ISO/IEC 29115:2013 - Entity Authentication Assurance Framework
The international entity authentication assurance framework: four levels of assurance, the enrolment, credential management and authentication phases, and the required controls at each level, from the complete common text ITU-T X.1254 (09/2012). Every leaf read against the full text.
ISO/IEC 29115:2013 - Entity Authentication Assurance Framework is a compliance framework from International (ISO/IEC JTC 1/SC 27 with ITU-T SG 17) with 6 domains and 77 controls that map to 254 other frameworks. The largest domains are Clause 10: Threats and controls – ISO/IEC 29115:2013 - Entity Authentication Assurance Framework (48 controls), Clause 8: EAAF phases (enrolment, credential management, entity authentication) – ISO/IEC 29115:2013 - Entity Authentication Assurance Framework (13 controls), Clause 6: Levels of assurance – ISO/IEC 29115:2013 - Entity Authentication Assurance Framework (7 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
Annex A: Characteristics of a credential – ISO/IEC 29115:2013 - Entity Authentication Assurance Framework
| Code | Title |
|---|---|
| iso-iec-29115-2013-entity-authentication-assurance-framework::A | A Annex A (normative): Characteristics of a credential |
Clause 10: Threats and controls – ISO/IEC 29115:2013 - Entity Authentication Assurance Framework
Clause 11: Service assurance criteria – ISO/IEC 29115:2013 - Entity Authentication Assurance Framework
| Code | Title |
|---|---|
| iso-iec-29115-2013-entity-authentication-assurance-framework::11 | 11 Service assurance criteria |
Clause 6: Levels of assurance – ISO/IEC 29115:2013 - Entity Authentication Assurance Framework
| Code | Title |
|---|---|
| iso-iec-29115-2013-entity-authentication-assurance-framework::6.1 | 6.1 Level of assurance 1 (LoA1) |
| iso-iec-29115-2013-entity-authentication-assurance-framework::6.2 | 6.2 Level of assurance 2 (LoA2) |
| iso-iec-29115-2013-entity-authentication-assurance-framework::6.3 | 6.3 Level of assurance 3 (LoA3) |
| iso-iec-29115-2013-entity-authentication-assurance-framework::6.4 | 6.4 Level of assurance 4 (LoA4) |
| iso-iec-29115-2013-entity-authentication-assurance-framework::6.5 | 6.5 Selecting the appropriate level of assurance |
| iso-iec-29115-2013-entity-authentication-assurance-framework::6.6 | 6.6 LoA mapping and interoperability |
| iso-iec-29115-2013-entity-authentication-assurance-framework::6.7 | 6.7 Exchanging authentication results based on the 4 LoAs |
Clause 8: EAAF phases (enrolment, credential management, entity authentication) – ISO/IEC 29115:2013 - Entity Authentication Assurance Framework
Clause 9: Management and organizational considerations – ISO/IEC 29115:2013 - Entity Authentication Assurance Framework
| Code | Title |
|---|---|
| iso-iec-29115-2013-entity-authentication-assurance-framework::9.1 | 9.1 Service establishment |
| iso-iec-29115-2013-entity-authentication-assurance-framework::9.2 | 9.2 Legal and contractual compliance |
| iso-iec-29115-2013-entity-authentication-assurance-framework::9.3 | 9.3 Financial provisions |
| iso-iec-29115-2013-entity-authentication-assurance-framework::9.4 | 9.4 Information security management and audit |
| iso-iec-29115-2013-entity-authentication-assurance-framework::9.5 | 9.5 External service components |
| iso-iec-29115-2013-entity-authentication-assurance-framework::9.6 | 9.6 Operational infrastructure |
| iso-iec-29115-2013-entity-authentication-assurance-framework::9.7 | 9.7 Measuring operational capabilities |
Your Compliance Coverage
If you comply with ISO/IEC 29115:2013 - Entity Authentication Assurance Framework, you already cover:
Maps to 254 other frameworks
Coverage is not the same as your position
This page shows what ISO/IEC 29115:2013 - Entity Authentication Assurance Framework overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is ISO/IEC 29115:2013 - Entity Authentication Assurance Framework and who does it apply to?
ISO/IEC 29115:2013 - Entity Authentication Assurance Framework is a compliance framework from International (ISO/IEC JTC 1/SC 27 with ITU-T SG 17) with 6 domains and 77 controls. The international entity authentication assurance framework: four levels of assurance, the enrolment, credential management and authentication phases, and the required controls at each level, from the complete common text ITU-T X.1254 (09/2012). Every leaf read against the full text. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO/IEC 29115:2013 - Entity Authentication Assurance Framework actually require?
ISO/IEC 29115:2013 - Entity Authentication Assurance Framework has 77 controls organised across 6 domains. The largest domains are Clause 10: Threats and controls – ISO/IEC 29115:2013 - Entity Authentication Assurance Framework (48 controls), Clause 8: EAAF phases (enrolment, credential management, entity authentication) – ISO/IEC 29115:2013 - Entity Authentication Assurance Framework (13 controls), Clause 6: Levels of assurance – ISO/IEC 29115:2013 - Entity Authentication Assurance Framework (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO/IEC 29115:2013 - Entity Authentication Assurance Framework do I already cover?
ISO/IEC 29115:2013 - Entity Authentication Assurance Framework maps to 254 other compliance frameworks. The top mapping partners are W3C Verifiable Credentials (VC) Data Model 2.0 (4% coverage), SLSA (4% coverage), SIG (Shared Assessments) (4% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement ISO/IEC 29115:2013 - Entity Authentication Assurance Framework?
Start your ISO/IEC 29115:2013 - Entity Authentication Assurance Framework compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 29115:2013 - Entity Authentication Assurance Framework requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 77 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.
Get Started Free →Free forever — no credit card required