Regulation · EU Regulatory Framework

eIDAS 2 & the EUDI Wallet — identity becomes infrastructure

Every member state must offer a digital identity wallet by 24 December 2026. Every wallet must be certified. No wallet is certified yet. Whether you build, host, secure or rely on this ecosystem — the certification chain is where it succeeds or stalls.

At a glance

Core mandate

A wallet per member state

Free to citizens, by 24 Dec 2026 — carrying identity and attestations with legal effect

Certification

Mandatory, Art. 5c

National schemes referencing implementing acts and Cybersecurity Act schemes; the ARF as technical anchor

New trust services

EAA, e-archiving, e-ledgers

Plus managed remote QSCDs — each with a qualification gate

Relying parties

Registered & constrained

Intended-use declarations, data minimisation; banks and very large platforms must accept the wallet

Rulebook

Implementing acts, batched

Wallet integrity, protocols, certification, registration — Dec 2024 onward, still arriving

The stack below

WSCD → wallet → services

Certified hardware (EUCC), certified wallet, audited QTSPs — one chain

What it is

The first regulation that certifies an entire ecosystem

eIDAS 2 rebuilt the 2014 trust framework around one object: a government-backed wallet in which citizens hold their identity and attestations — diplomas, licences, powers of attorney, payment credentials — and disclose them selectively, with legal effect across the Union. The regulation entered into force in May 2024; its implementing acts have been arriving in batches since December 2024, fixing wallet integrity, protocols, certification and relying-party registration, with the Architecture Reference Framework as the engineering anchor.

What makes it unique in this regulatory family is that trust is enforced by certification at every layer. Wallets must be certified under national Article 5c schemes before member states can field them. Wallet keys must live in secure hardware — WSCDs whose assurance comes from the Common Criteria/EUCC world. Qualified trust service providers remain audited under the ETSI EN 319 framework, now extended to new services: electronic attestations of attributes, e-archiving, e-ledgers, managed remote QSCDs. Even relying on the wallet is regulated — registration, declared intended use, enforced data minimisation, and acceptance obligations for banks and very large platforms.

The mid-2026 tension is stark: the December deadline is immovable, several member states doubt they will meet it, national certification schemes are only now materialising, and CAB accreditation is the structural bottleneck. Wallets will certify under deadline pressure — which makes early, composition-smart certification strategies disproportionately valuable, and precedent-setting inevitable.

Key dates

The eIDAS 2 clock, as of July 2026

20 May 2024 DONE

Regulation in force

Wallet framework, new trust services, relying-party regime

Dec 2024 → now

Implementing acts land

Integrity, protocols, certification, registration — the rulebook in batches

Now the crunch

Schemes & CABs racing

National Art. 5c schemes finalising; CAB accreditation the bottleneck; zero wallets certified

24 Dec 2026

Wallet deadline

Every member state must offer one; acceptance obligations scale from 2027

What it means for you

Four positions in the chain, four different projects

Wallet builders: design the composition first

Which claims come from EUCC-certified hardware, which the wallet scheme evaluates itself — settled early, this halves the certification; settled late, it re-architects the product in public.

QTSPs: the new services reward the early

EAAs, e-archiving, e-ledgers — supervisory practice is still forming, and first applicants set the audit precedents everyone else inherits. Go early with a complete policy framework, or not at all.

Hardware vendors: demand is arriving now

WSCDs, secure elements and HSMs behind remote signing — certified supply is scarcer than wallet-driven demand. Certificates, not roadmaps, win these design-ins.

Relying parties: it's an architecture programme

Registration, intended-use declarations and selective disclosure break assumptions in most KYC and IAM stacks. Map the flows in 2026; onboard in weeks instead of quarters when volume arrives.

Expert notes

What we tell clients before they commit

The deadline will bend behaviour, not the law

Several member states have signalled they will miss December 2026; none can miss it by much, and the acceptance obligations on banks and platforms keep the pressure on through 2027. The realistic pattern: wallets certified under compressed schedules, assurance-level interpretations diverging by member state, and early findings setting precedents — including how much a wallet evaluation may lean on composition from hardware certificates. Whoever shapes those precedents shapes the market’s cost structure.

Our position: being in the first certification cohort is worth real money — but only with the composition methodology and evidence architecture prepared beforehand. Arriving early and unprepared just donates your schedule to precedent-setting against you.

The wallet is plumbing; electronic attestations of attributes are the product. QEAAs turn regulated attributes — diplomas, professional licences, company mandates, age — into wallet-consumable credentials with legal effect, creating a qualification-gated market that barely existed before. Payments, mobility (mDL) and age verification land there first. Issuers who secure qualified status and integration patterns early own distribution channels that are expensive to displace later.

Our position: if your business holds authoritative data about people or organisations, run the QEAA feasibility analysis this year. The certification gate is exactly what makes the position defensible once you’re through it.

The trust chain, end to end

Wallet certification strategy, QTSP audits, WSCD composition, relying-party architecture — thirty minutes with people who have built trust infrastructure before.

Contact us

Request this document

We’ll send you access by email.