The EUDI Wallet: What Europe's Digital Identity Push Means for Business
The European Union is doing something no large economy has attempted before: mandating that every member state give its citizens a free digital identity wallet, and requiring large parts of the private sector to accept it. If you build products that touch identity, age, or KYC, the EUDI Wallet is the single most important regulatory development on your roadmap. Here is what it actually requires, and what it leaves open.
eIDAS 2.0: the regulation behind the wallet
The legal foundation is the revised eIDAS regulation, commonly called eIDAS 2.0, which entered into force in May 2024. The original eIDAS (2014) standardized electronic signatures and cross-border login between government systems, but adoption stayed thin. The revision goes much further: it establishes the European Digital Identity (EUDI) Wallet as a thing every member state must provide.
Because it's a regulation rather than a directive, it applies directly across all member states without national transposition. The core obligation is blunt: each member state must offer at least one EUDI Wallet to its citizens and residents, free of charge. The implementing acts that pin down technical detail were adopted at the end of 2024, starting the clock. Member states are required to make wallets available by late 2026.
What the wallet actually holds
The wallet is not a login button. It is a container for cryptographically signed attestations about you, anchored by one mandatory credential:
- PID (person identification data) is the core government-issued identity attestation: name, date of birth, and other legal identity attributes. This is the wallet's anchor credential, issued under each member state's authority.
- Attestations of attributes cover everything else: driver's licenses, diplomas, professional qualifications, prescriptions, payment-related attributes. Both public bodies and qualified private issuers can issue these.
Crucially, the wallet is designed for selective presentation. You can prove you are over 18 without revealing your birth date, or share your degree without your address. The user sees what is being requested and approves each presentation. That consent-and-minimization model is written into the regulation, not just the UX guidelines.
Tested in the open: the large-scale pilots
The EU did not design this in a vacuum. Since 2023, large-scale pilot consortia, spanning hundreds of public and private organizations across member states, have been testing wallet use cases: opening bank accounts, mobile SIM registration, travel credentials, education credentials, and digital driver's licenses. The pilots feed directly back into the Architecture and Reference Framework, which is why the spec has gone through multiple substantial revisions. Imperfect, but a far more battle-tested process than most government IT efforts.
The part businesses underestimate: mandatory acceptance
Most coverage focuses on member states issuing wallets. The sharper edge for business is the acceptance obligation: eIDAS 2.0 requires relying parties in certain sectors to accept the EUDI Wallet when users want to identify themselves with it.
That includes sectors that legally require strong identification (banking and financial services, telecoms, and other regulated industries) plus very large online platforms for login. If you operate in those categories in the EU, "we only support document upload and a selfie" stops being a complete answer. Wallet acceptance becomes a compliance requirement, not a feature request.
The wallet is also positioned as Europe's preferred answer to age verification under the DSA: proving "over 18" from a wallet attestation rather than uploading an ID to every platform. For compliance and product teams, the practical implication is the same either way: somewhere on your roadmap there needs to be an integration that can request, receive, and verify wallet presentations.
Built on open standards, not a Brussels-only stack
The Architecture and Reference Framework (ARF), the technical blueprint for the wallet, deliberately builds on the same open standards stack the broader identity industry has converged on:
- OID4VCI and OID4VP (OpenID for Verifiable Credential Issuance and Presentations) as the protocols for getting credentials into a wallet and presenting them to verifiers
- SD-JWT-based credentials for selective disclosure
- ISO mdoc formats for documents like mobile driver's licenses
- The same issuer-holder-verifier model defined in the W3C Verifiable Credentials work
This matters enormously. The EUDI Wallet is not a proprietary European protocol island; it is the largest deployment yet of the standards stack that wallets, issuers, and verifiers worldwide are already building on. Code and infrastructure written for the open stack will substantially carry over.
What it means for private-sector identity products
A reasonable question: if governments hand everyone a free identity wallet, what is left for private identity companies?
Quite a lot, because the regulation builds rails, not businesses. The EU is standardizing how credentials are issued, held, and presented. It is not building the marketplace of issuers and verifiers, the developer experience for relying parties, the cross-border KYC products, or the incentive layer that makes holders want to reuse credentials. Public rails, private value on top: the same pattern as open banking, where PSD2 mandated the APIs and an entire fintech ecosystem grew on top of them.
For anyone building in identity, the strategic read is straightforward: don't compete with the rails. Build the layer that makes them useful: orchestration, verification UX, credential marketplaces, and the trust products regulators won't ship.
A realistic view on timelines
Some skepticism is warranted. Government software deadlines slip; eIDAS 1.0 itself badly underdelivered on adoption. Twenty-seven member states will not ship equally polished wallets at the same moment, certification is a real bottleneck, and early versions will support a narrower set of attestations than the vision describes. Expect the late-2026 deadline to produce uneven results, with genuine consumer-scale usage building over the years after.
But direction matters more than dates. The regulation is in force, the implementing acts are adopted, budgets are committed, and the acceptance obligations give the ecosystem demand-side pull that version 1.0 never had. Whether mainstream adoption lands in 2027 or 2029, businesses that treat wallet-based identity as a someday problem will be retrofitting under deadline pressure while competitors are already integrated.
Where OpenKYC fits
OpenKYC is building a reusable KYC marketplace on the same open standards (W3C Verifiable Credentials, OpenID4VC): verify once, hold the credential in your own wallet, reuse it everywhere, and earn every time it's used. Join the waitlist at openkyc.org.