All posts
5 min readOpenKYC Team

eIDAS 2.0 and the EU Digital Identity Wallet: What Businesses Need to Know

eidaseudi-walletverifiable-credentials

eIDAS 2.0 is the update to the European framework that governs electronic identification and trust services. Its most visible product is the European Digital Identity Wallet, usually shortened to the EUDI Wallet: a user-held wallet, on a phone, that holds verified identity data and credentials a person can present to public and private services across the EU. For businesses that accept customers in Europe, this is not a niche compliance detail. It changes how a verified identity can arrive at your door.

A caution before the detail. Regulatory specifics here are moving, and the implementing rules are technical and still being finalized in places. We will speak at the level of direction and the known framework, and we will avoid asserting exact dates we are not certain of. Treat this as orientation, then confirm specifics against current official sources for your sector and member state.

What eIDAS 2.0 changes

The original eIDAS framework, in force for years, did two main things: it set rules for electronic trust services (signatures, seals, timestamps, website authentication) and it created a way for member states to recognize each other's national electronic identity schemes. It worked, but adoption of cross-border electronic identity was uneven, and there was no common, citizen-held wallet.

eIDAS 2.0 is the revision that adds that missing piece. The headline changes:

  • A common wallet. Member states are required to make an EU Digital Identity Wallet available to citizens and residents who want one. The wallet is held by the user, on their device.
  • A shift toward user-held credentials. Rather than a service calling a national identity system in the background, the person presents credentials from their own wallet and consents to what is shared.
  • Recognition across borders and into the private sector. The intent is that a wallet issued in one member state is accepted across the EU, and not only by governments. Many private-sector relying parties are expected to accept it for defined purposes.

The model the wallet implements, where a person holds verified credentials and decides what to disclose, is the self-sovereign identity idea moving from theory into regulation. We unpack that model in self-sovereign identity explained, and we cover the wallet itself in more depth in the EUDI Wallet explained.

What the wallet holds

The EUDI Wallet is designed to carry more than a single government ID. Broadly, it is meant to hold:

  • A core set of verified identity attributes. Person identification data sourced from authoritative national systems: the high-assurance backbone of the wallet.
  • Electronic attestations of attributes. These are credentials issued by trusted parties that attest to specific facts: a qualification, a membership, a licence, an age threshold, an account relationship. This is where the private sector and reusable credentials come in.
  • Trust-service artifacts. Support for qualified electronic signatures and related functions, so a person can sign with legal weight from the wallet.

The important shift for businesses is that a customer can arrive holding a credential that a trusted issuer already verified, and present a proof of exactly the attribute you need, with the user consenting to that disclosure.

What relying parties should prepare for

A relying party is any service that accepts a credential from a wallet. If you onboard or serve users in the EU, you are likely to be one. Preparing well means a few things.

  • Plan to accept wallet presentations, not just collect documents. The wallet flow is different from a document upload. The user presents a signed credential and consents, and you verify it. Your onboarding will need a path that receives and checks a presentation, not only one that scans an ID.
  • Understand the registration and rules for relying parties. eIDAS 2.0 contemplates that relying parties identify themselves and declare what data they intend to request. You can ask for what your use case needs and are expected not to over-ask. Build your flows to request the minimum.
  • Design for selective disclosure. The wallet is built so a person can prove a single attribute, for example that they are over an age threshold or resident in a country, without handing over a full identity record. Asking for the narrow claim is both good practice and aligned with the framework's intent.
  • Verify signatures and issuer trust. Accepting a credential means checking that it was issued by a trusted party and has not been tampered with or revoked. This is signature and trust-list verification, not a manual review of a scanned photo.
  • Watch your sector's obligations. Some sectors and very large platforms face stronger expectations to accept the wallet than others. Confirm where your business sits.

Timelines, at the level we are confident about

Here is where we stay deliberately careful. eIDAS 2.0 entered into force and set in motion a multi-year rollout. Member states are required to make wallets available within a defined window after the implementing technical rules are finalized, and those technical specifications have been arriving in stages. Pilots have been running to test wallet interoperability across borders.

What we will commit to is the shape, not precise dates: this is a phased rollout over multiple years, the technical detail is being settled through implementing acts, and the obligation to make wallets available, plus expectations on certain relying parties to accept them, lands progressively rather than all at once. If you need a specific date for a specific obligation in a specific member state, check the current official sources. Anyone quoting you a single EU-wide "go live" date is oversimplifying.

The practical takeaway does not depend on the exact dates: the direction is set, the wallet is being built, and businesses that serve EU customers should plan to accept user-held verified credentials rather than assuming the document-upload status quo will persist.

How reusable verifiable credentials fit

The wallet does not replace the need for someone to verify an attribute in the first place. It standardizes how a verified attribute is held and presented. Those two things are complementary. A trusted issuer verifies a fact once and issues an electronic attestation. The person holds it in their wallet. A relying party later verifies the attestation by checking its signature and issuer, in milliseconds, without re-running the original verification.

That is the reusable credential pattern, and it is exactly the model the EUDI Wallet normalizes at the scale of a continent. The wallet provides the container and the legal recognition. Reusable verifiable credentials, built on open standards like W3C Verifiable Credentials and OpenID4VC, provide the portable, signed attestations the wallet is designed to carry. The closer an organization's verification approach already sits to that pattern, the smaller the leap to a wallet-ready world.

Where OpenKYC fits

OpenKYC is building a reusable KYC marketplace on open standards (W3C Verifiable Credentials, OpenID4VC): verify once, hold the credential in your own wallet, reuse it everywhere, and earn every time it is used. That is the same shape the EUDI Wallet pushes the whole EU toward, user-held credentials a relying party can verify by signature rather than by collecting documents again. We are building for that direction. Join the waitlist at openkyc.org.

Verify once. Use everywhere. Earn every time.

OpenKYC is building the reusable KYC marketplace on open identity standards. Be first in line.

Join the waitlist