eIDAS 2.0 and the EU Digital Identity Wallet
eIDAS 2 updates the EU’s digital-identity and trust-services rules and creates the framework for the EU Digital Identity Wallet. It is in a phased implementation period, with wallet deployment and technical integration continuing through 2026 and beyond.
eIDAS 2 is the common name for the revised EU regulation on electronic identification, authentication and trust services. It updates the original eIDAS Regulation, which established rules for electronic signatures and cross-border recognition of notified national eID schemes. The revised framework is directly applicable across EU Member States, although national delivery and technical implementation take time.
As of 1 January 2026, eIDAS 2 is phasing in. Its most visible element is the EU Digital Identity, or EUDI, Wallet: software that lets people hold and share verified identity data and other digital credentials under a common European framework.
What eIDAS 2 changes
The original eIDAS focused on interoperability for national electronic-identification schemes that Member States chose to notify to the European Commission. It also gave defined legal effect to electronic signatures, seals, timestamps, registered delivery services and website-authentication certificates. In practice, access to cross-border digital identity remained uneven because coverage, user experience and national capabilities varied.
eIDAS 2 expands that model. It requires each Member State to make at least one EUDI Wallet available to residents, citizens and businesses under its jurisdiction. It also creates detailed rules for the wallet ecosystem, including security, certification, privacy, interfaces and the issuance of electronic attestations of attributes. An attribute can be a fact such as age, address, professional qualification or driving entitlement.
The regulation is designed around selective disclosure. Rather than routinely sending a full identity record, a user should be able to share only the information needed for a transaction, such as proving they are over 18. Actual outcomes depend on the credential, wallet implementation and the service requesting the data.
The EU Digital Identity Wallet
The EUDI Wallet is not one centrally operated EU app or a replacement for every national ID document. Member States may provide wallets themselves or authorize providers under the EU framework. Wallets are intended to support identification, authentication and the storage or presentation of digital credentials, including qualified electronic signatures where the relevant requirements are met.
Users remain in control of whether to use a wallet and which data to present. The framework places limits on tracking and requires safeguards intended to prevent wallet providers from learning unnecessary details about a user’s transactions. Service providers seeking wallet data must clearly identify themselves and state the data requested.
Rollout and timing
The revised regulation entered into force in 2024, followed by implementing rules that specify common technical standards and procedures. Member States, wallet providers, credential issuers and relying parties are now moving from pilots and specifications toward production services.
The timetable is staged rather than a single launch date. EU rules set deadlines around wallet availability and acceptance obligations, while national procurement, authorization, integration and sector-specific rules affect when a person or business can use a particular service. Broad wallet availability is expected during 2026, with adoption continuing after that.
- Wallet availability does not mean every public or private service will support every credential immediately.
- Technical interoperability depends on common specifications, conformance testing and security certification.
- Existing national eID schemes and conventional identity-verification routes will continue to operate during the transition.
Qualified trust services and recognition across borders
Trust services are services that help establish the integrity, origin or time of electronic data. A qualified trust service meets the regulation’s higher requirements and is supervised by a national authority. Qualified electronic signatures, for example, generally have the legal effect of handwritten signatures throughout the EU.
eIDAS 2 preserves these cross-border effects and broadens the framework for trust services and digital credentials. Qualified trust service providers appear on national trusted lists, which businesses can use when assessing whether a provider has qualified status. Cross-border recognition reduces the need for each country or platform to create separate assurance arrangements, but it does not remove sector rules on customer due diligence, fraud controls or recordkeeping.
What this means for identity-verification businesses
For identity-verification, or IDV, providers, eIDAS 2 creates both an integration opportunity and a compliance challenge. Businesses that verify customers may be able to accept wallet-based identity data or attributes instead of collecting document images and running separate checks. That can improve data minimization and reduce friction where the wallet credential meets the required assurance level.
However, a wallet presentation is not automatically sufficient for every use case. IDV providers and their customers must determine what assurance, liveness detection, sanctions screening, age checks, evidence retention and fraud monitoring are required by the relevant law and risk policy. They should also prepare for wallet relying-party registration or certification requirements where applicable, verify credential provenance, secure their interfaces and maintain non-wallet paths for users who cannot or choose not to use a wallet.