Our Credentials Are Not the Credential the Regulation Means
What we issue is not a person identification credential in the regulatory sense, and the distinction is the whole page. Nothing here is legal advice.
Two things called an identity credential
One is a regulatory artefact. The person identification credential the European framework defines is issued by or on behalf of a Member State, carries a defined attribute schema, and comes with legal recognition. A relying party accepting it is accepting something a state stands behind.
The other is a commercial attestation. A business verifies somebody and issues a signed statement about what it found. Useful and checkable, and standing on that business's own credibility rather than on a state's.
They are both credentials, they use overlapping technology, and they are not substitutes for each other. Confusing them is how a buyer ends up believing they procured legal recognition.
What we issue
Our credentials record a verification level and the country the verification was performed in. They say, in effect: this party checked this person to this standard, in this jurisdiction, on this date.
They are not person identification credentials. They do not map onto the regulatory attribute schema, they are not issued by or on behalf of any Member State, and they carry no legal recognition of any kind.
A credential shaped like the regulatory one is a roadmap item, and even that would be a shape rather than a status: producing a document with the right fields does not make it the thing the regulation means, because the recognition comes from who issued it rather than from what it contains.
Why the distinction is commercial rather than pedantic
Because it determines what a relying party is relying on.
Accept a state-backed credential and you are relying on a Member State's identification process, with whatever legal effect that carries in your jurisdiction.
That is a much smaller thing to rely on, and it should be priced as such. A buyer who treats the two as interchangeable has substituted a startup's word for a government's without noticing.
Where that leaves the commercial attestation as a category
Not nowhere, which is the part worth arguing.
Most of what businesses verify is not covered by any state credential. Employment, professional standing, membership, account history, a check performed to a particular standard for a particular purpose. A state credential proves who you are; it does not prove what a business found out about you.
So the honest framing is that the two coexist: the regulatory credential answers identity with legal weight, and commercial attestations carry everything else. The mistake is a vendor implying its commercial attestation carries the first kind of weight.
What to ask any vendor here
"Is this a state-recognised credential or a commercial attestation?" The single question, and the answer changes what you are relying on entirely.
"Who stands behind it if it is wrong?" For a state credential, a state.
"Does it map onto the regulatory attribute schema?" Shape is not status, and a vendor offering shape as though it were status should be pressed.
"What does the credential tell me about how strong the original check was?" If nothing, you are assuming, and assumptions are what an examination finds.
Where this leaves a decision
If your requirement is a credential with legal recognition, only a Member State or a body acting for one can supply it, and no vendor claim substitutes for that.
If your requirement is a checkable record of what a business verified, to what standard and where, that is what we issue, the assurance level travels with it so you can price it, and its weight is exactly our credibility rather than anybody else's.