What is the eIDAS 2.0 wallet certification process?

European passport and smartphone displaying a digital credential card on marble, with an embossed certification seal nearby.

The eIDAS 2.0 wallet certification process is the official procedure through which a European Digital Identity Wallet solution is assessed, verified, and approved as meeting the security and technical requirements set out in the eIDAS 2.0 regulation. Certification is carried out by accredited conformity assessment bodies and is a mandatory step before a wallet can be officially deployed and recognised across EU Member States. This article walks through the key questions organizations are asking about wallet certification, from who is responsible to when compliance deadlines apply.

Who is responsible for certifying eIDAS 2.0 wallets?

Responsibility for certifying eIDAS 2.0 wallets is shared between accredited conformity assessment bodies (CABs) and national supervisory authorities. CABs carry out the technical assessment of a wallet solution against the defined certification requirements. National authorities then oversee the process and maintain the official list of certified European Digital Identity Wallets.

The European Commission has published implementing regulations that set out the framework for this certification, including rules on how CABs must be accredited and how the assessment scheme works. This means the process is not left to individual Member States to define from scratch. Instead, there is a common European certification scheme that all wallet solutions must go through, regardless of which country they originate from.

Member States themselves are legally required to provide a wallet to all citizens, residents, and businesses. Whether they build the wallet themselves or rely on a private provider, the solution must still pass through this certification process before it can be officially recognised and used across the EU.

What are the requirements a wallet must meet to get certified?

To receive eIDAS 2.0 wallet certification, a wallet solution must demonstrate compliance with the Architecture and Reference Framework (ARF), which covers security, interoperability, data protection, and core functional requirements. The wallet must protect user data, support selective disclosure of attributes, and be technically capable of interoperating with services across EU Member States.

The implementing regulations published under eIDAS 2.0 cover a wide range of specific requirements. Key areas include:

  • Core functionalities and integrity: The wallet must perform its essential functions reliably and securely, including storing and presenting credentials.
  • Protocols and interfaces: The wallet must use standardised protocols so it can communicate with relying parties and other wallets across borders.
  • Security of personal identification data (PID) and electronic attestations of attributes (EAA): The wallet must handle identity data and credentials according to strict security standards.
  • User control and privacy: Users must be able to choose what data they share, with whom, and when. Selective disclosure is a core requirement.
  • Cross-border identity matching: The wallet must support mechanisms for verifying identity across different Member States.

The large-scale pilot projects that ran across Europe from 2023 to 2025 played an important role in stress-testing these requirements in real-world scenarios, from opening a bank account to registering a SIM card to accessing government services. The feedback gathered from those pilots has directly informed the technical specifications and certification criteria now in use.

How does the conformity assessment process work?

The conformity assessment process for an eIDAS 2.0 wallet follows a structured sequence: the wallet provider engages an accredited conformity assessment body, submits documentation and the wallet solution for review, and undergoes a formal technical assessment. If the wallet meets all requirements, the CAB issues a conformity assessment report, which forms the basis for official certification.

The process draws on a certification scheme that is defined at the European level, ensuring consistency across Member States. The CAB evaluates whether the wallet solution meets the ARF and the relevant implementing regulations. This includes reviewing technical documentation, testing the wallet’s functionality and security controls, and assessing how the solution handles personal data.

Once a wallet solution has been certified, it is added to the official list of certified European Digital Identity Wallets. This list is maintained and made publicly available, giving relying parties and users transparency about which wallet solutions have been formally approved.

It is worth noting that certification is not a one-time event. If a wallet solution is updated or significantly changed, it may need to go through a new assessment or, at minimum, a review to confirm it still meets the certification requirements. This keeps the certification relevant as technology and threats evolve.

What’s the difference between wallet certification and wallet provider notification?

Wallet certification and wallet provider notification are two distinct steps in the eIDAS 2.0 ecosystem. Certification confirms that a wallet solution meets the technical and security requirements. Notification is the formal process by which a Member State informs the European Commission that a certified wallet is being made available, making it officially recognised across the EU.

Think of it this way: certification is about the product, notification is about the deployment. A wallet can be technically certified but not yet notified, which means it has not yet entered the official EU-wide recognition framework. Only once a wallet has been both certified and notified by a Member State does it gain full cross-border legal recognition under eIDAS 2.0.

The notification process involves the Member State submitting information about the wallet scheme to the Commission, including details of the certification. The Commission then publishes this information, making the wallet part of the trusted ecosystem that relying parties across Europe can rely on. This two-step structure is intentional: it separates technical quality assurance from political and legal recognition.

For organizations building services that accept wallet credentials, understanding this distinction matters. A certified wallet that has not yet been notified may not yet carry the same legal weight as a fully notified one, even if it is technically sound.

When do organizations need to be ready for wallet certification compliance?

Member States are legally required to make a certified European Digital Identity Wallet available to all citizens, residents, and businesses by 2026. This means organizations that need to accept wallet credentials, integrate wallet-based authentication, or build services that rely on the EUDI Wallet ecosystem should be preparing their systems and compliance frameworks now.

For wallet providers, the certification process takes time. Engaging a conformity assessment body, preparing documentation, and completing the assessment is not a quick exercise. Organizations involved in wallet development or deployment should factor this lead time into their planning well ahead of the 2026 deadline.

For organizations that are not building wallets but will be required to accept them as relying parties, such as banks, healthcare providers, and government services, the timeline is equally pressing. Regulated sectors in particular need to assess how wallet-based identity verification fits into their existing compliance frameworks, including KYC, AML, and strong customer authentication requirements.

In 2026, the first wave of wallet deployments is expected across multiple Member States. Organizations that wait until wallets are fully live before beginning their integration work will find themselves under significant time pressure. The practical advice from those who have been following the large-scale pilots closely is clear: start the groundwork now, not when the regulation is already in force.

How TrustTech helps with eIDAS 2.0 wallet certification

Navigating the eIDAS 2.0 wallet certification process involves more than reading the regulation. It requires translating complex technical and legal requirements into concrete actions across your systems, processes, and compliance frameworks. That is exactly where TrustTech adds value.

TrustTech supports organizations at every stage of the wallet certification and compliance journey:

  • Compliance readiness assessment: Understanding where your current infrastructure stands relative to eIDAS 2.0 requirements, including ARF alignment and data handling standards.
  • Technical integration: Connecting your services to the EUDI Wallet ecosystem using standardised protocols and interfaces, so you are ready to accept and issue wallet credentials.
  • Reusable identity infrastructure: Building onboarding and verification flows that are wallet-ready from day one, reducing duplication and compliance overhead.
  • Sector-specific guidance: Whether you operate in financial services, government, or healthcare, TrustTech brings practical experience in regulated environments where identity trust is business-critical.
  • End-to-end platform: From first identity verification to qualified digital signatures, TrustTech’s platform covers the full digital identity lifecycle in a single, eIDAS 2.0-ready solution.

The 2026 deadline is closer than it looks, and the certification process takes time. If your organization needs to understand what wallet compliance means for you specifically, get in touch with TrustTech and start the conversation today.