/

/

eIDAS 2.0 & the EU Digital Identity Wallet: What Businesses Need to Know

eIDAS 2.0 & the EU Digital Identity Wallet: What Businesses Need to Know

Europe is building a single, portable digital identity for 450 million people. Under eIDAS 2.0, every EU citizen and resident will be able to prove who they are, sign documents, and share verified credentials from a free app on their phone: the EU Digital Identity Wallet.

For banks, fintechs, telecoms, and any business that verifies customers, this is not a minor update. It changes how remote onboarding and KYC work across the whole single market.

This guide explains what eIDAS 2.0 is, how it differs from the original regulation, the rollout timeline, what the wallet stores and who must accept it, how it converges with the EU's new anti-money-laundering rules, and the practical steps businesses should take now.


What Is eIDAS 2.0?

eIDAS 2.0, formally the European Digital Identity Regulation (Regulation (EU) 2024/1183), is the updated EU framework for electronic identification and trust services. eIDAS stands for electronic Identification, Authentication, and Trust Services.

The regulation amends the original 2014 framework and, most importantly, introduces the EU Digital Identity Wallet (EUDI Wallet): a secure app that lets people store and selectively share their national eID and verified attributes such as a driving licence, diploma, or bank details. It was adopted in April 2024 and entered into force on 20 May 2024.


eIDAS 1 vs eIDAS 2.0: What Changed and Why


The original eIDAS (Regulation (EU) No 910/2014) let member states recognize each other's national eIDs, but only if a country chose to notify its scheme, and it focused narrowly on access to public services.

Adoption stalled. By some estimates, only around 14% of key public services allowed cross-border eID authentication, and private-sector uptake was limited. eIDAS 2.0 replaces that voluntary, fragmented model with a mandatory, harmonized one.

Area

eIDAS (2014/2016)

eIDAS 2.0 (2024)

Digital identity

National eIDs, recognized only if voluntarily notified

Every member state must issue an EU Digital Identity Wallet

Scope

Mainly cross-border access to public services

Public and private sectors, with mandatory acceptance in key sectors

User control

Limited, dependent on national schemes

Sole user control and selective disclosure built in

Trust services

Signatures, seals, timestamps, website certificates

Adds electronic archiving, ledgers, remote QSCD, attribute attestations

Adoption

Voluntary, uneven across states

Harmonized, with cross-border acceptance obligations


The EU Digital Identity Wallet (EUDI Wallet)


The wallet is a secure container on a user's phone. Issuance, use, and revocation are free for individuals, and using it is voluntary for citizens. It can hold and present three broad kinds of credential:

  • Person identification data (PID): core identity attributes issued by a member state at the highest assurance level, equivalent to showing a government ID.

  • Qualified electronic attestations of attributes (QEAA): certified credentials such as a driving licence, professional qualification, or proof of financial status.

  • Qualified electronic signatures (QES): legally binding digital signatures with the same effect as a handwritten signature.

Its defining feature is selective disclosure: a user can prove they are over 18 without revealing their birth date, or confirm an address without exposing their full identity record. The wallet also works offline via NFC and Bluetooth, keeps data stored locally, and includes a privacy dashboard so users see who requested what. See our overview of digital identity for the wider context.


Levels of Assurance Explained

eIDAS defines three levels of assurance (LoA) that describe how much confidence an identity check provides. The wallet must operate at the highest level.

Level

What it means

Low

Limited confidence; basic identity checks with minimal verification

Substantial

Meaningful confidence; verified identity evidence and stronger authentication

High

Highest confidence; robust proofing designed to prevent identity spoofing. Required for the EUDI Wallet


eIDAS 2.0 Timeline: Key Dates and Deadlines

The regulation is in force, and the detailed technical rules are being set through a series of implementing acts. Member states must provide wallets within 24 months of the relevant implementing acts. Forward dates below are targets and depend on those acts, so confirm them against current EU sources.

Date

Milestone

June 2021

European Commission proposes the European Digital Identity framework

Nov 2023

Political agreement reached on the EU Digital Identity Wallet

11 Apr 2024

Regulation (EU) 2024/1183 adopted; published in the Official Journal on 30 Apr 2024

20 May 2024

eIDAS 2.0 enters into force

Nov 2024 onward

First implementing acts adopted, setting technical and certification standards

Target: end of 2026

Member states expected to make at least one EUDI Wallet available to citizens

Target: from 2027

Large private-sector relying parties (e.g. banks, telecoms) required to accept the wallet

July 2027

The EU Anti-Money Laundering Regulation (AMLR) enters full application

2030

Digital Decade target of 80% wallet adoption among EU citizens


Trust Services Under eIDAS 2.0


eIDAS 2.0 keeps the existing regulated trust services and adds four new ones. Qualified versions carry the strongest legal weight and must come from a Qualified Trust Service Provider (QTSP).

Trust service

Status

Purpose

Electronic signatures (incl. QES)

Existing

Sign documents; QES equals a handwritten signature

Electronic seals

Existing

Prove origin and integrity of documents from a legal entity

Electronic timestamps

Existing

Prove data existed at a point in time

Electronic registered delivery (ERDS)

Existing

Evidence of sending, receipt, and integrity

Website authentication certificates (QWACs)

Existing

Authenticate a website's identity

Electronic archiving

New

Preserve documents securely over long retention periods

Electronic ledgers

New

Secure, immutable record of transactions

Remote QSCD management

New

Cloud-based signing while the user keeps sole key control

Attestation of attributes (QEAA)

New

Certify specific attributes: age, licences, qualifications


Who Must Accept the Wallet?


eIDAS 2.0 creates acceptance obligations that fall on the businesses consuming identity (the relying parties):

  • Very large online platforms designated under the Digital Services Act must accept the wallet for login.

  • Regulated, high-value sectors such as banking and telecoms are expected to accept the wallet for defined use cases from 2027.

  • Public services and services legally required to authenticate users must accept it as well.

  • Cross-border acceptance: member states must accept wallets issued by other member states for the covered use cases.

Is eIDAS 2.0 mandatory? The answer has three parts. It is voluntary for citizens to use a wallet, mandatory for every member state to issue one, and mandatory for certain relying parties (large online platforms and regulated sectors like banking) to accept it.


eIDAS 2.0, AML, and What It Means for KYC


For compliance teams, the biggest change is how eIDAS 2.0 converges with the EU's new Anti-Money Laundering Regulation (AMLR), which enters full application in July 2027. Today, AML directives are implemented 27 different ways: some countries allow video-based remote onboarding, others still require in-person checks.

AMLR harmonizes this, and industry analysis suggests that after it applies, remote identity verification will effectively rely on a short list of methods: national eIDs notified under eIDAS, the EUDI Wallet, and qualified trust services from certified providers.

The practical upside is significant. A customer verified once can reuse trusted credentials to onboard elsewhere in the EU without repeating checks. Industry estimates cited by Deloitte suggest onboarding times in financial services could fall by as much as 90%, and KYC automation could cut related operational costs by 40 to 60%. For identity-verification programs, the wallet becomes a new, high-assurance input alongside document and biometric verification, not a replacement for them.


How eIDAS 2.0 Changes Remote Onboarding

The wallet does not remove the need for strong verification; it changes where trust comes from. Expect a hybrid model:

  • Wallet present: a customer shares a verified, high-assurance credential through the wallet, and the business consumes it with selective disclosure, minimal data, and instant results.

  • Wallet absent: many customers will not have a wallet for years, so document capture, NFC reading, face matching, and liveness detection remain essential.

  • Ongoing checks: AML screening, sanctions, and PEP checks still sit on top of identity, whichever route is used.

Businesses that build flexible digital onboarding now, able to accept both wallet credentials and traditional eKYC, will be ready as adoption grows.


Criticisms and Open Questions


eIDAS 2.0 is not without debate. The main concerns raised during and after negotiations include:

  • Website certificate rules (Article 45): browser makers argued that requirements to trust certain government-approved certificates could slow their ability to revoke compromised certificates. Later drafts added safeguards, but the debate continues.

  • Privacy and surveillance: digital-rights groups warned that a large identity framework could enable cross-service tracking. The regulation responds with data minimization, selective disclosure, zero tracking by design, and a privacy dashboard.

  • Implementation complexity: delivering interoperable wallets across 27 member states, with hundreds of trust service providers meeting consistent standards, is a major undertaking.


What Businesses Should Do Now


Although the EUDI Wallet rollout is still developing, businesses should not wait until acceptance becomes mandatory to begin preparing. Integrating wallet-based identity affects onboarding flows, technical architecture, privacy controls, compliance procedures, and the way customer data is requested and stored.

Early planning gives organisations time to test interoperability, adapt their KYC processes, and maintain a smooth experience for customers who continue to use traditional verification methods.

  1. Confirm your role. Are you a relying party (you consume identity) or a trust service provider? Your obligations differ.

  2. Check your sector deadline. Banks, telecoms, and very large online platforms face acceptance obligations first.

  3. Plan wallet acceptance. Map how your onboarding will consume EUDI Wallet credentials and selective disclosure.

  4. Keep verification flexible. Maintain strong document, NFC, biometric, and liveness checks for customers without a wallet.

  5. Align eIDAS with AML. Prepare for AMLR in 2027 by ensuring your customer due diligence accepts eIDAS-conformant identity methods.


Getting eIDAS 2.0 Ready with Qoobiss

Qoobiss helps EU businesses onboard customers with high-assurance identity verification today and adapt as the EUDI Wallet rolls out. Our platform combines document verification, NFC reading, biometrics, and liveness with AML, sanctions, and PEP screening, giving you a flexible flow that accepts both traditional verification and, as it matures, wallet-based credentials.

Prepare for eIDAS 2.0. Talk to our team about future-proofing your onboarding and KYC, book a Qoobiss demo.


Frequently Asked Questions

What is eIDAS 2.0?

When was eIDAS 2.0 released?

Is eIDAS 2.0 mandatory?

What is the EU Digital Identity Wallet?

What are eIDAS 2.0 verifiable credentials?

How does eIDAS 2.0 affect KYC and onboarding?

Why Qoobiss

Book a 30-minute KYC verification demo → sales@qoobiss.com



Expo Business Park

54A Av. Popisteanu Street, 1st floor

Bucharest, Romania

© Qoobiss 2026. All rights reserved

Expo Business Park

54A Av. Popisteanu Street, 1st floor

Bucharest, Romania

© Qoobiss 2026. All rights reserved

Expo Business Park

54A Av. Popisteanu Street, 1st floor

Bucharest, Romania

© Qoobiss 2026. All rights reserved