eIDAS 2.0 Explained: The EU Digital Identity Regulation
A plain-language explanation of eIDAS 2.0, the EUDI Wallet, electronic attestations, signatures, relying parties, and the 2026 rollout.
“eIDAS 2.0” is the informal name commonly used for Regulation (EU) 2024/1183, which amended the original 2014 eIDAS Regulation and established the European Digital Identity Framework.
The headline feature is the EU Digital Identity Wallet, but the amendment is broader. It changes how electronic identity can work across borders, extends trust services, creates rules for wallet-relying parties and gives digital attestations a clearer place in the European trust framework.
From notified eID schemes to wallets
The original eIDAS framework created mutual recognition for national electronic identification schemes notified by Member States. It did not require every Member State to provide a broadly usable digital identity, and cross-border use remained uneven.
The amended framework requires each Member State to provide at least one EUDI Wallet. A wallet can be provided directly by the state, under a state mandate, or independently and recognized by the state. The goal is shared rules and interoperability rather than a single centralized provider.
The European Commission says Member States must provide wallets by the end of 2026.
The six changes that matter most
1. Every Member State must provide a wallet
Article 5a of the amended regulation creates the delivery obligation. The wallet must operate under an electronic identification scheme at assurance level high and be certified under the framework.
This does not create one identical national app. It creates minimum legal and technical conditions that national wallet solutions must meet.
2. Wallet use must remain voluntary
Natural persons must be able to obtain, use and revoke the wallet free of charge. People who do not use it must not be disadvantaged when accessing public or private services, the labour market or business activity. Existing identification and authentication options must remain possible.
That requirement has direct product implications: an organization cannot make a wallet-only journey its silent default without considering a lawful alternative.
3. Identity expands into attestations
The framework is not limited to a legal name and identifier. It includes electronic attestations of attributes—digitally authenticated statements about characteristics, rights, permissions or objects.
The regulation distinguishes:
- ordinary electronic attestations of attributes;
- qualified electronic attestations of attributes issued by qualified trust service providers; and
- electronic attestations issued by or on behalf of public-sector bodies responsible for authentic sources.
That makes credentials such as qualifications, licences and entitlements part of a governed trust ecosystem. Their legal effect and verification requirements still depend on the attestation category and issuer.
4. Relying parties must register
An organization that intends to rely on EUDI Wallets for a digital public or private service must register in the Member State where it is established. Registration includes the relying party's identity, contact details, intended use and requested data.
Article 5b also says a relying party must:
- request no more wallet data than it declared;
- identify itself to the user;
- validate PID and electronic attestations it receives;
- update its registration information when it changes; and
- accept pseudonyms where legal identification is not required.
The Commission's current service-provider guidance notes that national registration detail is still developing. That makes registration an operational dependency, not a checkbox an SDK can erase.
5. Acceptance becomes mandatory in defined cases
Article 5f does not require every private business to accept the wallet.
It applies to public-sector online services that require electronic identification, very large online platforms that require authentication, and certain non-small private relying parties where Union law, national law or contract requires strong user authentication for online identification. For the latter group, the regulation names sectors such as banking, health, transport, energy, education and telecommunications and uses a deadline tied to the relevant implementing acts.
In each case, wallet use is initiated at the user's voluntary request. The exact applicability should be assessed against the service, entity size, sector and national law.
6. eIDAS gains new trust services
The amended framework extends beyond wallets. It adds or expands rules for areas including electronic archiving, electronic ledgers, remote signature and seal creation devices, and website authentication certificates.
That matters because an EUDI Wallet transaction may connect several trust services. Identity presentation, qualified signature creation, timestamping and long-term archiving are related, but they are not interchangeable.
Privacy and user control
The regulation requires selective disclosure, a wallet transaction dashboard, relying-party identification and mechanisms to request erasure or report suspicious data requests. Wallet providers face restrictions on tracking use and combining wallet data with unrelated services.
The legal text also calls for privacy-preserving techniques that enable unlinkability where an attestation does not require identifying the user.
These controls do not make every wallet transaction anonymous. The relying party may legitimately request identifying data, and it remains responsible for its own GDPR purpose, lawful basis, minimisation, retention and security obligations.
Standards and implementing rules
The regulation establishes the legal outcomes. Implementing regulations and the EUDI Architecture and Reference Framework translate them into technical requirements, protocols, interfaces and trust models.
The Commission adopted core technical standards in late 2024, including rules for wallet functionality, PID and attestations, ecosystem notifications, certification, protocols and interfaces. Additional implementation work has continued since then.
The architecture is versioned and remains active. A team should pin the version it implements and distinguish final implementing law from an evolving reference document or discussion paper.
What eIDAS 2.0 does not guarantee
The regulation does not guarantee that:
- every national wallet launches on the same date;
- every credential is issued in every Member State;
- every service can request every attribute;
- one technical integration automatically satisfies national registration;
- an identity presentation is a qualified electronic signature; or
- every wallet-supported transaction meets a business's sector-specific compliance duties.
The common framework reduces fragmentation. It does not make jurisdiction, credential availability or legal purpose disappear.
A useful way to remember the framework
Think in four layers:
- Law: eIDAS as amended by Regulation 2024/1183.
- Implementation rules: Commission implementing regulations.
- Architecture: the EUDI ARF, technical specifications and trust model.
- Deployment: certified national wallets, issuers, relying-party registers and live credentials.
A statement can be true at one layer and premature at another. “The regulation supports qualified signatures” does not prove that a specific national production wallet and qualified provider can complete a particular signing journey today.
For the broader product and user picture, read the complete EUDI Wallet guide. For dates, see the EUDI Wallet rollout timeline.
This article is general information, not legal advice. Use the consolidated legal text and relevant national guidance for an actual compliance decision.
Our field notes are checked against primary regulations, standards, and official provider documentation. Read the research standard.