Everything you should know about the EUDI Wallet and eIDAS 2.0: what it means for businesses
If you've been reading this blog for a while, you'll already be familiar with the key terms: wallet, verifiable credentials, sovereign identity... We've talked about how the EUDI Wallet is set to put an end to our digital 'Groundhog Day', how businesses will have their own European Business Wallet, and how to build sustainable business models around all of this.
Today, though, it's time to get back to basics and explain everything from the ground up, without assuming any prior knowledge. Because behind every technological revolution there's always a law driving it forward and a timetable that won't wait. And when it comes to digital identity, that law is called eIDAS 2.0.
So make yourself comfortable and let me explain what it is, who it applies to, the key deadlines, and why it matters to you, even if your business isn't (yet) involved in digital identity.
First things first: what is eIDAS 2.0?
Let's start with the name, which sounds more intimidating than it really is. eIDAS stands for electronic IDentification, Authentication and trust Services. The original version dates back to 2014 (Regulation (EU) No 910/2014) and was Europe's first attempt to bring order to electronic identification and trust services (electronic signatures, seals and certificates) across Member States.
The problem was that the 2014 version of eIDAS never gained the traction that had been expected, and interoperability became extremely complex. On paper, your Spanish electronic ID card should have allowed you to set up a business in Germany or enrol at a university in France. In practice, it became a legal and technical balancing act that hardly anyone used.
eIDAS 2.0, officially known as Regulation (EU) 2024/1183, is designed to change that. It entered into force on 20 May 2024, and its headline innovation has a name of its own: the EUDI Wallet (European Digital Identity Wallet). It is no longer simply a framework that "allows" digital identity; it is a Regulation that makes it mandatory. And that word, "Regulation", matters: unlike a directive, an EU Regulation applies directly in all 27 Member States. It doesn't need to be transposed into Spanish law; it is already the law.
The 2014 eIDAS framework made a European digital identity possible; eIDAS 2.0 makes it mandatory. That single word sums up the entire paradigm shift.
The EUDI Wallet: your European identity in your pocket
At the heart of eIDAS 2.0 is the EUDI Wallet, an official app on your mobile phone where your European digital identity, issued or certified by your Member State, will be stored.
Think of it as the physical wallet you carry in your pocket, but in digital form and protected against tampering. Just as your wallet holds your ID card, driving licence, health card and gym membership card, your EUDI Wallet will hold your verifiable credentials: everything from your core identity to, over time, your driving licence, academic qualifications and health card.
It's worth being precise here, because two technical points are often confused:
- The EUDI Wallet is not a login app or a form of two-factor authentication. It is a cryptographically protected identity container capable of presenting verified attributes to whomever you choose, whether online or in person, and always with your explicit consent. That said, one of the use cases we can implement is authentication through credentials.
- The jewel inside is called the PID (Person Identification Data). This is the set of core identity data, such as your first name, surname and date of birth, that your Member State verifies and stores in your wallet. Think of it as the 'root credential' on which everything else is built.
■ The PID then provides the foundation for EAAs (Electronic Attestations of Attributes), which are attestations of specific attributes: 'I am over 18', 'I hold a valid driving licence', 'I meet the income threshold for social energy support'. Every Member State must provide at least one free EUDI Wallet to all its citizens and residents before the end of 2026 (the formal deadline is 24 December 2026).
The million-pound question: who is required to do what?
This is the part I'd really like you to pay attention to, because it's the aspect that's most often misunderstood, and probably what brought you to this article in the first place.
eIDAS 2.0 assigns roles within an ecosystem of three actors, the 'triangle of trust' we've already talked about:
- The Issuer: the trusted entity that certifies something about you (the State issuing the PID, a university issuing a degree, and so on).
- The Holder: you, the person who stores the credential in your wallet and decides what to share.
- The Relying Party: the organisation that needs to verify your identity or one of your attributes and trusts the credential you present without having to contact the issuer. Yes, without notifying them. It's completely decentralised.
Three actors make up a 'triangle of trust'
And here's the key point: the legal obligation falls primarily on private-sector Relying Parties.
■ Article 5f of the Regulation couldn't be clearer. Whenever a private-sector organisation is required by EU law, national law or a contractual obligation to use Strong Customer Authentication (the well-known SCA introduced by PSD2 for payments), it must also accept the EUDI Wallet as a valid authentication method.
The question is no longer whether you'll accept the wallet, but how you'll integrate it.
Who are we talking about in practice? The usual suspects when it comes to robust identity verification: banks, payment institutions, insurers, energy suppliers, telecoms providers and very large online platforms (those with more than 45 million users in the EU). If your organisation already requires robust identity verification to onboard customers, chances are you'll be a Relying Party by 2027, whether you've planned for it or not.
Becoming a Relying Party is not optional for organisations covered by the Regulation. It's not enough simply to continue accepting other digital identity methods; you must specifically accept the EUDI Wallet.
The deadline that won't wait: December 2027
Now let's look at the dates, because they're what really keep executive teams awake at night. The rollout of eIDAS 2.0 is phased:
- May 2024: the Regulation enters into force.
- December 2026: every Member State must make at least one EUDI Wallet available to its citizens.
- December 2027: the obligation to accept the EUDI Wallet comes into effect for the affected private-sector Relying Parties. More specifically, they have 36 months from the entry into force of the implementing acts to accept EUDI Wallet credentials whenever they are presented. That countdown ends in December 2027.
—I like to compare this to installing a mandatory lift in an old building. You can see it as an expense that's been imposed on you and do the bare minimum to pass inspection... or you can use the opportunity to increase the value of the whole building. Spoiler: the second option is the interesting one, and I'll explain why.
From 'an obligation to comply with' to 'a competitive advantage'
This is the message I really want you to take away. If your company sees the EUDI Wallet as just another compliance box to tick, you'll comply with the law... but you'll leave almost all of the business value on the table.
Because once you've built the infrastructure to consume the PID, the technical layer that translates the wallet's cryptography into something your internal systems can understand—you'll have a platform that can deliver far more than the legal minimum. In fact, the Regulation defines only the minimum mandatory use cases; beyond that, the European Commission describes the wallet as a "catalyst" that can be used for much more. Let's look at some practical examples:
Onboarding in seconds, not minutes
Today, onboarding a customer usually means asking them to upload photos of both sides of their ID card, take a selfie while moving their head as though they were trying to hypnotise their phone, and hoping the OCR gets everything right. A huge proportion of users abandon the process at exactly that point.
With the EUDI Wallet, that customer simply shares their already verified PID using biometric authentication, and that's it. What used to take five minutes now takes five seconds. Abandonment rates plummet, and you receive accurate, cryptographically signed data, with no OCR and no manual review of fraudulent documents.
Reusable KYC and issuing your own credentials
A bank that has already invested in verifying a customer can do more than simply consume the PID: it can also issue its own credentials, such as an attestation stating "verified customer", "holder of this account" or "income above a specified threshold". The customer stores these credentials in their wallet and reuses them wherever they choose. You move from being solely an identity consumer to becoming a trusted issuer, which is where much of the future business value lies.
Less data, less risk, greater compliance
This is where one of the most elegant technical principles comes into play: selective disclosure, which can be supported by Zero-Knowledge Proofs.
Let's go back to the nightclub bouncer. When you show your physical ID card to prove you're over 18, you're also handing over your full name, home address and that dreadful photo from five years ago. It's a massive overexposure of personal data. With the wallet, your app can mathematically prove that "this person is over 18" or that "their name is X" without revealing their date of birth, unless the Relying Party has a documented legal basis for receiving it.
For your company, this is compliance gold. The wallet is GDPR-compliant by design, because you can request only the attributes that are strictly necessary for each transaction. Asking for more than you need isn't just bad practice; it exposes you to penalties under both the GDPR and eIDAS 2.0.
Complying with eIDAS 2.0 will be mandatory. Turning that obligation into less friction, lower compliance costs and higher conversion rates will be the real opportunity.
A product warning: don't leave it too late
I'll finish with the least glamorous but perhaps the most important point. Integrating the EUDI Wallet isn't simply a matter of plugging in a plugin on a Friday afternoon. The legacy systems used by banks and telecoms providers were designed for a centralised world, whereas the wallet operates within a decentralised model. Bringing the two together requires a "translation layer" that converts the wallet's cryptography into something your internal systems can understand, without having to rewrite the core platform.
Current estimates put implementation projects at between 6 and 18 months, depending on the size and complexity of the company. Do the maths: if the obligation takes effect in December 2027 and your integration takes more than a year, the time to start planning your budget and roadmap is now, not in 2027. Those who leave it too late will face compressed delivery times, greater technical risk and, as an added consequence, a competitive disadvantage compared with companies that already offer onboarding in seconds.
In summary
eIDAS 2.0 is the European Regulation that places the EUDI Wallet at the heart of our digital identity. Member States must make wallets available to citizens by the end of 2026, and private-sector organisations that carry out robust identity verification, including banks, insurers, energy suppliers, telecoms providers and large online platforms, are required to accept it and consume the PID by the end of 2027.
So the question is no longer whether your company will become a Relying Party. The real question is how: will you approach it as a compliance exercise to meet the regulatory requirements, or as the opportunity to transform your onboarding, your KYC processes and the trusted relationship you have with your customers? We know where we stand: the lift has to be installed anyway, so it might as well add value to the whole building.
Hybrid Cloud
Cybersecurity
Data & AI
IoT & Connectivity
Industry
Health
Banking and Finance
Public Sector
Retail
Tourism and Leisure
Transport & Logistics
Energy & Utilities
Smart Cities