EUDAMED module security keys: generation, storage and rotation dependencies
The acquired help makes security keys module-specific and combines them with sender SRN. Keys cannot be viewed after closing the generation window; regeneration requires new XML files to use the new module key. Plan key custody and producer cutover without placing credentials in a public brief.
Evidence retrieved 2026-10-07. Source versions and topic-specific limits are listed below.
Sourced criteria · EU · EUDAMED
What changes the service scope?
Decision or task
What the source describes
What to prepare
generate-your-security-key / HTML p [5]
The security key is specific for each EUDAMED module, and the combination of this key and the SRN of the sender is used as security to ensure that the message is received from the correct actor. Without this key, your message will not pass our security checks. An incorrect key will give the following error response: [1]
Apply this source context to the specific tasks below; retain missing facts and review current target-environment compatibility.
Apply this source context to the specific tasks below; retain missing facts and review current target-environment compatibility.
generate-your-security-key / HTML p [21]
Please copy the security key. You will not be able to view your security key after closing the pop-up window. If you lose your security key, you must regenerate it ( see Regenerate your security key page for further details). [3]
Apply this source context to the specific tasks below; retain missing facts and review current target-environment compatibility.
regenerate-your-security-key / HTML p [17]
Please copy the regenerated security key. You will not be able to view your security key after closing the pop-up window. If you lose your security key, you must regenerate it. [4]
Apply this source context to the specific tasks below; retain missing facts and review current target-environment compatibility.
regenerate-your-security-key / HTML p [19]
When a security key is regenerated, all new XML files must include the new security key for that module, otherwise they will be rejected. [5]
Apply this source context to the specific tasks below; retain missing facts and review current target-environment compatibility.
Dated technical/help evidence, not a complete legal duty set or live EUDAMED response. Current target-environment release, business rules, permissions and actual buyer records remain unresolved. Blank dictionary flags are unknown; occurrence and update notes keep their stated conditions. No credentials, registration deadline or completed production exchange is inferred.
Prepare the EUDAMED module security keys work package
Use this checklist to gather your business or product details before speaking with a specialist. The items below explain what to record and suggest useful supporting documents. You can add your own answers in the editable project brief.
Inventory module and actor identities
Record the sender actor/SRN and producing systems for each module; keep the actual tokens in approved private secret storage.
Useful evidence: A module/actor/system inventory with secret references, never token values.
Plan secure capture and custody
Assign the person/system responsible for securely retaining the generated key and recovering from loss.
Useful evidence: A private key-management procedure and access responsibilities.
Coordinate regeneration
Update each XML producer for the rotated module and test a new exchange; separate old queued messages from newly generated files.
Useful evidence: A rotation/cutover plan, producing-system acknowledgements and post-change test evidence.
Work packages and dependencies
Conditional: EUDAMED module security keys: generation, storage and rotation dependencies — Review the actual current records and target-environment requirements; complete the specific mapping/onboarding or maintenance task with source/version and acceptance evidence.
Questions for providers
How will you resolve the specific field/identity or state dependencies shown here for our actual records?
Which current environment release, permissions and business rules support the proposed operation?
What mapping, unresolved-error and acceptance evidence will you hand over, and who owns each correction?
Sources and data dates
Read the official document in context. The audit details identify the precise locators and preserved versions used for this page.