eIDAS 2.0 / EUDI Wallet

Your proof. In your wallet.

For thirty years verifying somebody meant collecting a document and keeping it. The European Digital Identity Wallet inverts that: the person holds the credential, presents only the attributes you actually need, and you verify it cryptographically without becoming its custodian. It is a change of model with a date attached, and the first thing it asks of most organisations is not to issue anything — it is to check.

What the revised regulation does

Mutual recognition, with an implementation date

The original regulation made electronic signatures and trust services interoperable across the Union. The revision extends the same logic to identity itself, and puts the wallet in the middle of it.

A wallet per member state

Each state provides at least one, certified at the highest assurance level the framework defines, holding both the person's identity data and attestations issued by others. Use is voluntary for the citizen — and services may not disadvantage those who do not use it.

An acceptance obligation, not an option

Where strong authentication is already required by law, relying parties will have to accept the wallet. That is what makes this different from every previous digital identity initiative: the demand side is regulated, not persuaded.

Standards, not a national interface

The technical framework is built on the same open specifications the rest of the market is converging on: W3C credentials and the OpenID protocols for issuance and presentation, alongside ISO's mobile document standards. Integrating once is meant to be enough.

Two wallets, four layers

The person's wallet and the company's are not the same problem

Citizen wallets are close to delivery. Organisation identity — identifying a legal entity and proving who may act for it — has lagged behind for years, and it is the layer that actually touches your business systems.

A personAn organisation
Foundations

Identify

A person identified to the assurance level the transaction requires, with the wallet itself certified at the highest level defined by the regulation.

A legal entity identified against an authoritative register rather than against a document somebody uploaded. Company identifiers become resolvable instead of transcribed.

Context

Attributes

Qualifications, licences, entitlements — a driving licence, a diploma, a professional registration — presented selectively, one attribute at a time.

Registration data, licences, permits, tax status, ownership. The things a counterparty currently proves with a PDF and a phone call to the chamber of commerce.

Agency

Mandates

Acting for someone else: a parent, a patient, a client. Delegation that today lives in a paper authorisation and a support agent's judgement.

Who may act on behalf of the company, for what, up to which value, until when. This is the capability that barely exists digitally today, and the reason business wallets are being regulated at all.

Execution

Transactions

Signatures and seals with legal effect, on the strength of trust services that already exist under the current regulation.

Legally binding contracts, filings and registered communications executed in the entity's name, with the mandate that authorised them attached to the record.

The highlighted row is the interesting one. Knowing that a company exists has been solved for years; reliably knowing that this person may sign for it, up to this amount, until this date, still runs on notaries, scanned mandates and phone calls.

The dates

What is already scheduled

Three moments, in the order they arrive. Only the third is still moving; the first two are the ones worth planning against.

By the end of 2026

Every member state offers a wallet

The revised regulation obliges each member state to make at least one European Digital Identity Wallet available to citizens and residents, certified at assurance level high. Large-scale pilots have been running for years to get the technical framework there.

Then, by sector

Relying parties have to accept it

Acceptance obligations reach services where strong user authentication is already required by law — banking, telecoms, healthcare, platforms, public services. For those organisations the wallet is not a product decision; being able to verify a presentation becomes part of operating.

24 to 36 months after adoption

Business wallets follow the same pattern

The proposed regulation on EU Business Wallets extends the model to legal entities, with public sector acceptance mandated within a comparable window. The direction is settled even while the text is still being negotiated.

Still in negotiation
How Monokee approaches it

Both ends of the exchange, on standards

Issuance and verification are capabilities the platform has today, expressed as blocks in a journey rather than as a separate wallet project.

Today

Verifier, as a step in a journey

A journey can request a credential the way it requests a second factor: at the point where it changes the decision. The request names the attributes needed, the wallet answers with a signed presentation, and the flow continues on the result. This runs on OpenID for Verifiable Presentations, so it is not wallet-specific.

Today

Issuer of what you already know

Attributes the organisation holds — an employment relationship, a role, a qualification, a verified check — become a credential the person carries away, issued over OpenID for Verifiable Credential Issuance after whatever proof the policy demands.

Today

Alongside the federation you already run

Wallet acceptance does not replace OpenID Connect and SAML, and pretending otherwise is how pilots stay pilots. A presentation becomes one more way to satisfy a step in a flow that also serves everyone who does not have a wallet — which the regulation itself requires you to keep serving.

Emerging

Mandates and organisation identity

Delegated administration and per-domain identities already model who may act inside which organisation, which is the shape mandate management will need. Formal conformance to the business wallet framework depends on a text that is still being negotiated, and is not claimed here.

Four things worth being clear about

Before anyone says the word pilot

  • The wallet is not a role Monokee takes. Issuing and verifying are; holding the credential belongs to the person, and an issuer that also holds it has rebuilt the intermediary the model removes.
  • Accepting a presentation is cheaper than issuing one, and it is the obligation that arrives first. Most organisations should scope verification long before they scope issuance.
  • Assurance level and certification apply to the wallet and the trust services, not to every system that speaks to them. What a relying party has to demonstrate is that it verified correctly and asked for no more than it needed.
  • Selective disclosure is the point, not a detail: asking for two attributes instead of a document is what makes the whole model defensible under data protection law. See the minimisation ladder →

This page describes how the platform relates to the European digital identity framework. It is not legal advice, and nothing here is a claim of certification under that framework: certification applies to wallets and trust service providers, and where a text is still in negotiation the page says so.

Bring us the document check you repeat every year

A licence, a certification, a company registration, a power of attorney. We will look at what it takes to verify it as a presentation instead — and what it would take to issue it.

Talk to an expert