ANNEX IVSupplementary provisions
ANNEX IV Requirements for wallet-relying party access certificates referred to in Article 7 1. The wallet-relying party access certificate policy applicable to the provision of wallet-relying party access certificates shall describe the security requirements that apply to, and the rules that indicate the applicability of, a wallet-relying party access certificate so that wallet-relying parties can be issued with and use those certificates in their interactions with wallet solutions. 2. The wallet-relying party access certificate practice statement applicable to the provision of wallet-relying party access certificates shall describe the practices that a provider of wallet-relying party access certificates employs in issuing, managing, revoking, and re-keying wallet-relying party access certificates. 3. The certificate policy and certificate practice statement applicable to the provision of wallet-relying party access certificates shall be syntactically and semantically harmonised across the Union and shall, as applicable, comply with at least the normalised certificate policy (‘NCP’) requirements as specified in standard ETSI EN 319411-1 version 1.4.1 (2023-10), and shall include: (a) a clear description of the public key infrastructure hierarchy and certification paths from the end-entity wallet-relying party access certificates up to the top of the hierarchy used for issuing them, indicating the expected trust anchor(s) in such hierarchy and paths which should rely on the trust framework established in accordance with Article 5a(18) of Regulation (EU) No 910/2014; (b) a comprehensive description of the procedures for the issuance of wallet-relying party access certificates, including for the verification of the identity and any other attributes of the wallet-relying party to which a wallet-relying party certificate is to be issued; (c) the obligation for the providers of wallet-relying party access certificates, when issuing a wallet-relying party access certificate, to verify that: — the wallet-relying party is included, with a valid registration status, in a national register of wallet-relying parties of the Member State in which that wallet-relying party is established; — any information in the wallet-relying party access certificate is accurate and consistent with the registration information available from that register. (d) a comprehensive description of the procedures for revocation of wallet-relying party access certificates; (e) the obligation for the providers of wallet-relying party access certificates to implement measures and processes on: — continuously monitoring any changes in the national register for wallet-relying parties in which wallet-relying parties to whom they have issued wallet-relying party access certificates are registered; — revoking, when changes require, any wallet-relying party certificate that the provider issued to the corresponding wallet-relying party, in particular when the content of the certificate is no longer accurate and consistent with the information registered, or when the registration of the wallet-relying party is suspended or cancelled. (f) a comprehensive description of the procedures and mechanisms for the harmonised validation of wallet-relying party access certificates across the Union; (g) the obligation for the providers of wallet-relying party access certificates to allow relevant stakeholders, including wallet-relying parties as regards their own certificates, competent supervisory bodies and data protection authorities, to request the revocation of wallet-relying party access certificates; (h) the obligation for the providers of wallet-relying party access certificates to register all such revocations in its certificate database and to publish the revocation status of the certificate in a timely manner, and in any event within 24 hours after receipt of the revocation request; (i) the obligation for the providers of wallet-relying party access certificates to provide information on the validity or revocation status of wallet-relying party certificates issued by that provider; (j) a description, where relevant, on how a provider of wallet-relying party access certificates logs all wallet-relying party access certificates they have issued, in compliance with internet engineering task force (‘IETF’) request for comments (‘RFC’) 9162 Certificate Transparency version 2.0; (k) the obligation for the wallet-relying party access certificates to include: — the location where the certificate supporting the advanced electronic signature or advanced electronic seal on that certificate is available, for the entire certification path to be built up to the expected trust anchor in the public key infrastructure hierarchy used by the provider; — a machine processable reference to the applicable certificate policy and certificate practice statement; — the information referred to in Annex I, points 1, 2, 3, 5, 6 and 7, (a), (b) and (c). 4. The revocation set out in point 3(g) shall become effective immediately upon its publication. 5. The information set out in point 3(h) shall be made available at least on a per certificate basis at any time and at least beyond the validity period of the certificate in an automated manner that is reliable, free of charge and effectively in accordance with the certificate policy.