← All insights

Regulation Update · Part 11 of 6 in this series

A weekly explainer on new and amended transport and logistics regulation across the EU, drawn from our document repository.

eFTI Authentication Rules: What Regulation 2025/2243 Really Requires

23 September 2026 · EN · NL · DE · FR

Why This Matters Now

Digital freight documentation is no longer a future concept. Since 21 August 2024, national authorities across the EU have been required to accept transport, custody and customs information submitted electronically in eFTI format, under Regulation (EU) 2020/1056. That obligation has pushed carriers, forwarders and customs agents to actually pick an eFTI platform, and that is exactly where a lesser-known implementing rule, Regulation (EU) 2025/2243, becomes relevant. It defines the technical bar an eFTI platform or eFTI service provider must clear before certification, and one part of it, the authentication requirement, is routinely misunderstood.

The Rule: Authentication Under Article 4 and Annex I

Regulation 2025/2243 sets out the detailed functional requirements eFTI platforms and service providers must meet for certification: data security, data processing, authentication and interoperability. Article 4, read together with Annex I, addresses how a platform must verify the identity of the people and organisations using it. The requirement is not simply "have a login screen." Annex I ties the authentication process to the assurance levels defined in the eIDAS Regulation (EU) No 910/2014, and platforms handling eFTI data must be able to authenticate users at a level equivalent to at least "substantial." That is a materially stronger bar than a username-and-password combination, and it is the detail most transport professionals overlook when they assume any cloud portal with a login box automatically counts as eFTI-compliant.

What It Means in Daily Practice

For owner-drivers, this means the app or portal a carrier asks them to use for digital proof of delivery or transport documents cannot rely on a throwaway account created in five minutes. It has to sit behind proper identity verification, which in practice often means a recognised eID, a qualified certificate or an equivalent verified login method. For planners and back-office staff, checking "does it have a login" is not enough when choosing or renewing an eFTI platform contract. They need written confirmation that the provider's authentication method meets the eIDAS "substantial" threshold required under Annex I. For customs and enforcement staff, the benefit runs the other way: an eFTI dataset arriving through a certified platform carries a documented, higher-assurance link between the data and the person who submitted it, which is exactly the trust eFTI was built to create. Problems surface when a company adopts a platform because it is cheap or familiar, without asking whether its authentication layer was actually certified against Reg. 2025/2243, and only discovers the gap during an audit or a border check.

Your Next Step

Before renewing or signing an eFTI platform contract, ask the provider one direct question: can you show certification evidence that your authentication process meets the eIDAS "substantial" assurance level required under Annex I of Regulation (EU) 2025/2243. If they cannot answer that clearly, treat it as a compliance gap, not a formality.

Sources

Frequently asked questions

What does Regulation (EU) 2025/2243 regulate?

It sets the detailed functional requirements that eFTI platforms and eFTI service providers must meet to be certified, covering data security, data processing, authentication and interoperability, as an implementing act under the eFTI Regulation (EU) 2020/1056.

What does the authentication requirement in Annex I mean in practice?

It means a simple username and password login is not enough. Annex I requires authentication at an assurance level equivalent to at least eIDAS 'substantial', so operators need a properly verified digital identity method, not a throwaway account.

Does this rule already apply, or is it upcoming?

Regulation 2025/2243 is an implementing act that is already in force, and it applies alongside the broader eFTI Regulation (EU) 2020/1056, which authorities have had to comply with since 21 August 2024.

What should a transport company check right now?

Ask your eFTI platform provider for documented certification evidence showing their authentication process meets the eIDAS 'substantial' assurance level required under Annex I, before renewing or signing a contract.

Share on LinkedIn

Source document: eFTI Platform Requirements (Reg. 2025/2243) →