Skip to main content
Regulation

electronic Identification, Authentication and Trust Services (eIDAS2)

eIDAS2 is Regulation (EU) 2024/1183, which amends Regulation (EU) No 910/2014. It contains no calendar deadline: wallet availability runs 24 months from the entry into force of five implementing acts, and private relying-party acceptance 36 months. Those acts entered into force on 24 December 2024, giving end-2026 and end-2027.

Checked by Remmert
13 min read

When does eIDAS2 actually bite?

There is no calendar date in the Regulation. Both deadlines float, anchored to the entry into force of a defined set of implementing acts. Article 5a(1) gives Member States 24 months to provide a wallet; Article 5f(2) gives private relying parties 36 months to accept one. Those acts entered into force on 24 December 2024, so the dates are end 2026 and end 2027.

That floating mechanism is why this file is misreported more than any other on this site. See the other regulations we track for the same treatment.

Last updated: 17 August 2026. Checked against the consolidated text of Regulation (EU) No 910/2014, the implementing regulations, the Commission's implementation pages, the Dutch Kamerbrief of 18 December 2025 and the German BMDS.

At a glance

The floating deadline, and how to compute it

Article 5a(1) says Member States shall provide at least one European Digital Identity Wallet "within 24 months of the date of entry into force of the implementing acts" referred to in Article 5a(23) and Article 5c(6).

Article 5f(2) says private relying parties shall "no later than 36 months from the date of entry into force of the implementing acts referred to in Article 5a(23) and Article 5c(6)" also accept wallets.

Five implementing acts satisfy those two references. All were adopted on 28 November 2024, published on 4 December 2024, and entered into force on 24 December 2024.

The five implementing acts that start the clock

ActSubjectBasis

Wallet acceptance: the Article 5f(2) duty

Where private relying parties that provide services, with the exception of microenterprises and small enterprises, are required by Union or national law to use strong user authentication for online identification, or where strong user authentication for online identification is required by contractual obligation (including in the areas of transport, energy, banking, financial services, social security, health, drinking water, postal services, digital infrastructure, education or telecommunications), those private relying parties shall, no later than 36 months from the entry into force of the implementing acts, and only upon the voluntary request of the user, also accept European Digital Identity Wallets.

Four things follow, and the first is the one most summaries get wrong.

The sector list is not the test. It is introduced by "including in the areas of," which is illustrative, not a condition. The actual trigger is the legal or contractual requirement to use strong user authentication for online identification. That is what pulls in banks, payment institutions and e-money institutions through their strong customer authentication obligations, and it reaches insurers, investment firms and crypto-asset service providers wherever law or their own contracts require strong authentication.

Micro and small enterprises are carved out, by reference to Article 2 of the Annex to Recommendation 2003/361/EC.

The duty is reactive. It bites "only upon the voluntary request of the user." You must be able to accept a wallet when a customer offers one. You are not required to push customers towards it, and under Article 5a(15) you cannot: wallet use is voluntary and services must remain accessible by other means of identification.

Public sector bodies are on a different clock. Article 5f(1) requires Member States to accept wallets for access to public sector online services with no date stated: the obligation is unconditional once compliant wallets exist. The Dutch government reads that as biting from end-2026. Very large online platforms have their own rule in Article 5f(3), again with no date, and again only on the user's voluntary request.

What does eIDAS2 require?

Five obligation families. Each gets its own theme page once it is written.

  • Art. 5f(2)

    Wallet acceptance duty

    Who is caught: not by sector, but by a legal or contractual requirement to use strong user authentication for online identification. The micro and small enterprise carve-out, and why the duty is reactive rather than something you can push on customers.

  • Art. 5b

    Relying party registration

    Registration in your Member State of establishment before you may rely on wallets at all, the attribute set your registration fixes under 5b(3), and the access certificate that is a technical gate before it is a legal one.

  • AMLR Art. 22(6); recital 62

    Using the wallet for KYC

    Whether a wallet presentation can stand in for identity verification under the Wwft and the AMLR, what DNB and the AFM have actually said, and why identity verification is only one element of customer due diligence.

  • Art. 5a(5)(g)

    Qualified electronic signatures in the wallet

    The default, free-of-charge right to sign with a qualified electronic signature inside the wallet, and the proportionate-measures sentence that lets Member States confine free use to non-professional purposes.

  • Arts. 5a(4)–(5), 45d–45f

    Attestations and selective disclosure

    What the wallet is required to let a user do with person identification data and electronic attestations of attributes: request, obtain, select, combine, store, delete, share and present, with selective disclosure built in.

Registration: the part firms have not planned for

Article 5b(1) requires a relying party to register in the Member State where it is established before relying on wallets. This is not a formality, and the detail decides your architecture.

ProvisionWhat it does

Is accepting the wallet free?

For the user, yes. Article 5a(13): "The issuance, use and revocation of the European Digital Identity Wallets shall be free of charge to all natural persons." Article 5a(8) requires Member States to provide validation mechanisms free of charge, including for verifying the identity of relying parties.

For you, there is no such guarantee. We found no provision stating that acceptance is cost-free to the relying party. Registration must be "cost-effective and proportionate to the risk," but integration, certificates and operations are your own cost. Do not budget on the assumption that "the wallet is free" applies to your side of it.

Can we use the wallet for KYC?

Not settled, and we are not going to pretend otherwise. This is the question the audience asks first, and the honest answer is more useful than a confident one.

What points that way, and it is only recitals. eIDAS2 recital 62 says secure electronic identification and attestation of attributes "should offer additional flexibility and solutions for the financial services sector to allow the identification of customers and the exchange of specific attributes necessary to comply with, for example, customer due diligence requirements." AMLR recital 66 says the eIDAS identification solutions "should be taken into account and accepted by obliged entities for the customer identification process."

What is true today in the Netherlands. DNB's Open Book Q&A on electronic identification means permits eID for Wwft identification and verification where the means meets eIDAS assurance level substantial or high, with the institution "responsible for complying with these conditions at all times" and no pre-approval by DNB. That Q&A does not mention eIDAS2 or the wallet.

And the obvious point that gets lost. Identity verification is one element of customer due diligence. Beneficial ownership, purpose and intended nature of the relationship, source of funds, ongoing monitoring and screening are all untouched by a wallet. "Wallet equals KYC done" is wrong even on the most favourable reading.

The AFM has been more forward than DNB. Its March 2025 supervision report on the EDI-wallet says certified source data from the wallet makes fraud harder and "het voldoen aan de Wwft vereisten eenvoudiger" (simpler, not automatic), while flagging identity-fraud risk and digital exclusion of less digitally skilled consumers as the counterweight.

What does the wallet carry?

Article 5a(4)–(5): the wallet lets a user securely request, obtain, select, combine, store, delete, share and present person identification data and electronic attestations of attributes, "while ensuring that selective disclosure of data is possible."

Operative rules sit in Articles 45d to 45f, implemented by Implementing Regulation (EU) 2025/1569 of 29 July 2025, whose Articles 6 to 9 apply from 19 August 2026.

TypeDefinitionWhere

What else the wallet protects

Qualified electronic signatures. Article 5a(5)(g) requires the wallet to offer all natural persons the ability to sign by means of qualified electronic signatures by default and free of charge, but read the sentence that follows, which is usually dropped: Member States "may provide for proportionate measures to ensure that the use of qualified electronic signatures free-of-charge by natural persons is limited to non-professional purposes." The free-QES right is not unlimited.

Anti-profiling. Article 5a(14) prohibits wallet providers from collecting information about wallet use that is not necessary, and from combining wallet data with personal data from other services they or third parties offer, unless the user expressly requests it. Article 5a(16) requires the technical framework not to allow providers to obtain data enabling transactions or user behaviour to be tracked, linked or correlated, and to enable privacy-preserving techniques ensuring unlinkability. Note the addressee: both are aimed at wallet providers and the technical framework, not directly at relying parties. Your constraint is Article 5b(3) plus the GDPR.

The dates

2024

  1. 20 May 2024Passed

    eIDAS2 enters into force

  2. 24 December 2024Passed

    The five implementing acts enter into force, the clock starts

2025

  1. 27 May 2025Passed

    IRs 2025/846 to 849 in force: cross-border identity matching, security breaches, relying-party registration, list of certified wallets

2026

  1. 20 May 2026Passed

    Existing QTSPs to have submitted a conformity assessment report, two years from entry into force

  2. 11 August 2026Passed

    IR (EU) 2026/1731 amends four of the five clock-starting acts on standards and specifications

  3. 19 August 2026Passed

    Articles 6 to 9 of IR (EU) 2025/1569 apply: qualified and public-sector electronic attestations of attributes

  4. End 2026Upcoming

    Member States to provide at least one wallet (Art. 5a(1))

  5. End 2026Upcoming

    Public sector bodies to accept wallets (Art. 5f(1), no date stated in the text)

2027

  1. End 2027Upcoming

    Private relying parties to accept wallets (Art. 5f(2))

Will the deadline be met? Three signals say no

The Commission has not conceded any slip. Its pages, last updated 22 June 2026, still say wallets are to be provided "by the end of 2026." But three signals point the other way.

The Netherlands has said in terms that it will be late. From the Verzamelbrief digitalisering of 18 December 2025, Kamerstuk 26 643 nr. 1450: "Zoals eerder aan uw Kamer is gemeld, is de verwachting dat de implementatie voor EDI-wallets langer gaat duren dan de verordening voorschrijft."

Germany's own ministry plans for 2027. The BMDS states the first stage of the state EUDI wallet is planned for "Anfang 2027," with private certified wallets roughly twelve months after that, against a Commission line of "end of 2026."

Certification was not ready. Article 5c requires a wallet to be certified before it can be listed. ENISA's cybersecurity certification scheme for wallets was still a draft candidate in public consultation in April 2026, with no adoption date announced.

Add that the technical baseline moved in August 2026: IR 2026/1731 on 11 August, and ARF version 3.0.0 on 23 July 2026, which aligns the framework with the amending implementing regulations and introduces a Functional Conformance Assessment Framework, four months before the availability year closes.

The Netherlands, and how Germany compares

BZK owns the programme and the public NL Wallet. The RDI is already the Dutch eIDAS trust-services supervisor, and the government's stated intention is to designate it stelseltoezichthouder in the implementing act.

The implementing act is not in parliament. National legislation to make the EDI-stelsel and the public NL Wallet work is "in voorbereiding," with public consultation expected end 2026. There is no Kamerstukken dossier number. Note a trap for anyone searching: an internetconsultatie page titled "Uitvoeringswet eidas-verordening" and a legislative calendar entry exist, but given the department said in July 2026 that consultation is still to come, those are most likely the original 2014 eIDAS files, not eIDAS2. Check the dates before citing either.

The NL Wallet has an adoption constraint worth knowing. Activation requires a single DigiD login at assurance level hoog, and the Kamerbrief flags that only "several hundred thousand" citizens hold DigiD-Hoog. Private wallets may be certified and admitted after the system goes live, under identical requirements.

DigiD and eHerkenning continue. Both are notified eID schemes at levels substantial and high (eHerkenning published 13 September 2019, DigiD published 21 August 2020). Chapter II of Regulation 910/2014 survives eIDAS2, and we found no sunset provision for notified schemes; wallets and notified eID means coexist, and new Article 11a governs cross-border identity matching using either.

Germany, for comparison, builds its wallet through a consortium coordinated by SPRIND including Bundesdruckerei and the BSI, under the BMDS. The Digitale-Identitäten-Gesetz reached a Referentenentwurf on 26 March 2026 and Cabinet adoption on 20 May 2026, ahead of the Netherlands on the legislative track, behind on the stated launch date.

What recently changed

23 July 2026: ARF v3.0.0, aligning the reference framework with the amending implementing regulations and introducing the Functional Conformance Assessment Framework. Note what the ARF is and is not: a Toolbox deliverable, not law. The binding technical content sits in the implementing regulations.

15 July, in force 11 August 2026: Implementing Regulation (EU) 2026/1731 amends four of the five clock-starting acts as regards applicable standards and specifications.

9 June 2026: the Council adopted its negotiating position on the European Business Wallet, targeting political agreement by end 2026 and building on eIDAS2. Worth watching if your customers are legal persons rather than natural persons.

7 April 2026: Implementing Regulation (EU) 2026/798 on remote onboarding of users to wallets, using eID at assurance level substantial combined with additional remote onboarding procedures meeting level high.

2 to 30 April 2026: ENISA consulted on the draft candidate wallet certification scheme. No adoption date announced.

5 March 2026: feedback closed on three Commission proposals to update existing implementing acts, including the relying-party registration act.

Through 2025, the trust-services build-out continued. A large tranche of implementing regulations on 29 and 30 July 2025 covered qualified electronic attestations of attributes, remote signature creation device management, peer reviews and supervisory notifications, followed by further acts through December 2025 on time stamps, validation, registered delivery, preservation, trusted lists, qualified electronic ledgers and qualified electronic archiving (the two genuinely new trust services eIDAS2 created, alongside attestation of attributes and remote QSCD management).

What can GenCompl.ai do for you?

Our pipeline is built for standards and certification schemes as well as for regulation, including where there is no supervisor at all, and eIDAS2 is the case where the obligation is buried in arithmetic rather than in a date. The Regulation names no deadline. It names two periods, running from the entry into force of five implementing acts, one of which has since been amended. Working out what applies to you, and when, means tracking the acts rather than the Regulation.

The question we can answer from facts an institution already holds: are you caught by Article 5f(2) (that is, does Union law, national law or one of your own contracts require strong user authentication for online identification), and what attribute set should your Article 5b registration declare, given that it becomes the ceiling on everything you may ever request. Each conclusion carries its article, its source and the date it was last recalculated.

Questions and answers

Must our bank accept the EU Digital Identity Wallet, and from when?
Do we have to register as a relying party?
Can we use the wallet for KYC onboarding under the AMLR?
Is accepting the wallet free?
What is a qualified electronic attestation of attributes?
What happens to DigiD and eHerkenning?
Does the wallet replace strong customer authentication under PSD2?
Can we insist a customer uses the wallet?
Can we ask for more attributes once we have integrated?
Can we outsource wallet integration to a vendor?
What if a wallet is compromised?

Sources

Glossary

  • Data record

    Electronic data recorded with related meta-data supporting the processing of the data.

  • Strong user authentication

    An authentication based on the use of at least two authentication factors from different categories of either knowledge, possession or inherence, that are independent, and designed to protect the confidentiality of the authentication data.

  • Remote qualified electronic seal creation device

    A qualified electronic seal creation device that is managed by a qualified trust service provider in accordance with Article 39a on behalf of a seal creator.

  • Remote qualified electronic signature creation device

    A qualified electronic signature creation device that is managed by a qualified trust service provider in accordance with Article 29a on behalf of a signatory.

  • Product

    Hardware or software, or relevant components of hardware or software, which are intended to be used for the provision of electronic identification and trust services.

  • Conformity assessment body

    A conformity assessment body as defined in Article 2, point 13, of Regulation (EC) No 765/2008, which is accredited in accordance with that Regulation as competent to carry out conformity assessment of a qualified trust service provider and the qualified trust services it provides, or as competent to carry out certification of European Digital Identity Wallets or electronic identification means.

  • Body governed by public law

    A body defined in point (4) of Article 2(1) of Directive 2014/24/EU.

  • Public sector body

    A state, regional or local authority, a body governed by public law or an association formed by one or several such authorities or one or several such bodies governed by public law, or a private entity mandated by at least one of those authorities, bodies or associations to provide public services, when acting under such a mandate.

  • Validation data (eIDAS2)

    Data that is used to validate an electronic signature, an electronic seal, electronic time stamps, electronic registered delivery services, electronic attestations of attributes, European Digital Identity Wallets, qualified certificates for website authentication or an electronic ledger. The EU AI Act defines the same term differently.

  • Qualified electronic ledger

    An electronic ledger which meets the requirements laid down in Article 45l.