eIDAS 2 rebuilt the 2014 trust framework around one object: a government-backed wallet in which citizens hold their identity and attestations — diplomas, licences, powers of attorney, payment credentials — and disclose them selectively, with legal effect across the Union. The regulation entered into force in May 2024; its implementing acts have been arriving in batches since December 2024, fixing wallet integrity, protocols, certification and relying-party registration, with the Architecture Reference Framework as the engineering anchor.
What makes it unique in this regulatory family is that trust is enforced by certification at every layer. Wallets must be certified under national Article 5c schemes before member states can field them. Wallet keys must live in secure hardware — WSCDs whose assurance comes from the Common Criteria/EUCC world. Qualified trust service providers remain audited under the ETSI EN 319 framework, now extended to new services: electronic attestations of attributes, e-archiving, e-ledgers, managed remote QSCDs. Even relying on the wallet is regulated — registration, declared intended use, enforced data minimisation, and acceptance obligations for banks and very large platforms.
The mid-2026 tension is stark: the December deadline is immovable, several member states doubt they will meet it, national certification schemes are only now materialising, and CAB accreditation is the structural bottleneck. Wallets will certify under deadline pressure — which makes early, composition-smart certification strategies disproportionately valuable, and precedent-setting inevitable.