The European Commission plays a central role in eIDAS 2.0 governance. It is responsible for developing the regulatory framework, publishing implementing acts, overseeing the Architecture and Reference Framework (ARF), and coordinating implementation across EU Member States. In short, the Commission acts as the driving force behind the entire European Digital Identity ecosystem. The sections below unpack exactly what that means in practice, from enforcement powers to how organizations should engage with Commission-led processes.
What powers does the European Commission have under eIDAS 2.0?
Under eIDAS 2.0, the European Commission holds significant legislative and executive powers. It can adopt delegated and implementing acts that set binding technical standards, define certification requirements, and establish interoperability rules for the EUDI Wallet and the broader trust services framework. These powers allow the Commission to shape how digital identity works across all 27 Member States.
More specifically, the Commission’s authority under eIDAS 2.0 covers a broad range of responsibilities:
- Adopting implementing regulations on topics such as identity matching, wallet certification, protocols and interfaces, and security breach management
- Developing and maintaining the Architecture and Reference Framework (ARF), which defines the technical blueprint for the EU Digital Identity Wallet
- Funding and coordinating the Large Scale Pilots that test the wallet in real-world scenarios
- Providing a reference implementation of the EUDI Wallet as an open-source prototype for Member States to build on
- Establishing and overseeing the European Digital Identity Cooperation Group (EDICG), which advises the Commission on policy and technical matters
These powers make the Commission the central authority in eIDAS 2.0 governance, though it works in close partnership with Member States rather than acting unilaterally.
How does the European Commission enforce eIDAS 2.0 compliance?
The European Commission enforces eIDAS 2.0 compliance primarily through its power to adopt legally binding implementing acts and through oversight of national supervisory bodies. While day-to-day enforcement sits with Member State authorities, the Commission sets the rules those authorities must apply and can take action when Member States fail to implement the regulation correctly.
Enforcement works at several levels. At the regulatory level, the Commission publishes implementing regulations that define mandatory requirements for wallet providers, trust service providers, and relying parties. These are not optional guidelines but binding EU law. Member States must transpose and apply them within their national frameworks.
At the oversight level, the Commission works with national supervisory bodies that are responsible for monitoring compliance within their borders. The EDICG supports this by facilitating peer reviews of electronic identification schemes and helping supervisory bodies align their approaches. If a Member State persistently fails to meet its obligations, the Commission has the option to initiate infringement proceedings through the European Court of Justice.
For organizations operating in regulated sectors such as financial services or healthcare, this means that compliance with eIDAS 2.0 is ultimately a legal obligation, not a voluntary choice. The Commission’s implementing acts define the floor, not the ceiling.
What is the Commission’s role in the EUDI Wallet governance framework?
The European Commission is the architect of the EUDI Wallet governance framework. It defines the technical standards, funds the pilots, provides the reference implementation, and maintains the Architecture and Reference Framework that all wallet solutions must conform to. Without the Commission’s coordination, the wallet ecosystem would lack the common foundation needed for cross-border interoperability.
In practical terms, the Commission’s role in EUDI Wallet governance includes three core functions.
Setting the technical foundation
The ARF, developed and maintained by the Commission in collaboration with the EDICG, defines how wallets must be built, what data formats they must support, and how they must interact with relying parties and trust service providers. The Commission has also published an open-source reference implementation of the wallet, which Member States and private parties can use as a starting point for their own solutions.
Funding and coordinating the pilots
In April 2023, the Commission launched four Large Scale Pilots involving over 350 entities from 26 Member States, Norway, Iceland, and Ukraine. These pilots test the wallet across real-world scenarios including accessing government services, opening bank accounts, SIM registration, and more. The Commission co-funds these consortia and uses the findings to refine the ARF and improve the wallet’s security, usability, and interoperability ahead of the December 2026 deadline for wallet issuance and public sector acceptance.
How does the Commission work with member states on eIDAS 2.0 implementation?
The Commission works with Member States through a structured cooperation framework built around the European Digital Identity Cooperation Group (EDICG). This group, formerly known as the eIDAS Expert Group, brings together representatives from Member States and the Commission to exchange best practices, advise on delegated and implementing acts, and co-develop the technical toolbox that underpins eIDAS 2.0 implementation.
This cooperation model is deliberately collaborative rather than top-down. The Commission does not dictate every implementation detail. Instead, it provides the framework, the standards, and the funding, while Member States retain responsibility for issuing wallets to their citizens and residents. By 24 December 2026, every Member State is legally required to have at least one certified EUDI Wallet operational and available to citizens, residents, and businesses that want one. Public sector bodies must also accept notified wallets as a means of identification from that date.
The EDICG also plays an important role in organizing peer reviews of national electronic identification schemes and supporting supervisory bodies as they work to implement the regulation. This helps ensure that the level of assurance and security remains consistent across borders, which is essential for the wallet to function as a genuinely pan-European tool. Organizations operating across multiple Member States, including those in the public sector, benefit directly from this harmonization effort.
What implementing acts has the European Commission already published for eIDAS 2.0?
The European Commission has published a substantial body of implementing regulations under eIDAS 2.0, covering the technical and procedural requirements for the EUDI Wallet and the broader trust services ecosystem. These acts translate the high-level requirements of the regulation into specific, enforceable rules that organizations must follow.
Among the implementing acts already published, organizations will find rules covering:
- Person Identification Data (PID) and Electronic Attestation of Attributes (EAA) — defining what identity data wallets must support and how it must be structured
- Wallet integrity and core functionalities — setting minimum security and functional requirements for wallet solutions
- Certification of wallet solutions — establishing how wallets must be assessed and certified before deployment
- Protocols and interfaces — defining how wallets communicate with relying parties and trust service providers
- Cross-border identity matching — specifying how identities are matched when a wallet is used across Member State borders
- Registration of wallet relying parties — setting out how organizations that accept wallet credentials must register and operate
- Qualified trust services — updating requirements for qualified electronic signatures, seals, timestamps, registered delivery services, and preservation services
- Supervisory body reporting — defining the formats and procedures for annual compliance reports by national supervisory bodies
This is not an exhaustive list, but it illustrates the breadth of the Commission’s legislative output under eIDAS 2.0. Organizations preparing for compliance need to track these implementing acts closely, as they define the specific obligations that apply to their use cases.
How should organizations engage with Commission-led eIDAS 2.0 processes?
Organizations should engage with Commission-led eIDAS 2.0 processes by monitoring the ARF and implementing acts as they are published, participating in public consultations where possible, and aligning their internal compliance and technology roadmaps with the Commission’s published timelines and technical specifications.
For most organizations, direct participation in Commission processes such as the EDICG is limited to Member State authorities and formally recognized stakeholders. However, there are several practical ways to stay engaged and prepared:
- Follow the ARF repository and public discussion topics, which are open for stakeholder input
- Track the Commission’s published implementing regulations and assess their impact on your current systems
- Engage with your national supervisory body, which participates in EDICG peer reviews and can provide guidance on domestic implementation
- Monitor the Large Scale Pilot outcomes, which will directly influence the final technical specifications organizations must implement
The 24 December 2026 deadline marks the point by which every Member State must have at least one certified EUDI Wallet available and by which public sector bodies must accept notified wallets as a means of identification. For regulated private sector organizations — including those in banking, financial services, healthcare, telecoms, energy, transport, education, social security, drinking water, postal services, digital infrastructure, digital services, and very large online platforms with more than 45 million users in the EU — the obligation to accept the EUDI Wallet within contexts where strong user authentication is legally or contractually required applies from 24 December 2027, under Article 5f of the regulation. Organizations that wait for final clarity before starting preparation risk falling behind. The implementing acts already published provide enough detail to begin assessing gaps in current identity infrastructure, compliance processes, and technology capabilities.
How TrustTech helps with eIDAS 2.0 governance readiness
Understanding the Commission’s role in eIDAS 2.0 governance is one thing. Translating that into concrete action for your organization is another. That is where TrustTech’s solutions come in. TrustTech helps organizations in regulated sectors bridge the gap between regulatory requirements and practical implementation, with a platform built on European digital identity standards and designed to be eIDAS 2.0 ready by design.
Working with TrustTech means your organization can:
- Align your identity and trust infrastructure with the ARF and Commission implementing acts
- Enable reusable, wallet-ready identity verification that meets eIDAS 2.0 requirements
- Reduce compliance overhead with a single platform that covers identification, qualification, and signing
- Move from preparation to production quickly, with an average time to production of under five months
- Support cross-border interoperability for customers and partners across EU Member States
Whether you are in finance, government, healthcare, or another regulated sector, the eIDAS 2.0 governance framework creates obligations your organization needs to meet. TrustTech provides the expertise and practical approach to help you get there. Ready to take the next step? Get in touch with TrustTech to discuss your eIDAS 2.0 readiness.