto-tested |
| EAA-4.2.11.1-04 | Status service must include a URI and may include a type | shall | | | Not auto-tested yet |
| EAA-4.2.11.1-05 | Status service incorporation, value, and placement is profile-specific | shall | | | Not auto-tested yet |
| EAA-4.2.12-01 | EAA renewal service must contain enough detail to request renewal | shall | | | Not auto-tested yet |
| EAA-4.2.12-02 | An EAA may incorporate the EAA renewal service data | may | | | Not auto-tested yet |
| EAA-4.2.12-03 | Renewal service data must include a URI and may include a type identifier | shall | | | Not auto-tested yet |
| EAA-4.2.12-04 | Renewal service incorporation and placement is profile-specific | shall | | | Not auto-tested yet |
| EAA-4.2.13-01 | An EAA may contain the EAA short-lived component | may | | | Not auto-tested yet |
| EAA-4.2.13-02 | Short-lived presence excuses revocation-status checks | shall | | | Not auto-tested yet |
| EAA-4.2.2-01 | EAA category must explicitly identify the category of the EAA | shall | | | Not auto-tested yet |
| EAA-4.2.2-02 | An EAA may include the EAA category | may | | | Not auto-tested yet |
| EAA-4.2.3-01 | EAA identifier must unambiguously identify the EAA itself | shall | | | Not auto-tested yet |
| EAA-4.2.3-02 | An EAA may incorporate the EAA identifier | may | | | Not auto-tested yet |
| EAA-4.2.3-03 | EAA identifier incorporation, value, and placement is profile-specific | shall | | | Not auto-tested yet |
| EAA-4.2.4.1-01 | EAA issuer identifier must unambiguously identify the issuing TSP | shall | | | Not auto-tested yet |
| EAA-4.2.4.1-02 | An EAA may incorporate the EAA issuer identifier | may | | | Not auto-tested yet |
| EAA-4.2.4.1-03 | Issuer identifier incorporation, value, and placement is profile-specific | shall | | | Not auto-tested yet |
| EAA-4.2.4.1-04 | EAA may include an identifier of the issuer's EU Member State | may | | | Not auto-tested yet |
| EAA-4.2.4.1-05 | Member State identifier must be the ISO 3166-1 alpha-2 country code | shall | | | Not auto-tested yet |
| EAA-4.2.4.1-06 | Legal-person issuer EAA may include a registration identifier | may | | | Not auto-tested yet |
| EAA-4.2.4.1-07 | Legal-person registration identifier may follow ETSI EN 319 412-1 clause 5.1.4 | may | | | Not auto-tested yet |
| EAA-4.2.4.1-08 | Legal-person issuer EAA may include the legal-person name | may | | | Not auto-tested yet |
| EAA-4.2.4.1-09 | National VAT id takes precedence over other national identifiers | shall | | | Not auto-tested yet |
| EAA-4.2.4.1-10 | Natural-person issuer EAA may include the natural-person name | may | | | Not auto-tested yet |
| EAA-4.2.5-01 | EAA may indicate that it was issued on behalf of another entity | may | | | Not auto-tested yet |
| EAA-4.2.5-02 | On-behalf-of indication incorporation, value, and placement is profile-specific | shall | | | Not auto-tested yet |
| EAA-4.2.5-03 | EAA may incorporate an identifier of the on-behalf-of entity | may | | | Not auto-tested yet |
| EAA-4.2.5-04 | EAA may include the name of the on-behalf-of entity | may | | | Not auto-tested yet |
| EAA-4.2.5-05 | Legal-person on-behalf-of entity may include a registration identifier | may | | | Not auto-tested yet |
| EAA-4.2.5-06 | On-behalf-of legal-entity registration id may follow EAA-4.2.4.1-07 format | may | | | Not auto-tested yet |
| EAA-4.2.6.2-01 | An EAA may include the EAA subject identifier, a pseudonym, or neither | may | | | Not auto-tested yet |
| EAA-4.2.6.2-02 | EAA subject identifier incorporation, value, and placement is profile-specific | shall | | | Not auto-tested yet |
| EAA-4.2.6.3-01 | EAA subject pseudonym presence must be clearly indicated | shall | | | Not auto-tested yet |
| EAA-4.2.6.3-02 | EAA subject pseudonym incorporation mechanism is profile-specific | shall | | | Not auto-tested yet |
| EAA-4.2.6.4-01 | EAA may bind each attribute to an attribute-subject identifier or pseudonym | may | | | Not auto-tested yet |
| EAA-4.2.6.4-02 | Attribute-subject identifier incorporation, value, and placement is profile-specific | shall | | | Not auto-tested yet |
| EAA-4.2.6.5-01 | An EAA may incorporate pseudonyms for attribute subjects | may | | | Not auto-tested yet |
| EAA-4.2.6.5-02 | Attribute-subject pseudonym incorporation mechanism is profile-specific | shall | | | Not auto-tested yet |
| EAA-4.2.6.5-03 | Attribute-to-pseudonym binding mechanism is profile-specific | shall | | | Not auto-tested yet |
| EAA-4.2.6.5-04 | Attribute-subject pseudonym presence must be clearly indicated | shall | | | Not auto-tested yet |
| EAA-4.2.6.6-01 | One attribute subject identifier must be the EAA subject identifier | shall | | | Not auto-tested yet |
| EAA-4.2.6.6-02 | Subject pseudonym must appear when no subject identifier is present | shall | | | Not auto-tested yet |
| EAA-4.2.7.1-01 | EAA issuance data must unambiguously identify the issuance instant | shall | | | Not auto-tested yet |
| EAA-4.2.7.1-02 | An EAA may incorporate the EAA issuance data | may | | | Not auto-tested yet |
| EAA-4.2.7.1-03 | EAA issuance data incorporation and placement is profile-specific | shall | | | Not auto-tested yet |
| EAA-4.2.7.2-01 | Time instants must be UTC, second-precision, no fractions, no offset | shall | | | Not auto-tested yet |
| EAA-4.2.8.2-01 | A validity period must be expressed by two UTC instant times | shall | | | Not auto-tested yet |
| EAA-4.2.8.2-02 | Each validity-period instant must follow EAA-4.2.7.2 time content rules | shall | | | Not auto-tested yet |
| EAA-4.2.8.2-03 | Validity-period information incorporation and placement is profile-specific | shall | | | Not auto-tested yet |
| EAA-4.2.8.3-01 | An EAA must incorporate its technical validity period | shall | | | Not auto-tested yet |
| EAA-4.2.8.4-01 | An EAA may incorporate an administrative validity period | may | | | Not auto-tested yet |
| EAA-4.2.9.2-01 | EAA audience must identify the relying parties the EAA is intended for | shall | | | Not auto-tested yet |
| EAA-4.2.9.2-02 | An EAA may incorporate the EAA audience | may | | | Not auto-tested yet |
| EAA-4.2.9.2-03 | Audience presence restricts the EAA to the listed relying parties | shall | | | Not auto-tested yet |
| EAA-4.2.9.2-04 | Audience must be a sequence of party ids, group ids, or both | shall | | | Not auto-tested yet |
| EAA-4.2.9.2-05 | Audience identifier values are profile-specific | shall | | | Not auto-tested yet |
| EAA-4.2.9.2-06 | Audience incorporation and placement is profile-specific | shall | | | Not auto-tested yet |
| EAA-4.2.9.3-01 | An EAA may incorporate a one-time-use signal | may | | | Not auto-tested yet |
| EAA-4.2.9.3-02 | One-time-use signal restricts EAA to a single use, no retention | shall | | | Not auto-tested yet |
| EAA-4.2.9.3-03 | Absence of the one-time-use signal lifts the single-use constraint | shall | | | Not auto-tested yet |
| EAA-4.2.9.3-04 | One-time-use signal incorporation, value, and placement is profile-specific | shall | | | Not auto-tested yet |
| EAA-4.3-01 | Each attribute must have a unique attribute identifier | shall | | | Not auto-tested yet |
| EAA-4.3-02 | Each attribute must have a value with attribute-specific semantics | shall | | | Not auto-tested yet |
| EAA-4.3-03 | Each attribute must refer to one attribute subject | shall | | | Not auto-tested yet |
| EAA-4.3-04 | Each attribute may have a component indicating the identifier format | may | | | Not auto-tested yet |
| EAA-4.3-05 | Each attribute may have a component identifying its type | may | | | Not auto-tested yet |
| EAA-4.3-06 | Each attribute may have a friendly-identifier component | may | | | Not auto-tested yet |
| EAA-4.3-07 | Each attribute may have a component for individual external referencing | may | | | Not auto-tested yet |
| EAA-4.3-08 | Attribute incorporation and placement is profile-specific | shall | | | Not auto-tested yet |
| EAA-4.4.2.2-01 | An EAA may incorporate the disclosure schema identifier | may | | | Not auto-tested yet |
| EAA-4.4.2.2-02 | Disclosure schema identifier must univocally identify the SD mechanism | shall | | | Not auto-tested yet |
| EAA-4.4.2.2-03 | Disclosure schema identifier incorporation and placement is profile-specific | shall | | | Not auto-tested yet |
| EAA-4.4.2.3-01 | An EAA may have one or more disclosures | may | | | Not auto-tested yet |
| EAA-4.4.2.3-02 | Each disclosure must contain the attribute and binding data | shall | | | Not auto-tested yet |
| EAA-4.4.2.3-03 | Disclosure incorporation and placement is profile-specific | shall | | | Not auto-tested yet |
| EAA-4.4.2.4-01 | Each disclosure reference must be unambiguously bound to one disclosure | shall | | | Not auto-tested yet |
| EAA-4.4.2.4-02 | Disclosure-to-reference binding must be ascertainable by an algorithm | shall | | | Not auto-tested yet |
| EAA-4.4.2.4-03 | EAA may include validity information for a set of disclosure references | may | | | Not auto-tested yet |
| EAA-4.4.2.4-04 | All disclosure references must be signed by the EAA issuer | shall | | | Not auto-tested yet |
| EAA-4.4.2.4-05 | Disclosures and disclosure references must be present together or absent together | shall | | | Not auto-tested yet |
| EAA-4.4.2.4-06 | Disclosure-reference computation, incorporation, and placement is profile-specific | shall | | | Not auto-tested yet |
| EAA-4.4.2.5-01 | Disclosure algorithm identifier must name the binding-verification algorithm | shall | | | Not auto-tested yet |
| EAA-4.4.2.5-02 | An EAA may incorporate the disclosure algorithm identifier | may | | | Not auto-tested yet |
| EAA-4.4.2.5-03 | Disclosure algorithm identifier must include the algorithm id and may include parameters | shall | | | Not auto-tested yet |
| EAA-4.4.2.5-04 | Disclosure algorithm identifier incorporation and placement is profile-specific | shall | | | Not auto-tested yet |
| EAA-4.5-01 | An EAA should incorporate proof of public-key possession by the EAA subject | should | | | Not auto-tested yet |
| EAA-4.5-02 | Key-binding component value may be a key, certificate, or reference to either | may | | | Not auto-tested yet |
| EAA-4.5-03 | Pointer-valued key binding must include a digest of the referenced object | shall | | | Not auto-tested yet |
| EAA-4.5-04 | Key-binding component should be a public key for security and privacy | should | | | Not auto-tested yet |
| EAA-4.6.1-01 | An EAA must incorporate a digital signature from the issuer | shall | | | Not auto-tested yet |
| EAA-4.6.1-02 | Digital signature must be AdES-B-B where the syntax permits | shall | | | Not auto-tested yet |
| EAA-4.6.1-03 | Selective disclosures must be placed in the unsigned-attributes container | shall | | | Not auto-tested yet |
| EAA-4.6.1-04 | AdES-B-B disclosures must use the AdES unsigned-attributes container | shall | | | Not auto-tested yet |
| EAA-4.6.1-05 | EAA signature may include the signing certificate | may | | | Not auto-tested yet |
| EAA-4.6.1-06 | EAA signature may include certification-path certificates except the trust anchor | may | | | Not auto-tested yet |
| EAA-4.6.1-07 | Signing certificate must meet the EAA profile in ETSI TS 119 412-6 | shall | | | Not auto-tested yet |
| EAA-5.1-01 | Clause 5 EAAs must be implemented as SD-JWT VC | shall | | | Auto-tested |
| EAA-5.2.1.2-01 | SD-JWT VC EAA must include the vct claim | shall | | | Auto-tested |
| EAA-5.2.1.2-03 | SD-JWT VC EAA must include vct#integrity | shall | | | Auto-tested |
| EAA-5.2.10.1-01 | status component implements the EAA status semantics | shall | | | Not auto-tested yet |
| EAA-5.2.10.1-02 | EAA may incorporate the status component | may | | | Not auto-tested yet |
| EAA-5.2.10.1-03 | status component must be a JSON Object | shall | | | Auto-tested |
| EAA-5.2.10.1-04 | Status JSON Object must include the type member | shall | | | Auto-tested |
| EAA-5.2.10.1-05 | status type member must be a JSON String, e.g. TokenStatusList | shall | | | Auto-tested |
| EAA-5.2.10.1-06 | Status JSON Object must include the purpose member | shall | | | Auto-tested |
| EAA-5.2.10.1-07 | status purpose member must be a JSON String | shall | | | Auto-tested |
| EAA-5.2.10.1-08 | Status JSON Object must include the index member | shall | | | Auto-tested |
| EAA-5.2.10.1-09 | status index member must be a JSON Integer | shall | | | Auto-tested |
| EAA-5.2.10.1-10 | Status JSON Object must include the uri member | shall | | | Auto-tested |
| EAA-5.2.10.1-11 | status uri member must point to the status list URL | shall | | | Auto-tested |
| EAA-5.2.10.1-12 | status object may include additional members | may | | | Not auto-tested yet |
| EAA-5.2.10.2-01 | status URI must resolve to a parseable Token Status List | shall | | | Auto-tested |
| EAA-5.2.11-01 | SD-JWT VC EAA must not encode renewal-service semantics | shall | | | Not auto-tested yet |
| EAA-5.2.12-01 | EAA may incorporate the shortLived claim | may | | | Not auto-tested yet |
| EAA-5.2.12-02 | shortLived claim must use the JSON null primitive type | shall | | | Auto-tested |
| EAA-5.2.4.1-01 | EAA may include the issuing_authority claim | may | | | Auto-tested |
| EAA-5.2.4.1-03 | issuing_authority must not coexist with the qualified certificate | shall | | - EAA payload
- EAA header
- Issuer cert
| Auto-tested |
| EAA-5.2.5.1-01 | sub claim implements the EAA subject identifier semantics | shall | | | Auto-tested |
| EAA-5.2.5.1-02 | EAA may include sub, also_known_as, or neither | may | | | Not auto-tested yet |
| EAA-5.2.5.2-01 | also_known_as claim implements subject pseudonym semantics | shall | | | Not auto-tested yet |
| EAA-5.2.5.2-02 | also_known_as claim must be a JSON String | shall | | | Auto-tested |
| EAA-5.2.5.3-01 | EAA may contain attributes referring to different entities | may | | | Not auto-tested yet |
| EAA-5.2.5.3-02 | Non-subject attributes need an attribute-subject identifier or pseudonym | shall | | | Auto-tested |
| EAA-5.2.5.3-03 | EAA may associate attributes to a non-subject identifier | may | | | Not auto-tested yet |
| EAA-5.2.5.4-01 | EAA may associate attributes to a non-subject pseudonym | may | | | Not auto-tested yet |
| EAA-5.2.6-01 | iat claim implements EAA issuance-time semantics | shall | | | Auto-tested |
| EAA-5.2.6-02 | EAA may incorporate the iat claim | may | | | Not auto-tested yet |
| EAA-5.2.7.1-01 | EAA includes the nbf claim for technical-validity start | shall | | | Auto-tested |
| EAA-5.2.7.1-02 | nbf marks the start of the technical-validity period | shall | | | Auto-tested |
| EAA-5.2.7.1-03 | EAA includes the exp claim for technical-validity end | shall | | | Auto-tested |
| EAA-5.2.7.1-04 | exp marks the end of the technical-validity period | shall | | | Auto-tested |
| EAA-5.2.7.2-01 | EAA may include the adm_nbf administrative-validity claim | may | | | Not auto-tested yet |
| EAA-5.2.7.2-02 | adm_nbf marks the start of the administrative-validity period | shall | | | Auto-tested |
| EAA-5.2.7.2-03 | EAA may include the adm_exp administrative-validity claim | may | | | Not auto-tested yet |
| EAA-5.2.7.2-04 | adm_exp marks the end of the administrative-validity period | shall | | | Auto-tested |
| EAA-5.2.7.2-05 | adm_nbf and adm_exp must appear together or not at all | shall | | | Auto-tested |
| EAA-5.2.7.2-06 | adm_nbf and adm_exp must use the NumericDate format | shall | | | Auto-tested |
| EAA-5.2.8.1-01 | SD-JWT VC EAA must not encode an audience constraint | shall | | | Auto-tested |
| EAA-5.2.8.2-01 | oneTime claim implements the one-time-use semantics | shall | | | Not auto-tested yet |
| EAA-5.2.8.2-02 | EAA may incorporate the oneTime claim | may | | | Not auto-tested yet |
| EAA-5.2.8.2-03 | Presence of oneTime claim restricts the EAA to single use | shall | | | Not auto-tested yet |
| EAA-5.2.8.2-04 | Absence of oneTime claim removes the single-use constraint | shall | | | Not auto-tested yet |
| EAA-5.2.8.2-05 | oneTime claim must use the JSON null primitive type | shall | | | Auto-tested |
| EAA-5.2.9-01 | EAA may incorporate the evidence claim | may | | | Not auto-tested yet |
| EAA-5.3-01 | Disclosable attributes require corresponding SD-JWT disclosures | shall | | | Auto-tested |
| EAA-5.3-02 | Non-subject attribute groupings require the subAttrs claim | shall | | | Not auto-tested yet |
| EAA-5.3-03 | subAttrs must have either sub_id or sub_aka | shall | | | Auto-tested |
| EAA-5.3-04 | sub_id is a JSON String identifying the attribute subject | shall | | | Auto-tested |
| EAA-5.3-05 | sub_aka is a JSON String holding the attribute-subject pseudonym | shall | | | Auto-tested |
| EAA-5.3-06 | subAttrs must include the attrs member | shall | | | Auto-tested |
| EAA-5.3-07 | attrs is a JSON Array of attributes for the named subject | shall | | | Auto-tested |
| EAA-5.4.1.1-01 | EAA must support SD-JWT selective disclosure | shall | | | Auto-tested |
| EAA-5.4.1.2-01 | Disclosure schema is implicit; no identifier in the EAA | shall | | | Auto-tested |
| EAA-5.4.1.3-01 | One disclosure per selectively-disclosable attribute | shall | | | Auto-tested |
| EAA-5.4.1.3-02 | Serialised EAA must carry its disclosures per IETF SD-JWT | shall | | | Auto-tested |
| EAA-5.4.1.4-01 | Selectively-disclosable JSON properties require the _sd component | shall | | | Auto-tested |
| EAA-5.4.1.4-02 | Selectively-disclosable array elements replaced by disclosure digests | shall | | | Auto-tested |
| EAA-5.4.1.5-01 | _sd_alg implements the disclosure-algorithm-identifier semantics | shall | | | Auto-tested |
| EAA-5.4.1.5-02 | _sd_alg must be present when disclosures exist | shall | | | Auto-tested |
| EAA-5.5-01 | EAA should incorporate the cnf claim for key binding | should | | | Auto-tested |
| EAA-5.5-02 | cnf carries the subject public key or subject certificate only | may | | | Auto-tested |
| EAA-5.5-03 | Subject certificate in cnf via x5c, x5t#S256, or x5u | may | | | Not auto-tested yet |
| EAA-5.5-04 | x5u in cnf must be paired with x5t#S256 | shall | | | Auto-tested |
| EAA-5.5-05 | x5c in cnf excludes x5u and x5t#S256 | shall | | | Auto-tested |
| EAA-5.5-06 | cnf should carry the subject public key, not certificate | should | | | Auto-tested |
| EAA-5.6.1-01 | Non-compact EAA signatures must be JAdES | shall | | | Not auto-tested yet |
| EAA-6.1-01 | Data structures shall be those of ISO/IEC 18013-5 | shall | | | Auto-tested |
| EAA-6.1-02 | mDL shall carry org.iso.18013.5.1 namespace data elements | shall | | | Auto-tested |
| EAA-6.1-03 | Non-mDL shall carry org.iso.23220.1 namespace data elements | shall | | | Auto-tested |
| EAA-6.1-04 | New data elements shall sit in org.etsi.01947201.010101 namespace | shall | | | Auto-tested |
| EAA-6.1-05 | mDL presence column of Table 5 of ISO/IEC 18013-5 applies | shall | | | Auto-tested |
| EAA-6.1-06 | Non-mDL type document shall specify mandatory data elements | shall | | | Auto-tested |
| EAA-6.1-07 | EAA shall be an instance of IssuerSigned per ISO/IEC 18013-5 | shall | | | Auto-tested |
| EAA-6.1-08 | New tstr elements shall encode in Unicode unless stated otherwise | shall | | | Auto-tested |
| EAA-6.2.10.1-01 | MSO may carry status member | may | | | Auto-tested |
| EAA-6.2.10.1-02 | status member implements clause 4.2.11 semantics | shall | | | Auto-tested |
| EAA-6.2.10.1-03 | status may contain status_list per IETF Token Status List | may | | | Auto-tested |
| EAA-6.2.10.1-04 | When status is present, the type member shall be present | shall | | | Auto-tested |
| EAA-6.2.10.1-06 | When status is present, the purpose member shall be present | shall | | | Auto-tested |
| EAA-6.2.10.1-08 | When status is present, the index member shall be present | shall | | | Auto-tested |
| EAA-6.2.10.1-10 | When status is present, the uri member shall be present | shall | | | Auto-tested |
| EAA-6.2.10.2-01 | Runtime status resolver for mdoc EAA | shall | | | Auto-tested |
| EAA-6.2.11-01 | ISO/IEC-mdoc EAA shall not carry a renewal-service component | shall | | | Auto-tested |
| EAA-6.2.12-01 | ISO/IEC-mdoc EAA may incorporate the shortLived data element | may | | | Auto-tested |
| EAA-6.2.12-02 | shortLived implements clause 4.2.13 semantics | shall | | | Auto-tested |
| EAA-6.2.12-03 | shortLived data element shall have CBOR bool type | shall | | | Auto-tested |
| EAA-6.2.12-04 | shortLived true bypasses revocation status check | shall | | | Auto-tested |
| EAA-6.2.12-05 | shortLived false or absent requires revocation status check | shall | | | Auto-tested |
| EAA-6.2.2.1-01 | Non-qualified, non-public-body EU mdoc shall not include category | shall | | | Auto-tested |
| EAA-6.2.2.1-02 | category data element implements clause 4.2.2 semantics | shall | | | Auto-tested |
| EAA-6.2.2.1-03 | category data element shall be of tstr type | shall | | | Auto-tested |
| EAA-6.2.3-01 | ISO/IEC-mdoc EAA shall incorporate the document_number element | shall | | | Auto-tested |
| EAA-6.2.3-02 | document_number implements clause 4.2.3 semantics | shall | | | Auto-tested |
| EAA-6.2.3-03 | mDL document_number shall match Table 5 of ISO/IEC 18013-5 | shall | | | Auto-tested |
| EAA-6.2.3-04 | Non-mDL document_number shall match clause 6.3 of ISO/IEC 23220-2 | shall | | | Auto-tested |
| EAA-6.2.4.1-01 | mDL shall include issuing_authority component | shall | | | Auto-tested |
| EAA-6.2.4.1-02 | issuing_authority implements clause 4.2.4 semantics | shall | | | Auto-tested |
| EAA-6.2.4.1-03 | Non-mDL shall include the unicode issuing-authority element | shall | | | Auto-tested |
| EAA-6.2.4.1-04 | issuing_authority_unicode implements clause 4.2.4 semantics | shall | | | Auto-tested |
| EAA-6.2.4.1-05 | ISO/IEC-mdoc EAA may incorporate issuing_country | may | | | Auto-tested |
| EAA-6.2.4.1-06 | mDL issuing_country shall match Table 5 of ISO/IEC 18013-5 | shall | | | Auto-tested |
| EAA-6.2.4.1-07 | Non-mDL issuing_country shall match clause 6.3 of ISO/IEC 23220-2 | shall | | | Auto-tested |
| EAA-6.2.4.1-08 | Optional issuing_country value shall match EAA-4.2.4.1-05 | shall | | | Auto-tested |
| EAA-6.2.4.1-09 | ISO/IEC-mdoc EAA may include iss_reg_id where applicable | may | | | Auto-tested |
| EAA-6.2.4.1-10 | iss_reg_id data element shall be of tstr type | shall | | | Auto-tested |
| EAA-6.2.4.1-11 | iss_reg_id value shall be a registration identifier | shall | | | Auto-tested |
| EAA-6.2.4.1-12 | iss_reg_id value may follow ETSI EN 319 412-1 LEG-5.1.4 rules | may | | | Auto-tested |
| EAA-6.2.4.1-13 | iss_reg_id mutex with embedded qualified certificate | shall | | | Auto-tested |
| EAA-6.2.5.1-01 | mDL identifying its subject shall include the standard triplet | shall | | | Auto-tested |
| EAA-6.2.5.1-02 | mDL shall include either the standard triplet or also_known_as | shall | | | Auto-tested |
| EAA-6.2.5.1-03 | also_known_as data element shall be of tstr type | shall | | | Auto-tested |
| EAA-6.2.5.1-04 | Non-mDL identifying its subject shall include the standard triplet | shall | | | Auto-tested |
| EAA-6.2.5.1-05 | Non-mDL shall include either the standard triplet or also_known_as | shall | | | Auto-tested |
| EAA-6.2.5.2-01 | ISO/IEC-mdoc EAA may carry also_known_as as subject pseudonym | may | | | Auto-tested |
| EAA-6.2.5.3-01 | ISO/IEC-mdoc EAA may include attribute subjects | may | | | Auto-tested |
| EAA-6.2.5.3-02 | Attribute subjects may be identified or pseudonymised | may | | | Auto-tested |
| EAA-6.2.5.3-03 | Attribute subject identifiers shall associate to their attributes | shall | | | Auto-tested |
| EAA-6.2.5.4-01 | ISO/IEC-mdoc EAA may include attribute subject pseudonyms | may | | | Auto-tested |
| EAA-6.2.5.4-02 | Attribute subject pseudonyms shall associate to their attributes | shall | | | Auto-tested |
| EAA-6.2.6-01 | ISO/IEC-mdoc EAA shall incorporate issue_date | shall | | | Auto-tested |
| EAA-6.2.6-02 | issue_date implements clause 4.2.7 semantics | shall | | | Auto-tested |
| EAA-6.2.6-03 | mDL issue_date shall match Table 5 of ISO/IEC 18013-5 | shall | | | Auto-tested |
| EAA-6.2.6-04 | Non-mDL issue_date shall match clause 6.3 of ISO/IEC 23220-2 | shall | | | Auto-tested |
| EAA-6.2.7.1-01 | validityInfo.validFrom marks technical validity start | shall | | | Auto-tested |
| EAA-6.2.7.1-02 | validityInfo.validUntil marks technical validity end | shall | | | Auto-tested |
| EAA-6.2.7.1-03 | validFrom and validUntil shall indicate UTC time | shall | | | Auto-tested |
| EAA-6.2.7.1-04 | validFrom and validUntil shall have seconds precision | shall | | | Auto-tested |
| EAA-6.2.7.1-05 | validFrom and validUntil shall not contain fractions of seconds | shall | | | Auto-tested |
| EAA-6.2.7.2-01 | mDL expiry_date marks administrative validity end | shall | | | Auto-tested |
| EAA-6.2.7.2-02 | Non-mDL expiry_date marks administrative validity end | shall | | | Auto-tested |
| EAA-6.2.7.2-03 | issue_date may mark administrative validity start | may | | | Auto-tested |
| EAA-6.2.8.1-01 | ISO/IEC-mdoc EAA shall not carry an audience component | shall | | | Auto-tested |
| EAA-6.2.8.2-01 | ISO/IEC-mdoc EAA may incorporate the oneTime data element | may | | | Auto-tested |
| EAA-6.2.8.2-02 | oneTime implements clause 4.2.9.3 semantics | shall | | | Auto-tested |
| EAA-6.2.8.2-03 | oneTime data element shall have CBOR bool type | shall | | | Auto-tested |
| EAA-6.2.8.2-04 | oneTime true means single-use, no retention | shall | | | Auto-tested |
| EAA-6.2.8.2-05 | oneTime false or absent removes the constraint | shall | | | Auto-tested |
| EAA-6.2.9-01 | ISO/IEC-mdoc EAA shall not carry attributes-evidence component | shall | | | Auto-tested |
| EAA-6.3-01 | Attested attributes shall be carried in IssuerSignedItem components | shall | | | Auto-tested |
| EAA-6.3-02 | Non-EAA-subject attributes shall use SubAttr in elementValue | shall | | | Auto-tested |
| EAA-6.3-03 | SubAttr shall have either subId or subAka member | shall | | | Auto-tested |
| EAA-6.3-04 | subId shall be a CBOR map identifying the attribute subject | shall | | | Auto-tested |
| EAA-6.3-05 | subAka shall be a CBOR String pseudonym | shall | | | Auto-tested |
| EAA-6.4.1.2-01 | ISO/IEC-mdoc EAA shall include version in MobileSecurityObject | shall | | | Auto-tested |
| EAA-6.4.1.3-01 | Disclosable attributes shall ride in IssuerSignedItem components | shall | | | Auto-tested |
| EAA-6.4.1.4-01 | valueDigests implements clause 4.4.2.3 semantics | shall | | | Auto-tested |
| EAA-6.4.1.4-02 | Disclosable mdoc shall include valueDigests in MSO | shall | | | Auto-tested |
| EAA-6.4.1.5-01 | Disclosable mdoc shall include digestAlgorithm in MSO | shall | | | Auto-tested |
| EAA-6.5-01 | deviceKey shall sit within deviceKeyInfo of MSO | shall | | | Auto-tested |
| EAA-6.5-02 | deviceKey shall be the EAA subject's public key | shall | | | Auto-tested |
| EAA-6.6.1-01 | ISO/IEC-mdoc EAA shall be signed by a CB-AdES digital signature | shall | | | Auto-tested |
| PuB-EAA-4.2.11.3-01 | A non-short-lived PuB-EAA must include the EAA status service | shall | | | Not auto-tested yet |
| PuB-EAA-4.2.2.3-01 | A PuB-EAA must explicitly signal its PuB-EAA condition | shall | | | Not auto-tested yet |
| PuB-EAA-4.2.2.3-02 | PuB-EAA URI category value must be urn:etsi:esi:eaa:eu:pub | shall | | | Not auto-tested yet |
| PuB-EAA-4.2.4.3-01 | A PuB-EAA must incorporate the EAA issuer identifier | shall | | | Not auto-tested yet |
| PuB-EAA-4.2.4.3-02 | A PuB-EAA must include the issuer's EU Member State identifier | shall | | | Not auto-tested yet |
| PuB-EAA-4.2.4.3-03 | PuB-EAA Member State identifier must follow the EAA-4.2.4.1-05 format | shall | | | Not auto-tested yet |
| PuB-EAA-4.2.4.3-04 | A PuB-EAA must include the issuing public body's registration identifier | shall | | | Not auto-tested yet |
| PuB-EAA-4.2.4.3-05 | PuB-EAA registration id must follow ETSI EN 319 412-1 clause 5.1.4 | shall | | | Not auto-tested yet |
| PuB-EAA-4.2.4.3-06 | A PuB-EAA must include the name of the issuing public body | shall | | | Not auto-tested yet |
| PuB-EAA-4.2.4.3-07 | A PuB-EAA must include the download URL of the supporting certificate | shall | | | Not auto-tested yet |
| PuB-EAA-4.2.6.8-01 | A PuB-EAA must include either the EAA subject identifier or its pseudonym | shall | | | Not auto-tested yet |
| PuB-EAA-4.2.6.8-02 | All attributes in a PuB-EAA must refer to a single entity, the EAA subject | shall | | | Not auto-tested yet |
| PuB-EAA-4.6.3-01 | PuB-EAA digital signature must be a qualified electronic signature or seal | shall | | | Not auto-tested yet |
| PuB-EAA-4.6.3-02 | PuB-EAA signature must include certificate URL and digest as signed attributes | shall | | | Not auto-tested yet |
| PuB-EAA-4.6.3-03 | PuB-EAA signature should embed the qualified certificate | should | | | Not auto-tested yet |
| PuB-EAA-4.6.3-04 | PuB-EAA signing certificate must meet the PSB profile in ETSI TS 119 412-6 | shall | | | Not auto-tested yet |
| PuB-EAA-5.2.10.3-01 | PuB-EAA without shortLived must carry a status claim | shall | | | Not auto-tested yet |
| PuB-EAA-5.2.4.3-02 | PuB-EAA must declare the issuer's country of establishment | shall | | | Auto-tested |
| PuB-EAA-5.2.4.3-03 | Legal-person PuB-EAA includes a registration identifier | shall | | | Auto-tested |
| PuB-EAA-5.2.4.3-04 | iss_reg_id follows ETSI organisation-identifier rules | shall | | | Auto-tested |
| PuB-EAA-5.2.5.6-01 | PuB-EAA attributes must all refer to the EAA subject | shall | | | Not auto-tested yet |
| PuB-EAA-5.6.3-02 | PuB-EAA protected header must include x5u and x5t#S256 | shall | | | Not auto-tested yet |
| PuB-EAA-5.6.3-03 | PuB-EAA protected header should include x5c | should | | | Not auto-tested yet |
| PuB-EAA-6.2.10.3-01 | PuB-EAA without shortLived shall carry status in MSO | shall | | | Auto-tested |
| PuB-EAA-6.2.2.3-01 | ISO/IEC-mdoc PuB-EAA shall include category data element | shall | | | Auto-tested |
| PuB-EAA-6.2.2.3-02 | PuB-EAA category value shall be the public-body URN | shall | | | Auto-tested |
| PuB-EAA-6.2.4.3-01 | PuB-EAA shall carry registration identifier where applicable | shall | | | Auto-tested |
| PuB-EAA-6.2.4.3-02 | PuB-EAA iss_reg_id shall match organizationIdentifier rules | shall | | | Auto-tested |
| PuB-EAA-6.2.5.6-01 | ISO/IEC-mdoc PuB-EAA attributes shall refer to the EAA subject | shall | | | Auto-tested |
| PuB-EAA-6.6.3-01 | PuB-EAA CB-AdES shall be a qualified electronic signature or seal | shall | | | Auto-tested |
| PuB-EAA-6.6.3-02 | PuB-EAA Protected Header shall contain x5u and x5t | shall | | | Auto-tested |
| PuB-EAA-6.6.3-03 | PuB-EAA x5t digest algorithm shall be SHA-256 | shall | | | Auto-tested |
| PuB-EAA-6.6.3-04 | PuB-EAA Protected Header should contain x5chain | should | | | Auto-tested |
| QEAA-4.2.11.2-01 | A non-short-lived QEAA must include the EAA status service | shall | | | Not auto-tested yet |
| QEAA-4.2.2.2-01 | A QEAA must signal its qualified condition via the EAA category | shall | | | Not auto-tested yet |
| QEAA-4.2.2.2-02 | QEAA URI category value must be urn:etsi:esi:eaa:eu:qualified | shall | | | Not auto-tested yet |
| QEAA-4.2.4.2-01 | A QEAA must incorporate the EAA issuer identifier | shall | | | Not auto-tested yet |
| QEAA-4.2.4.2-02 | A QEAA must include the issuer's EU Member State identifier | shall | | | Not auto-tested yet |
| QEAA-4.2.4.2-03 | QEAA Member State identifier must follow the EAA-4.2.4.1-05 format | shall | | | Not auto-tested yet |
| QEAA-4.2.4.2-04 | Legal-person QEAA issuer must include a registration identifier | shall | | | Not auto-tested yet |
| QEAA-4.2.4.2-05 | Legal-person QEAA registration id must follow ETSI EN 319 412-1 clause 5.1.4 | shall | | | Not auto-tested yet |
| QEAA-4.2.4.2-06 | Legal-person QEAA must include the legal-person name | shall | | | Not auto-tested yet |
| QEAA-4.2.4.2-07 | Natural-person QEAA must include the natural-person name | shall | | | Not auto-tested yet |
| QEAA-4.2.4.2-08 | A QEAA must include the download URL of the supporting certificate | shall | | | Not auto-tested yet |
| QEAA-4.2.6.7-02 | All attributes in a QEAA must refer to a single entity, the QEAA subject | shall | | | Not auto-tested yet |
| QEAA-4.6.2-01 | QEAA digital signature must be a qualified electronic signature or seal | shall | | | Not auto-tested yet |
| QEAA-4.6.2-02 | QEAA signature must include certificate URL and digest as signed attributes | shall | | | Not auto-tested yet |
| QEAA-4.6.2-03 | QEAA signature should embed the qualified certificate | should | | | Not auto-tested yet |
| QEAA-4.6.2-04 | QEAA signing certificate must meet the QEAA profile in ETSI TS 119 412-6 | shall | | | Not auto-tested yet |
| QEAA-5.2.10.2-01 | QEAA without shortLived must carry a status claim | shall | | | Not auto-tested yet |
| QEAA-5.2.5.5-01 | QEAA attributes must all refer to the EAA subject | shall | | | Auto-tested |
| QEAA-5.6.2-01 | QEAA signature must be a qualified signature or qualified seal | shall | | | Not auto-tested yet |
| QEAA-5.6.2-02 | QEAA protected header must include x5u and x5t#S256 | shall | | | Not auto-tested yet |
| QEAA-5.6.2-03 | QEAA protected header should include x5c | should | | | Not auto-tested yet |
| QEAA-6.2.10.2-01 | QEAA without shortLived shall carry status in MSO | shall | | | Auto-tested |
| QEAA-6.2.2.2-01 | ISO/IEC-mdoc QEAA shall include category data element | shall | | | Auto-tested |
| QEAA-6.2.2.2-02 | QEAA category value shall be the qualified URN | shall | | | Auto-tested |
| QEAA-6.2.4.2-01 | Legal-person QEAA shall carry registration identifier | shall | | | Auto-tested |
| QEAA-6.2.4.2-02 | QEAA iss_reg_id shall match organizationIdentifier rules | shall | | | Auto-tested |
| QEAA-6.2.5.5-01 | ISO/IEC-mdoc QEAA attributes shall refer to the EAA subject | shall | | | Auto-tested |
| QEAA-6.6.2-01 | QEAA CB-AdES shall be a qualified electronic signature or seal | shall | | | Auto-tested |
| QEAA-6.6.2-02 | QEAA Protected Header shall contain x5u and x5t | shall | | | Auto-tested |
| QEAA-6.6.2-03 | QEAA x5t digest algorithm shall be SHA-256 | shall | | | Auto-tested |
| QEAA-6.6.2-04 | QEAA Protected Header should contain x5chain | should | | | Auto-tested |