Denne siden er ennå ikke tilgjengelig på norsk og vises på engelsk. Sider på norsk

SOVEREIGN DEPLOYMENTS · eID AND CBDC INFRASTRUCTURE VENDORS

Vendors that sell sovereignty are audited for it.

No buyer reads a security architecture harder than a government. A vendor whose product is trust infrastructure answers procurement diligence about its own: where its systems stand, who reached which document, which version of the architecture was represented to which ministry. Meanwhile its rulebook is still being written. A sovereign deployment gives the vendor the same property it sells, a record produced inside its own perimeter, as the work happens.

The review is conducted under mutual NDA, with the vendor's security and technical leads in the room. Nothing is uploaded and nothing is trialled.

THE SECTOR AS THE LAW MEETS IT

A rulebook in motion, and buyers who file everything.

Each entry is a published fact with its primary source. Which regime reaches a given vendor, product or contract is a question for the vendor and its counsel, never for a platform.

Of the jurisdictions the selector covers, this sector is verified in one European Union. The others are not yet verified for it, so there is nothing to choose between.

European Union

  • Network security

    The operating rules land on the vendor’s own systems. Trust service providers are among the sectors of high criticality of the network-security directive, and a vendor serving financial entities appears in those clients’ registers of ICT third-party arrangements under the operational-resilience framework, with the contractual and audit duties that follow. Both arrive as questionnaires, contract terms and evidence requests addressed to the vendor.

    Directive (EU) 2022/2555, Annex I

    Source checked

  • Digital identity

    The identity framework was rewritten in 2024. The European Digital Identity Framework of 11 April 2024 amends the eIDAS regulation, establishes the European Digital Identity Wallet, and adds new trust services including a framework for qualified electronic archiving. For the vendors building this infrastructure, every implementing deadline is a procurement wave, and every procurement is a diligence file about the vendor itself.

    Regulation (EU) 2024/1183

    Source checked

  • Currency legislation

    The currency layer is legislation in motion. The digital euro sits in the Single Currency Package presented on 28 June 2023. The Council adopted its position on 19 December 2025, the Parliament on 9 July 2026, and trilogue negotiations are under way, with the central bank deciding on issuance only once the regulation is adopted. Vendors are bidding, partnering and raising against a regime whose final shape is not yet law, which makes the dated record of what was represented, when, unusually valuable.

    ECB, digital euro FAQ

    Source checked

Ledger entries are published in English only, and cite each instrument by its own official name.

WHAT A SOVEREIGN DEPLOYMENT CHANGES

The vendor's own record, held to the vendor's own standard.

This buyer already knows what in-perimeter deployment means; it sells one. On a sovereign deployment the vendor's raise, procurement diligence and counterparty contracts run on infrastructure the vendor controls. The security architecture and audit material sit behind a narrower door than the commercial deck, with per-person, per-document access under the vendor's own rules, and every grant and every access becomes a dated, signed entry as it happens. What was represented to which ministry, in which version, on which date, is answerable from signed versions rather than from anyone's memory.

The boundary is stated so no one has to infer it: the deployment is the vendor's compliance and evidence rail for its own deals and diligence. It does not connect to, integrate with, or process transactions of any national eID scheme or any central bank digital currency, and nothing about a sovereign deployment changes that.

The plausible configuration
For an eID or CBDC infrastructure vendor: identity verification client-supplied, since the vendor runs its own identity processes; screening client-supplied or operated, as the vendor prefers; mail on vendor infrastructure with the delivery-evidence downgrade stated; timestamping in the default connected posture, or by a qualified authority the vendor procures, a posture this sector tends to have opinions about. Decided per engagement, in writing: the switchboard, with every consequence stated.
WHAT EXEDRA GATE DOES NOT SOLVE HERE

Stated before anyone asks.

  • NOT QUALIFIED

    No supervised trust-service status. Exedra Gate is not a qualified trust service provider and holds no supervised status under the eIDAS framework. Where a deployment's timestamps come from a qualified authority, that authority's status is its own; it never becomes Exedra Gate's, and no sentence on this site claims otherwise.

  • NO SCHEME

    No national scheme integration. The platform connects to no national eID scheme and processes no wallet, credential or identity transaction of one. A vendor's product does that; the vendor's deployment of this platform documents the vendor's business.

  • NO RAIL

    Nothing near the money. The platform holds, routes and settles no funds in any form, digital euro included, and takes no part in any payment rail. That is a standing property of the product, not a configuration.

  • NO STATUS

    No procurement outcome. Certifications, accreditations and framework awards are granted by the bodies that grant them. A reproducible diligence file changes the work of bidding, not the decision.

THE CLOSE

The ministry will ask what was represented. The record answers.

An architectural review with the vendor's security and technical leads, under mutual NDA, covers the deployment shapes, the switchboard and its claim consequences, the timestamp postures, and what an engagement would scope for the vendor's raise and procurement files. A short note on the business and its jurisdictions is enough to begin.

Exedra Gate is a technology platform, not a broker, dealer, custodian, escrow provider, or investment adviser. It never holds, routes, or settles investor funds, does not recommend offerings to investors, and charges no success-based fees. It is not a qualified trust service provider, holds no supervised status under the eIDAS framework, integrates with no national eID scheme, and takes no part in any central bank digital currency or payment rail. A sovereign deployment is an implementation engagement, scoped per client. Records and timestamps attest integrity and existence as of a date, not compliance with any regime; that judgment remains with the vendor and its counsel.

Regulatory references on this page are orientation, not legal advice: see Sources & verification.