Book an Appointment
← Back to BlogIT Security

VamiSec on site in Tallinn: 12th Trust Services and eID Forum & 18th CA-Day 2026 — eIDAS 2.0, EUDI Wallet and the future of trust services

September 13, 2026

VamiSec in Tallinn: Europe's trust community in one place

VamiSec is on site in Tallinn on 15–16 September 2026: at the 12th Trust Services and eID Forum organized by ENISA with the European Commission, and at the 18th CA-Day organized by D-Trust with TÜV NORD Cert. At Kultuurikatel — the former power plant turned creative hub of the Estonian capital — everyone who builds, audits and supervises Europe's digital identity comes together: supervisory bodies, qualified trust service providers (QTSPs), conformity assessment bodies, standardization experts and the EU institutions. On-site seats are sold out — all the more reason we are glad to be there.

The double event: Forum + CA-Day

The Trust Services and eID Forum has been organized by ENISA together with the European Commission since 2015 and is the meeting point of the eIDAS community. The CA-Day — originally a Berlin event by Bundesdruckerei subsidiary D-Trust — has grown into the European flagship event for trust service providers; the two formats have run as a double bill for years. After Vienna (2023), Heraklion (2024) and Split (2025), it is Tallinn's turn in 2026 — flanked by a full theme week with the ETSI ESI CA Open Session, supervisory meetings (FESA/ECATS) and a PQC migration workshop by the EU-funded PQCSA.

Why Tallinn is the right place

Few countries embody digital identity like Estonia: its Digital Signature Act dates back to 2000, the eID card with qualified signature has been issued since 2002 (99% coverage, more than 800 million signatures), the X-Road data exchange layer has been running since 2001, internet voting since 2005, e-Residency since 2014 — and since 2024 the state has declared itself 100% digital. Fittingly, Estonia's Minister of Justice and Digital Affairs, Liisa-Ly Pakosta, opens the Forum; the Estonian Information System Authority (RIA) and the QTSP SK ID Solutions are on the program as well.

Day 1 — Forum: EUDI Wallet, certification and regulatory cross-overs

By 24 December 2026, every EU member state must provide at least one European Digital Identity Wallet — so day 1 focuses on implementation and certification: ENISA reports on the wallet certification scheme, and a five-country panel (including BSI, ANSSI and Estonia's RIA) discusses what it will take to deliver certification by 2027. For us, the session on regulatory cross-overs is particularly relevant: eIDAS meets CRA, NIS2, the planned European Business Wallet and the GDPR — exactly the landscape in which our clients have to make compliance decisions today.

Day 2 — CA-Day: SRP launch, the future of TLS and a quantum fireside

Day 2 gets practical: ENISA presents the Single Reporting Platform to trust service providers — just days after the CRA reporting obligation for actively exploited vulnerabilities and severe incidents went live via that very platform on 11 September 2026. Add the future of TLS certificates, engineering qualified electronic attestations of attributes (QEAA), real-world QTSP compliance from audit practice, the European Business Wallet, trusted agentic AI — and a fireside chat on trust services in the quantum era with Bundesdruckerei, ANSSI and DigiCert.

The deadlines behind the agenda

eIDAS 2.0 (Regulation (EU) 2024/1183) sets a tight pace: wallet provision per member state by 24 December 2026; acceptance obligations for regulated private services using strong user authentication — from banking to energy to telecoms — and for very large online platforms by 24 December 2027. In parallel, new qualified trust services are emerging: electronic archiving and electronic ledgers (implementing regulations of December 2025) and the management of remote signature creation devices. And with the European Business Wallet proposal of 19 November 2025, the next stage for companies is already on the table.

Post-quantum: from discussion item to deadline

The quantum question is no longer science fiction but scheduling: the EU's coordinated roadmap requires national PQC transition strategies by the end of 2026, quantum-safe high-risk use cases by the end of 2030 and largely completed migration by 2035. In February 2026, Germany's BSI announced the end of purely classical encryption from the end of 2031 and of classical signature schemes by the end of 2035. ETSI's TS 119 312 V2.1.1 adds the NIST algorithms ML-DSA and SLH-DSA and hybrid certificates for CA keys to the crypto suites for trust services — including a phase-out of RSA below 3000 bits for new certificates after the end of 2026. Anyone who needs signatures, seals or timestamps to remain evidentially sound long-term needs a crypto-agility plan now.

Why we are on site — and what is in it for you

The cross-overs discussed in Tallinn are our daily business: qualified trust service providers are essential entities under NIS2 regardless of their size, the CRA reporting obligation has been running via the Single Reporting Platform since 11 September, and eIDAS requirements end up in the same management systems that also have to carry ISO 27001, ISO 42001 or DORA. That is exactly what we do: building integrated management systems, preparing organizations for audits and mapping more than 50 standards in VamiGRC on an OSCAL basis — custom catalogs included. Are you in Tallinn, or do you want to translate the results of these two days for your organisation? Write to contact@vamisec.com — or meet us live at it-sa in Nuremberg six weeks later: https://vamisec.com/en/it-sa-2026.

All links for the event

Event page & online registration: https://www.enisa.europa.eu/events/trust-services-and-eid-forum-ca-day-2026 · Detailed agenda (PDF, version of 7 Sep 2026): https://www.enisa.europa.eu/sites/default/files/2026-09/Agenda_TSF_CAD_20260907.pdf · Practical information for the event week (PDF): https://www.enisa.europa.eu/media/57342 · ETSI ESI CA Open Session on 14 Sep: https://www.etsi.org/events/etsi-esi-certification-authority-ca-open-session/ · PQCSA PQC migration workshop on 17 Sep: https://pqcsa.eu/events.html · eIDAS 2.0 full text (Regulation (EU) 2024/1183): https://eur-lex.europa.eu/eli/reg/2024/1183/oj · Coordinated EU roadmap for post-quantum cryptography: https://digital-strategy.ec.europa.eu/en/library/coordinated-implementation-roadmap-transition-post-quantum-cryptography

Do you have questions about your organization's IT security?

Free Initial Consultation →