Skip to main content

SOL-07 — Multi-factor user authentication at LoA high

Where the WSCA verifies UAE for LoA high, the verification shall ensure protection against duplication, tampering, and high attack potential. The wallet instance captures knowledge + possession factors; the WSCA verifies the artefact before authorising cryptographic operations.

PropertyValue
SectionTR 4.1 §6.3

Mapped Controls

ControlTitle
SID-AUTH-01FIDO2/WebAuthn Passwordless Authentication
SID-KEY-04R2PS Remote WSCD SCAL2 Compliance
SID-AUTH-05Wallet Unlock, Lockout, and PIN Security

Source: Nordic EUDIW Common Certification System (NOBCCS) v0.4, June 2026