SOL-07 — Multi-factor user authentication at LoA high
Where the WSCA verifies UAE for LoA high, the verification shall ensure protection against duplication, tampering, and high attack potential. The wallet instance captures knowledge + possession factors; the WSCA verifies the artefact before authorising cryptographic operations.
| Property | Value |
|---|---|
| Section | TR 4.1 §6.3 |
Mapped Controls
| Control | Title |
|---|---|
| SID-AUTH-01 | FIDO2/WebAuthn Passwordless Authentication |
| SID-KEY-04 | R2PS Remote WSCD SCAL2 Compliance |
| SID-AUTH-05 | Wallet Unlock, Lockout, and PIN Security |
Source: Nordic EUDIW Common Certification System (NOBCCS) v0.4, June 2026