Every member state must offer an EUDI Wallet by 24 December 2026 — and not one wallet is certified yet. Whether you build wallets, run trust services or rely on them: the certification path is the project now.
The landscape
eIDAS2 rebuilt the entire European trust architecture — and put certification at the centre of it. The short version:
Wallets must be certified under national schemes rooted in Article 5c before member states can rely on them — and those schemes are only now materialising, with CAB accreditation still in progress across the Union. The implementing acts and the ARF fix the target; the assessment machinery is the bottleneck. If your wallet roadmap assumes certification is a formality, it assumes wrong.
ART. 5c
DEC 2026
The qualified regime still runs on ETSI: EN 319 401 policy requirements, EN 319 411 for certificate issuance, EN 319 421 for time-stamping, audited under EN 319 403 by accredited CABs. eIDAS2 adds new qualified services — electronic archiving, electronic ledgers, electronic attestations of attributes — each a new market with a certification gate. First movers set the audit precedents.
ETSI EN 319
NEW SERVICES
Wallet security ultimately rests on certified cryptographic devices: WSCDs backed by secure elements, HSMs behind remote signing (QSCD certification via EN 419 241 and Common Criteria), eSIM-adjacent architectures for mobile deployment. EUCC is where this hardware gets its assurance — wallet certification schemes will lean on it by composition. Demand is arriving faster than certified supply.
QSCD · WSCD
EUCC
Relying parties must register in their member state, declare their intended use of wallet data, and — for banks and very large platforms — accept the wallet for strong authentication when users offer it. Your onboarding, KYC and SCA flows all intersect with wallet attestations. The integration is an identity-architecture decision, not a checkbox.
RELYING PARTY
PSD2 / KYC
Payment wallets, in-car identity, mobile driving licences (mDL), age verification — the attestation economy lands here first. EAAs let regulated attributes travel with legal effect; ISO/IEC 18013 mDL work and eIDAS2 converge on the same wallets. The products that treat certified identity as a feature, not a burden, will define these categories.
EAA · mDL
PAYMENTS
The clock is running
That is not a reason to relax. It is a reason to be early in the certification queue.
Wallet framework, new qualified trust services, relying-party regime — all law.
Wallet integrity, protocols, certification, relying-party registration and enrollment rules — the technical rulebook keeps arriving in batches.
Schemes are being stood up and CABs accredited while wallets are still in development. No wallet is certified yet; several member states are openly unsure of the deadline. Evaluation capacity will be the scarcest resource of 2026–2027.
The legal deadline stands regardless of ecosystem readiness. Late wallets will certify under pressure — with all the shortcuts and findings that implies.
Banks and very large platforms must accept wallet authentication; the attestation economy scales. The trust chain gets audited end-to-end for the first time.
How we work
Wallet scheme, QTSP audit, QSCD route or relying-party posture — mapped against the implementing acts that actually apply to you.
Wallet and WSCD architecture against ARF and Article 5a/5c requirements — before the design freezes around an uncertifiable choice.
Against ETSI EN 319 series, national wallet scheme drafts and CC/EUCC requirements for the hardware layer.
Certification files, security targets, audit evidence — written for the CAB that will actually read them.
CAB liaison, finding remediation, composition with hardware certificates — through to the certificate and the trusted list.
Implementing acts tracked, re-certification planned, incident procedures aligned with supervisory expectations.
Wallet certification composes upward from certified hardware and sideways from QTSP audits. Understanding the whole chain is what keeps each link’s certification small.
For the specialists
If you read the implementing acts as they drop, start here.
Wallet certification runs through national schemes that must reference the implementing acts and, where available, European schemes under the Cybersecurity Act — with the ARF as the de-facto technical anchor. The intent is a future harmonised EU wallet scheme; the 2026 reality is national schemes of varying maturity, CABs still being accredited, and assurance-level questions (substantial vs. high) resolved differently per member state.
The hard technical problem is the WSCD: proving that wallet keys live in hardware certified to the right level, across the deployment models — embedded SE, external token, HSM-backed remote WSCD — each with a different composition story.
Our position: design the certification composition first — which claims come from the EUCC-certified hardware, which the wallet scheme must evaluate itself. Wallets that settle this late will re-architect under deadline pressure, in public.
eIDAS2 extends the qualified regime to electronic archiving, electronic ledgers, and electronic attestations of attributes — plus the management of remote QSCDs. ETSI policy standards and national supervisory practice for these services are still forming, which means early applicants negotiate the interpretation with their CAB and supervisor rather than inheriting settled practice.
QEAAs are the strategically interesting one: they turn regulated attributes (diplomas, licences, powers of representation) into wallet-consumable, legally effective credentials — a new product category with a qualification gate.
Our position: being early is worth more here than usual — audit precedents you help set become the norm your competitors must match. But go early with a complete policy framework, or you will set precedents against yourself.
The EN 319 401/411 framework is mature, but conformity assessment findings cluster predictably: key ceremony evidence gaps, subcontractor and registration-authority oversight, incident and vulnerability procedures that exist on paper but produce no records, and termination plans nobody could execute. eIDAS2 adds pressure through tighter supervision cycles and breach notification expectations.
Our position: run the audit before the audit. A dry run against EN 319 403 practice, six months ahead, converts findings into fixes instead of trusted-list delays.
Registration, intended-use declarations and data-minimisation enforcement make relying on the wallet a regulated act, not an API call. For banks, wallet-based SCA must coexist with PSD2 exemption logic; for platforms, age and attribute verification flows must consume EAAs without over-collecting. The wallet’s selective disclosure model breaks assumptions built into most KYC and IAM stacks.
Our position: treat wallet acceptance as an identity-architecture programme with a legal layer, not a connector. The institutions mapping their flows now will onboard wallet users in weeks, not quarters, when volume arrives.
Thirty minutes with an eIDAS expert. A straight answer on your certification path — wallet, trust service, hardware or relying party.
We’ll send you access by email.