openideurope.eu

eIDAS 2.0 explained: what the EU identity law changes

eIDAS 2.0 (Regulation (EU) 2024/1183) obliges every EU country to offer a digital identity wallet. Key dates, what changes for citizens, and who must accept it.

Digital identityPublished

eIDAS 2.0 is the common name for Regulation (EU) 2024/1183, the law that creates the European Digital Identity Framework. It entered into force on 20 May 2024 and amends Regulation (EU) No 910/2014, the original eIDAS Regulation on electronic identification and trust services. Its centrepiece is a state-backed wallet app that lets people prove who they are, and share verified documents, in any EU country. You can read the legal text on EUR-Lex.

Where eIDAS 2.0 comes from

The 2014 regulation had two main effects. It required member states to recognise each other’s notified electronic identification schemes for public services, and it created a legal framework for electronic signatures, seals, time stamps and similar trust services. In practice, uptake of cross-border eID stayed low: national schemes were uneven, and few private services could use them.

The European Commission proposed an update in 2021. After negotiation with the Parliament and the Council, the amended regulation was published in the Official Journal in April 2024. The core idea is simple: instead of relying on each country’s separate login scheme, every member state offers a wallet built to common technical rules, and services across Europe can rely on it.

What eIDAS 2.0 changes

  • The European Digital Identity Wallet. A mobile app, provided or recognised by each member state, that can hold your identity data and other credentials. See our guide to the EU Digital Identity Wallet.
  • Electronic attestations of attributes. Verified statements such as a diploma, a driving licence or a proof of age, issued in a form the wallet can store and present.
  • Free qualified signatures. The wallet must let natural persons sign with a qualified electronic signature free of charge for non-professional use. More in qualified electronic signatures.
  • Pseudonyms and privacy rules. Users can use pseudonyms where identification is not legally required, and a dashboard shows what has been shared. Wallet providers must not collect more data about how you use the wallet than is necessary.
  • New trust services. Electronic archiving, electronic ledgers and the remote management of qualified signature creation devices join the existing list.
  • Acceptance duties. Some services must take the wallet, covered below.
  • High level of assurance. Wallets must reach the assurance level ‘high’. See levels of assurance.

The regulation also changes rules on website authentication certificates, which has drawn criticism from some browser vendors and civil society. Whether and how browsers must treat qualified website certificates is a separate debate from the wallet itself.

The dates that matter

Date What happens
20 May 2024 Regulation (EU) 2024/1183 enters into force
28 November 2024 Commission adopts the first five implementing regulations on wallet functions, credentials, protocols, notification and certification
24 December 2024 The first implementing acts take effect, which starts the clock
2025 Further implementing acts on trust services and attestations follow
Around 24 December 2026 Each member state must make at least one wallet available
Around 24 December 2027 Acceptance duties for regulated private services and very large platforms apply

As of October 2026 the picture is uneven. Several countries have public test environments and a few national apps are live, but ENISA has noted that certification of wallets was still ahead of the member states for much of 2026. Our rollout timeline tracks the current status.

Who has to accept the wallet

The acceptance rules are one of the most consequential parts of the regulation.

  1. Public sector. Where a member state requires electronic identification to access an online service, public bodies must accept the wallet.
  2. Regulated private services. Organisations that are legally or contractually required to use strong user authentication, for example banks, energy and telecom providers, must accept the wallet when a customer offers it. Micro and small enterprises are largely exempt.
  3. Very large online platforms. Platforms designated under the Digital Services Act must allow users to authenticate with the wallet if the user asks.

Businesses that need to identify other businesses should also look at the European Business Wallet, which is a related but separate initiative.

Criticism and open questions

eIDAS 2.0 was contested during negotiation and still raises questions. Privacy experts have asked whether the wallet can really prevent services from linking your transactions, and whether limits on what verifiers may request can be enforced technically (see wallet privacy). Others point to cost and complexity for member states and small businesses, and to the risk that people without a modern smartphone are left behind, which is why access to services must stay possible without the wallet. Delays in standards and certification are a further practical concern.

Supervision follows the usual EU pattern: member states designate supervisory bodies for trust services and for the wallet framework, the Commission publishes the lists of notified schemes and certified wallets, and it can start infringement proceedings against a member state that fails to implement the rules.

What it means for you

For individuals, the regulation promises three things: a free wallet, control over what you share, and recognition across borders. For example, you could prove your identity to open a bank account in another member state. We cover that scenario in cross-border eID.

Be realistic about the first years. Early wallets will support a limited set of credentials, and the number of services that accept them will grow gradually. Keep your existing eID, passkeys and second factors in good order meanwhile.

For organisations, the key tasks are to register as a relying party in the member states where you operate, map which login and identification flows fall under the acceptance duty, and prepare technical integration based on the standards named in the Commission’s implementing rules. See OpenID4VP for one of the building blocks.

Frequently asked questions

What is the difference between eIDAS and eIDAS 2.0?

The original eIDAS Regulation of 2014 made national eIDs recognisable across borders and set rules for electronic signatures and trust services. eIDAS 2.0 is not a new law but an amendment that adds the European Digital Identity Wallet, electronic attestations of attributes and several new trust services.

Is the EU wallet mandatory for citizens?

No. Member states must offer a wallet, but citizens are free to use it or not. The regulation also states that using the wallet must not be a precondition for accessing public or private services, so alternatives have to stay available.

Who has to accept the wallet?

Public sector bodies that already require electronic identification must accept it. Private organisations that are legally or contractually required to use strong user authentication, for example banks, as well as very large online platforms under the Digital Services Act, have to accept it from 24 December 2027. Micro and small enterprises are generally exempt.

Does eIDAS 2.0 apply outside the EU?

It binds the EU member states, and the EEA states are expected to follow through the EEA agreement. Switzerland and the United Kingdom are not bound, but both run their own programmes and may seek mutual recognition.

More in Digital identity