Digital Identity & Trust Services

The wallet deadline is December.
The certification schemes barely exist.

Every member state must offer an EUDI Wallet by 24 December 2026 — and not one wallet is certified yet. Whether you build wallets, run trust services or rely on them: the certification path is the project now.

EUDI WALLET ATTESTATION CERTIFIED

The landscape

What applies to you

eIDAS2 rebuilt the entire European trust architecture — and put certification at the centre of it. The short version:

You build or supply an EUDI Wallet solution

Wallets must be certified under national schemes rooted in Article 5c before member states can rely on them — and those schemes are only now materialising, with CAB accreditation still in progress across the Union. The implementing acts and the ARF fix the target; the assessment machinery is the bottleneck. If your wallet roadmap assumes certification is a formality, it assumes wrong.

ART. 5c

DEC 2026

You are — or want to become — a QTSP

The qualified regime still runs on ETSI: EN 319 401 policy requirements, EN 319 411 for certificate issuance, EN 319 421 for time-stamping, audited under EN 319 403 by accredited CABs. eIDAS2 adds new qualified services — electronic archiving, electronic ledgers, electronic attestations of attributes — each a new market with a certification gate. First movers set the audit precedents.

ETSI EN 319

NEW SERVICES

You provide the secure hardware underneath

Wallet security ultimately rests on certified cryptographic devices: WSCDs backed by secure elements, HSMs behind remote signing (QSCD certification via EN 419 241 and Common Criteria), eSIM-adjacent architectures for mobile deployment. EUCC is where this hardware gets its assurance — wallet certification schemes will lean on it by composition. Demand is arriving faster than certified supply.

QSCD · WSCD

EUCC

You will rely on wallets: banks, platforms, governments

Relying parties must register in their member state, declare their intended use of wallet data, and — for banks and very large platforms — accept the wallet for strong authentication when users offer it. Your onboarding, KYC and SCA flows all intersect with wallet attestations. The integration is an identity-architecture decision, not a checkbox.

RELYING PARTY

PSD2 / KYC

You operate in payments and mobility

Payment wallets, in-car identity, mobile driving licences (mDL), age verification — the attestation economy lands here first. EAAs let regulated attributes travel with legal effect; ISO/IEC 18013 mDL work and eIDAS2 converge on the same wallets. The products that treat certified identity as a feature, not a burden, will define these categories.

EAA · mDL

PAYMENTS

The clock is running

Six months to a deadline the ecosystem isn't ready for

That is not a reason to relax. It is a reason to be early in the certification queue.

May 2024 DONE

eIDAS2 in force

Wallet framework, new qualified trust services, relying-party regime — all law.

Dec 2024 – 2026 ROLLING

Implementing acts land

Wallet integrity, protocols, certification, relying-party registration and enrollment rules — the technical rulebook keeps arriving in batches.

Now – Dec 2026 CRUNCH

National certification schemes & CAB accreditation

Schemes are being stood up and CABs accredited while wallets are still in development. No wallet is certified yet; several member states are openly unsure of the deadline. Evaluation capacity will be the scarcest resource of 2026–2027.

24 Dec 2026

Every member state must offer a wallet

The legal deadline stands regardless of ecosystem readiness. Late wallets will certify under pressure — with all the shortcuts and findings that implies.

2027+

Relying-party obligations bite

Banks and very large platforms must accept wallet authentication; the attestation economy scales. The trust chain gets audited end-to-end for the first time.

How we work

From ARF ambition to certified reality

1

Certification strategy

Wallet scheme, QTSP audit, QSCD route or relying-party posture — mapped against the implementing acts that actually apply to you.

2

Architecture review

Wallet and WSCD architecture against ARF and Article 5a/5c requirements — before the design freezes around an uncertifiable choice.

3

Gap assessment

Against ETSI EN 319 series, national wallet scheme drafts and CC/EUCC requirements for the hardware layer.

4

Evidence & documentation

Certification files, security targets, audit evidence — written for the CAB that will actually read them.

5

Audit & evaluation support

CAB liaison, finding remediation, composition with hardware certificates — through to the certificate and the trusted list.

6

Lifecycle & policy watch

Implementing acts tracked, re-certification planned, incident procedures aligned with supervisory expectations.

One trust chain, certified end to end

Wallet certification composes upward from certified hardware and sideways from QTSP audits. Understanding the whole chain is what keeps each link’s certification small.

TRUST CHAIN SE / HSM (EUCC) QSCD (EN 419 241) Wallet (Art. 5c) QTSP (EN 319 403) EAA issuance Relying parties

For the specialists

The detail behind the summary

If you read the implementing acts as they drop, start here.

Wallet certification: Article 5c in practice

Wallet certification runs through national schemes that must reference the implementing acts and, where available, European schemes under the Cybersecurity Act — with the ARF as the de-facto technical anchor. The intent is a future harmonised EU wallet scheme; the 2026 reality is national schemes of varying maturity, CABs still being accredited, and assurance-level questions (substantial vs. high) resolved differently per member state.

The hard technical problem is the WSCD: proving that wallet keys live in hardware certified to the right level, across the deployment models — embedded SE, external token, HSM-backed remote WSCD — each with a different composition story.

Our position: design the certification composition first — which claims come from the EUCC-certified hardware, which the wallet scheme must evaluate itself. Wallets that settle this late will re-architect under deadline pressure, in public.

eIDAS2 extends the qualified regime to electronic archiving, electronic ledgers, and electronic attestations of attributes — plus the management of remote QSCDs. ETSI policy standards and national supervisory practice for these services are still forming, which means early applicants negotiate the interpretation with their CAB and supervisor rather than inheriting settled practice.

QEAAs are the strategically interesting one: they turn regulated attributes (diplomas, licences, powers of representation) into wallet-consumable, legally effective credentials — a new product category with a qualification gate.

Our position: being early is worth more here than usual — audit precedents you help set become the norm your competitors must match. But go early with a complete policy framework, or you will set precedents against yourself.

The EN 319 401/411 framework is mature, but conformity assessment findings cluster predictably: key ceremony evidence gaps, subcontractor and registration-authority oversight, incident and vulnerability procedures that exist on paper but produce no records, and termination plans nobody could execute. eIDAS2 adds pressure through tighter supervision cycles and breach notification expectations.

Our position: run the audit before the audit. A dry run against EN 319 403 practice, six months ahead, converts findings into fixes instead of trusted-list delays.

Registration, intended-use declarations and data-minimisation enforcement make relying on the wallet a regulated act, not an API call. For banks, wallet-based SCA must coexist with PSD2 exemption logic; for platforms, age and attribute verification flows must consume EAAs without over-collecting. The wallet’s selective disclosure model breaks assumptions built into most KYC and IAM stacks.

Our position: treat wallet acceptance as an identity-architecture programme with a legal layer, not a connector. The institutions mapping their flows now will onboard wallet users in weeks, not quarters, when volume arrives.

Talk to people who have built trust infrastructure before

Thirty minutes with an eIDAS expert. A straight answer on your certification path — wallet, trust service, hardware or relying party.

Contact us

Request this document

We’ll send you access by email.