PART 2 OF 2. 

Promotional banner for Identity Week 2026 in Amsterdam, featuring the event logo and details including dates (9-10 June 2026) and a call to action.

There is a tendency, particularly in the identity sector, to treat events as milestones. Each June, Identity Week Europe 2026 becomes a focal point for announcements, partnerships, and positioning. Yet the event itself is not the story. It is a moment of visibility for something that has already shifted more fundamentally.

What is now emerging across Europe is not simply a set of identity solutions, nor even a coordinated move toward digital wallets. It is the construction of an infrastructure layer that determines how participation, trust, and control are defined in digital systems. That layer can be described, with some precision, as the trust stack.

The trust stack is already taking shape. It is not being built by a single category of company, nor through a single regulatory initiative. It is being assembled across distinct layers, each with its own role, its own constraints, and its own strategic importance.

Players and their place in the Trust Stack

At the point of interaction sits the adoption layer. Identity only becomes infrastructure when it is used at scale, repeatedly, and across contexts. Platforms such as itsme illustrate how this transition is occurring. What began as a consumer authentication mechanism is now extending into broader participation models, where identity underpins transactions, authorisation, and access to services. Adoption, in this sense, is not the end state. It is the entry point into a wider system.

Beneath this sits the enforcement layer, where trust moves beyond assertion into evidence. Trust services providers such as Tinexta Infocert operate within frameworks that are increasingly defined by legal and regulatory enforceability. Signatures, certificates, and time-stamps are no longer procedural requirements. They are mechanisms through which digital actions gain legal weight. The shift is not dramatic in appearance, but it changes the nature of trust entirely.

For organisations operating at this layer, the challenge is no longer simply maintaining compliance with existing frameworks. It is ensuring that trust remains verifiable and enforceable as services scale across jurisdictions and increasingly complex digital ecosystems. Trust services are becoming embedded within business processes rather than sitting alongside them. As a result, evidential integrity is becoming an operational requirement rather than a compliance objective.

“We treat enforceability not as a property you declare, but as one you have to sustain under load.”

Tinexta InfoCert

The significance of this observation extends beyond today’s trust services market. Increasingly, the same principles that underpin legally enforceable digital interactions are being considered for environments where regulation has yet to mature. Industrial systems, connected devices and autonomous AI agents all raise questions about accountability, verification and trust that existing frameworks only partially address.

The more demanding frontier may lie where no regulatory equivalent to eIDAS yet exists. As machine identities become more common and AI systems begin acting with greater autonomy, the challenge will be extending proven trust mechanisms into environments where accountability frameworks remain largely undefined. The organisations that succeed in doing so may help define the next generation of digital trust infrastructure before regulators arrive.

Supporting both adoption and enforcement is the cryptographic backbone. Companies such as Cryptomathic occupy a position that is often underestimated precisely because it is so fundamental. Cryptography defines the lifespan and integrity of trust. As systems move toward post-quantum readiness, and as composite cryptographic approaches become necessary, this layer becomes less about security features and more about systemic resilience over time.

None of this, however, exists in isolation from deployment. The issuance layer determines whether identity systems can be realised at scale and sustained over time. Providers such as Mühlbauer operate in an environment where theory meets operational reality. National identity programmes, secure credential issuance, and lifecycle management are not abstract challenges. They are continuous processes that define whether identity infrastructure functions reliably in practice.

At a broader level, identity is increasingly tied to sovereign infrastructure. Organisations such as IN Groupe reflect a shift in how identity is understood at the state level. It is no longer sufficient to provide access mechanisms. Identity is being integrated into national capability, regulatory alignment, and cross-border frameworks. The emergence of European wallet initiatives reinforces this direction, even as implementation remains uneven.

The discussion around sovereignty is also evolving. The first phase focused largely on wallet applications, citizen adoption and interoperability. The next phase is increasingly concerned with the resilience of the infrastructure itself. Sovereign identity systems must remain trustworthy over long operational lifecycles while accommodating changing standards, evolving threats and future cryptographic transitions.

“The infrastructure built today must remain uncompromised for decades to come.”

IN Groupe

This perspective introduces a longer-term dimension to the trust stack. Identity infrastructure is no longer being designed solely for current requirements. It must also accommodate future post-quantum cryptography migrations, changing regulatory expectations and evolving cross-border trust frameworks. Sovereignty increasingly depends not only on who controls a system today, but on whether that system can remain trusted tomorrow.

For organisations such as IN Groupe, this means looking beyond the user interface of the wallet itself and towards the lifecycle of the underlying infrastructure. Supply-chain assurance, cryptographic agility and long-term operational resilience are becoming strategic requirements rather than technical considerations. As a result, the sovereign layer is emerging as one of the most influential components of the trust stack.

At the base of the stack sits the hardware root of trust. This layer is rarely visible, yet it underpins everything above it. Semiconductor providers such as NXP Semiconductors anchor identity within physical devices, secure elements, and embedded systems. As identity extends beyond centralised platforms into distributed environments, the integrity of this layer becomes critical. Without it, higher layers lose their reliability.

A System rather than a Sector

What becomes clear is that the identity sector is no longer defined by individual solutions. It is being reorganised around a layered architecture of trust, where each component depends on the others. The companies shaping this landscape are not competing within a single category. They are defining positions within a system that is still taking form.

The significance of Identity Week lies in its ability to make this structure visible. The technologies, partnerships, and conversations on display provide a snapshot of how the trust stack is evolving. Some layers are mature. Others remain in transition. All are interconnected.

The question that follows is not simply who is present in this ecosystem, but who defines it. As identity, cryptography, and infrastructure converge, control shifts toward those who can operate across layers, or anchor a critical one.

Identity Week may provide the stage but it is the trust stack determines what is being built behind it.

TQS Insight

The structure of the trust stack is no longer abstract. It is visible, and it is forming around distinct layers that carry very different strategic weight. Companies will not compete solely on capability, but on the position they occupy within that structure and the extent to which they can define it.

Being present within the ecosystem is not the same as being understood within it. As Identity Week approaches, the companies that articulate their role clearly—and connect it to the wider architecture of trust—will shape how the market interprets them.

The rest will be seen as participants rather than anchors.


Identity Week Europe 2026 takes place between 9-10 June 2026 at the RAI Amsterdam. Meet the contributors to this article:

• IN Groupe – Stand 820
• Tinexta InfoCert – Stand 432

For more Identity Week coverage, interviews and analysis, visit The Quantum Space.


Discover more from The Quantum Space

Subscribe to get the latest posts sent to your email.

Leave a Reply

Trending

Discover more from The Quantum Space

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The Quantum Space

Subscribe now to keep reading and get access to the full archive.

Continue reading