
SIS351224I008
ISO/IEC 27001:2022
Mobile-ID information security management system, within the holder and scope printed on the certificate.
Issued: 2024-12-05Printed expiry: 2027-12-04
Review document & scope →Inspect certificates, the data model, policies and evidence before making a deployment decision.
Document availability, applicability and verification needs are separated.
| Domain | Record | State and boundary |
|---|---|---|
| Mobile-ID organization | ISMS and printed scope | Document image available; maintenance status needs verification |
| Identity / PAD module | PCEB 26/04/06 and PCEB 26/04/07 | Not automatically extended to palm sensors/matchers |
| Devices and biometric profiles | Model, versions and compatibility scope | Configuration-specific records and tests required |
| Data and privacy | References, identity, bindings and lifecycle | Mobile-ID-confirmed model; deployment controls need mapping |
| Policies | 13 working documents | No issuance decision supplied |

Mobile-ID information security management system, within the holder and scope printed on the certificate.

eIDAS eID 2.0 module in Trusted Hub Service Provider Appliance QSCD; the certificate states Level 2 on Android phones and iPhones.

The eIDAS eID 2.0 module in Trusted Hub Service Provider Appliance QSCD, with electronic identity and KYC/AML statements at HIGH under the references printed in the document.
| Layer | Evidence | Limit |
|---|---|---|
| Organization | ISMS, holder, certification scope | Does not automatically certify all models or services. |
| Module / device | Version, configuration and evaluation | Do not extend mobile PAD certification to a palm sensor. |
| Customer deployment | Identity source, policy, UAT, operations | Requires acceptance for its own risks and purposes. |
Define purpose, devices, risks and acceptance criteria before scaling.