WAYF is NSIS-notified as a so-called broker with the Danish Agency for Digital Government. This means that WAYF is authorised to receive authentications (login tokens) from organisations that are themselves NSIS-notified, and forward them to other organisations while preserving their so-called NSIS assurance level. The assurance level of an authentication refers to the quality of the issuing organisation's effort to ensure that it was issued to the intended physical person.
The National Standard for Assurance Levels of Identities (NSIS) defines three levels of assurance: Low, Substantial, and High. WAYF has been approved for forwarding the first two. WAYF may receive an authentication at the High level but may only forward it as Substantial. Each authentication’s assurance level appears in a specific field (“eduPersonAssurance”) – digitally signed by WAYF, so the that value can be trusted to originate from WAYF.
The notification as a broker at the NSIS-Substantial level is a crucial precondition for WAYF being able to provide NemLog-in (MitID) to its service providers. Only public entities, or private entities processing authentications on behalf of a public entity, are allowed to receive authentications from NemLog-in – whether through WAYF or otherwise. But with WAYF as an intermediary, it is easier than with direct a connection to NemLog-in – see here.