EU eIDAS Regulation
eIDAS is the European Union regulation governing electronic identification and trust services. The original 2014 regulation made electronic signatures and national electronic identity schemes mutually recognizable across member states. The 2024 revision, commonly called eIDAS 2.0, goes considerably further: it requires every member state to offer citizens a European Digital Identity Wallet, and requires large parts of the private sector to accept it.
| Original regulation | Regulation (EU) No 910/2014, applicable from 2016 |
| Revision | Regulation (EU) 2024/1183, in force since 20 May 2024 |
| What the original did | Mutual recognition of national eID schemes, and a legal framework for trust services |
| Assurance levels | Low, substantial and high |
| Trust services | Electronic signatures, seals, timestamps, registered delivery, website authentication |
| The 2024 addition | The European Digital Identity Wallet, or EUDI Wallet |
| Member state obligation | Offer at least one certified wallet to citizens and businesses by late 2026 |
| Private sector obligation | Obligated sectors must accept the wallet from late 2027 |
What the original regulation established
Two things, and the second is the one most people mean when they say eIDAS.
Mutual recognition. A national electronic identity scheme notified under eIDAS must be accepted by public bodies in other member states for online services. A Spanish citizen can use a Spanish eID to access an Estonian public service.
Trust services. A legal framework for electronic signatures, seals, timestamps and website authentication certificates, with a tiered structure. A qualified electronic signature, issued by a qualified trust service provider, carries the same legal effect as a handwritten signature across the whole union — which is the provision that made cross-border digital contracting workable.
The assurance levels — low, substantial and high — describe how much confidence an identification scheme provides, and they are the concept most likely to appear in a European verification requirements document. They map loosely onto the levels described under identity proofing, and a service specifying “substantial” is making a statement about the evidence and process behind an identity, not about the technology.
What eIDAS 2.0 changes, and when
The revision creates the European Digital Identity Wallet: an application, provided or certified by each member state, in which a citizen holds verified identity attributes and presents them selectively.
| Milestone | Requirement |
|---|---|
| May 2024 | Regulation (EU) 2024/1183 enters into force |
| November 2024 | Implementing acts adopted covering wallet functionality, interoperability and certification |
| Late 2026 | Member states must offer at least one certified wallet to citizens and businesses |
| Late 2027 | Obligated private-sector organizations must accept the wallet for authentication |
| 2030 target | 80% of EU citizens using a digital identity wallet |
The member state deadline is imminent. Anyone operating in Europe who has not yet decided how they will handle wallet presentation is now working to a short timetable, and the private sector acceptance obligation follows roughly a year later.
The obligation to accept is the part with commercial consequence. It applies to sectors including banking, telecommunications, healthcare and very large online platforms — which means a substantial number of organizations will need to consume a wallet presentation as an alternative to the verification flow they operate today.
Why this matters for identity verification
The honest reading is that the wallet changes where verification happens rather than whether it is needed — and it is worth being clear about that, because the framing in the market runs both ways.
What the wallet removes. For a citizen who holds one, a relying party can receive attributes already verified by a member state, presented selectively. That is materially better than re-photographing a document: the evidence is stronger, the data minimization is better, and the user experience is shorter.
What it does not remove. Coverage will be partial for years — the 2030 target is 80%, which is an admission that a fifth of citizens will not hold one at the end of the decade. Non-EU customers hold nothing. And the wallet has to be populated in the first place, which means document and biometric verification at issuance rather than at every transaction.
The practical position for anyone building onboarding in Europe is therefore two paths rather than one: accept a wallet presentation where offered, and run identity document verification for everyone else — which will remain the majority for some time. eKYC in a European context increasingly means supporting both, and the binding question for a provider is whether it can consume a wallet credential as well as read a document.
What eIDAS can’t do
It does not reach outside the EU. Non-EU customers hold no wallet, and a global service cannot build on the assumption of one.
It does not deliver coverage quickly. The 2030 aspiration is 80%, and wallet issuance itself requires identity verification at the point of enrollment.
It does not settle who bears liability. Relying on a wallet attestation shifts some risk and the allocation is still being worked through in practice.
It does not standardize acceptance. Member states implement within the framework, and the practical experience of consuming a wallet will differ by country for some time.
Frequently asked questions
What is eIDAS?
The EU regulation governing electronic identification and trust services. The 2014 original made national electronic identity schemes mutually recognizable across member states and created a legal framework for electronic signatures, seals and timestamps. The 2024 revision adds the European Digital Identity Wallet.
What is the EU Digital Identity Wallet?
An application, provided or certified by each member state, in which citizens hold verified identity attributes and present them selectively to relying parties. Member states must offer at least one certified wallet by late 2026, and obligated private-sector organizations must accept it from late 2027.
What are eIDAS assurance levels?
Low, substantial and high — a grading of how much confidence an electronic identification scheme provides, based on the evidence and process behind the identity rather than the technology used. A service specifying ‘substantial’ is making a statement about how rigorous the proofing was.
Does the EUDI Wallet replace identity document verification?
For citizens who hold one, it can replace re-verifying at each transaction. It does not remove the need for document verification overall: coverage will be partial for years, non-EU customers hold no wallet, and the wallet itself must be populated through identity verification at issuance.
Related reading
- Identity proofing — the assurance concept eIDAS levels describe, in its general form
- Digital certificate — the trust service machinery underneath qualified signatures
- GDPR — the other EU regime constraining how this data is handled
- Digital passport — the travel-credential equivalent of moving identity onto a device