What are the biggest compliance challenges with eIDAS 2.0?

Worn EU passport resting against a modern security card reader on a glass desk, with red tape coiled nearby symbolizing bureaucratic complexity.

The biggest compliance challenges with eIDAS 2.0 include adapting legacy identity infrastructure to new technical standards, navigating cross-border interoperability requirements, managing the tension between data minimization under GDPR and the wallet’s data exchange model, and meeting hard regulatory deadlines that are already in effect. These challenges apply to a wide range of organizations, from banks and healthcare providers to government agencies and technology platforms. The sections below break down each challenge in practical terms and explain what organizations should do about it.

Which organizations are actually required to comply with eIDAS 2.0?

eIDAS 2.0 compliance obligations apply to a broad range of organizations, not just public authorities. Any organization that offers digital services to EU citizens or businesses and requires identity verification is likely affected. This includes banks, insurance companies, healthcare providers, telecoms, e-commerce platforms, and any entity classified as a “relying party” under the regulation.

The regulation introduces a specific obligation for large online platforms to accept the European Digital Identity Wallet (EUDI Wallet) as a means of authentication. This requirement targets platforms that fall under the Digital Services Act and provide services to significant numbers of EU users. Public sector bodies in all EU Member States are also required to support wallet-based authentication for digital public services.

Beyond these direct obligations, many organizations will feel indirect pressure to comply. If your competitors or partners integrate the EUDI Wallet and you do not, you risk losing customers who expect seamless, reusable digital identity across services. Organizations in financial services and healthcare face particularly strong compliance incentives, given the overlap with existing AML, KYC, and patient data regulations.

What makes eIDAS 2.0 technically harder to implement than eIDAS 1.0?

eIDAS 2.0 is significantly more complex to implement than its predecessor because it introduces a completely new technical architecture built around verifiable credentials, cryptographic proofs, and wallet-based identity. eIDAS 1.0 was primarily about recognizing national eID schemes across borders. eIDAS 2.0 goes much further by defining how identity attributes are issued, stored, and selectively disclosed.

The key technical shift is the move toward verifiable credentials and the Architecture and Reference Framework (ARF), which specifies how wallets, issuers, and relying parties must interact. Organizations that built their identity verification flows on traditional username-password or single sign-on systems will need to re-engineer significant parts of their infrastructure.

Specific technical challenges include:

  • Integrating with wallet protocols that may differ between Member States during the transition period
  • Supporting selective disclosure, which allows users to share only specific attributes rather than full identity documents
  • Implementing cryptographic verification of credentials without a centralized trust anchor
  • Ensuring your systems can handle both legacy eID methods and new wallet-based flows simultaneously
  • Meeting the security and assurance level requirements for different use cases, from low-assurance logins to high-assurance transactions

Organizations that have not yet invested in modern identity infrastructure will find that the gap between where they are and where they need to be is substantial. Exploring the right digital identity solutions early in the process is essential to avoid costly rework later.

How do cross-border interoperability requirements create compliance risk?

Cross-border interoperability is one of the most complex compliance risks in eIDAS 2.0 because it requires your systems to accept and validate identity credentials issued by any EU Member State, not just your own. If your platform cannot reliably verify a wallet credential from another country, you are technically non-compliant and risk excluding users or failing regulatory audits.

The challenge is that while eIDAS 2.0 defines a common framework, implementation details vary across Member States during the rollout phase. National wallet implementations may differ in how they encode attributes, which trust anchors they use, or how they handle edge cases. This creates a moving target for organizations that need to build interoperable systems before all national implementations are finalized.

The Large-Scale Pilots launched in 2023 and running through 2025 are specifically designed to stress-test interoperability across borders, involving over 350 entities from 26 Member States plus Norway, Iceland, and Ukraine. The insights from these pilots are feeding back into the technical specifications. However, organizations cannot simply wait for the pilots to conclude before starting their own preparations.

Practical interoperability risks include rejecting valid credentials from users in other countries, failing to recognize trust anchors from foreign wallet issuers, and building integrations that work today but break when national implementations are updated. Organizations in government services and cross-border financial transactions face this risk most acutely.

What data protection conflicts arise between eIDAS 2.0 and GDPR?

The most significant tension between eIDAS 2.0 and GDPR centers on the legal basis for processing identity data and the principle of data minimization. eIDAS 2.0 enables rich, verified identity attributes to flow between parties, while GDPR requires that only the minimum necessary data is collected and processed for a specified purpose. Balancing these two obligations in practice is genuinely difficult.

One concrete conflict arises with audit trails. eIDAS 2.0 requires organizations to maintain records of identity transactions for accountability and legal certainty. GDPR, on the other hand, limits how long personal data can be retained and requires a clear legal basis for doing so. Organizations must define retention policies that satisfy both frameworks, which often requires legal analysis rather than a simple technical fix.

A second tension involves the wallet’s selective disclosure feature. While the EUDI Wallet is designed to let users share only the attributes they choose, relying parties must not request more data than they need. If your onboarding or verification flow asks for more attributes than strictly necessary, you risk a GDPR violation even if the user technically consents to sharing them.

Organizations should treat eIDAS 2.0 implementation as a data protection project as much as a technical one. Privacy impact assessments, updated data processing agreements, and clear documentation of the legal basis for each identity transaction are all necessary steps. This is especially relevant for organizations handling sensitive categories of data, such as health or financial information.

When do organizations need to be fully compliant with eIDAS 2.0?

The core eIDAS 2.0 regulation entered into force in 2024, and Member States are legally required to make the EUDI Wallet available to citizens, residents, and businesses by 2026. For organizations classified as relying parties with mandatory acceptance obligations, the practical compliance window is now. Waiting until the last moment significantly increases implementation risk.

The timeline breaks down roughly as follows:

  1. 2024: eIDAS 2.0 regulation formally adopted; implementing acts and technical specifications published progressively
  2. 2025: Large-Scale Pilots conclude; final technical specifications consolidated; national wallet implementations accelerate
  3. 2026: Member States must have wallets available; mandatory relying parties must be capable of accepting wallet-based authentication
  4. Ongoing: Supervision and enforcement ramp up; non-compliant organizations face regulatory scrutiny

In 2026, organizations that have not yet begun their eIDAS 2.0 implementation are already behind. The technical complexity, the need for legal and compliance review, and the time required to integrate new identity infrastructure mean that organizations realistically need 12 to 24 months of lead time for a full implementation. Starting now is not early; it is necessary.

How should organizations start preparing for eIDAS 2.0 compliance today?

Organizations should start by mapping their current identity verification flows against eIDAS 2.0 requirements to identify where the gaps are. This means understanding which of your services require identity verification, what assurance levels are needed, and whether your existing infrastructure can support wallet-based credentials. A gap analysis is the foundation of any realistic compliance roadmap.

From there, practical preparation involves several parallel workstreams. On the technical side, organizations should begin testing integrations with available wallet reference implementations and reviewing the Architecture and Reference Framework. On the legal and compliance side, teams should update data processing documentation, review contracts with identity service providers, and assess the GDPR implications of new data flows.

It is also worth engaging with industry groups, sector-specific guidance, and the outputs of the Large-Scale Pilots, which are designed to share learnings broadly. Organizations that participate in or follow pilot outcomes will have a clearer picture of what works in practice, not just in theory.

Finally, do not underestimate the organizational dimension. eIDAS 2.0 touches compliance, legal, IT, product, and customer experience teams simultaneously. Assigning clear ownership and building cross-functional alignment early will save significant time and cost later. You can explore how other organizations in similar sectors have approached this challenge by reviewing customer experiences and sector-specific use cases.

How TrustTech helps with eIDAS 2.0 compliance challenges

TrustTech is purpose-built to help organizations navigate exactly the compliance challenges described in this article. Rather than leaving you to piece together solutions from multiple vendors, TrustTech provides an integrated platform that covers the full identity lifecycle, from initial verification to qualified digital signature, all designed to meet eIDAS 2.0 requirements from the ground up.

Concretely, TrustTech helps your organization with:

  • EUDI Wallet readiness: Connecting your systems to wallet-based identity flows so you can accept verified credentials from any EU Member State
  • Reusable compliance: Enabling customers to verify once and reuse their identity across your services, reducing onboarding friction and repeated KYC checks
  • Qualified digital signatures: Linking identity to every signature and decision, with a complete audit trail that satisfies both eIDAS 2.0 and GDPR requirements
  • Cross-border interoperability: Infrastructure that handles the complexity of different national implementations so you do not have to build it yourself
  • Sector-specific expertise: Deep experience in finance, healthcare, government, and other regulated sectors where identity compliance is business-critical

TrustTech sits between the parties that need to interact, without owning any of them, making it a neutral and trusted infrastructure layer for your digital identity ecosystem. Whether you are just starting your compliance assessment or already deep in implementation, the right partner makes the difference between a project that stalls and one that delivers. Get in touch with TrustTech to discuss your eIDAS 2.0 compliance roadmap.