Marco Combetto

AI & Digital Transformation — Public Sector — Data Science

Digital Identity and Federated IAM

Project management and advisory for trusted, interoperable digital identity — helping public administrations and EU institutions give citizens, businesses, and officials secure access to cross-border digital services.

Digital Identity and Federated IAM

Current Engagement

I currently work as a freelance Project Manager for the European Commission, Directorate-General for Taxation and Customs Union (DG TAXUD), on the UUM&DS (Uniform User Management and Digital Signatures) federated Identity and Access Management platform.

UUM&DS is the common EU customs component, publicly described in the Commission’s customs IT planning, that allows economic operators and customs officials to access trans-European customs systems using identities managed in a federated way by the Member States’ national IAM systems.

My contribution focuses on project delivery in a multi-stakeholder European context:

  • Planning and coordination of releases within a large-scale, mission-critical IT programme
  • Alignment between Commission services, Member State administrations, and contractors
  • Requirements management, risk and change control, and quality assurance of deliverables
  • Governance reporting and follow-up of IT service management processes

Out of respect for my client’s confidentiality obligations, this page describes only publicly available information and my general role. Views expressed are my own and do not represent the European Commission.

Services include

  1. Digital Identity Strategy and Roadmaps
    Assessment of existing identity landscapes and definition of target architectures and adoption roadmaps.
    Alignment with eIDAS 2.0, the European Digital Identity (EUDI) Wallet, and national eID schemes.
  2. Federated Identity and Access Management
    Design and governance of identity federation across organisations and borders.
    Standards-based integration using SAML 2.0, OpenID Connect, and OAuth 2.0.
  3. Authorisation, Roles, and Mandates
    Role- and attribute-based access models (RBAC/ABAC), delegation and representation of legal entities.
    Identity lifecycle management: onboarding, provisioning, recertification, and de-provisioning.
  4. Trust Services and Electronic Signatures
    Advisory on qualified electronic signatures, seals, and trust frameworks under eIDAS.
    Integration of signature services into public-sector business processes.
  5. Security, Compliance, and Zero Trust
    Strong and multi-factor authentication, Zero Trust principles, and alignment with NIS2 and GDPR.
    Privacy-by-design and data-minimisation in identity data flows.
  6. Programme and Project Management
    Delivery management of complex IAM programmes with many stakeholders and contractors.
    Release planning, risk management, and ITSM-aligned operations.

Deliverables

  • Identity strategy, target architecture, and adoption roadmap
  • Federation and trust-framework models
  • Access-control and role models, with lifecycle procedures
  • Integration guidelines for relying parties and identity providers
  • Security and compliance assessments (eIDAS, NIS2, GDPR)
  • Project plans, risk registers, and governance reports

Why Digital Identity for the Public Sector?

Digital identity is the front door to every public digital service. When it works well, citizens and businesses reach the services they need once and securely, across administrations and borders; when it is fragmented, every system reinvents login, roles, and trust. With eIDAS 2.0 and the EUDI Wallet reshaping the landscape, public administrations need identity solutions that are federated, interoperable, and secure by design — delivered through disciplined project management that brings many stakeholders together.