What are the eIDAS 2.0 requirements for mobile ID documents?

Smartphone displaying a digital ID card beside an EU passport on a marble government-office desk, bathed in soft blue ambient light.

Under eIDAS 2.0, mobile ID documents are digital representations of physical identity credentials stored and presented through the European Digital Identity Wallet. The regulation sets out specific requirements covering document types, technical standards, assurance levels, and privacy rules that apply to any mobile ID used in regulated interactions across the EU. This article walks through each of those requirements so your organisation knows exactly what to prepare for.

Which mobile ID documents fall under eIDAS 2.0?

eIDAS 2.0 covers a broad range of mobile ID documents that can be stored and presented through the EUDI Wallet. The most prominent example is the mobile driving licence (mDL), but the framework also applies to digital passports, national identity cards, residence permits, and other government-issued credentials presented in digital form.

Beyond these foundational identity documents, eIDAS 2.0 extends to a wider category of attestations that carry legal weight in regulated interactions. The large-scale pilots currently testing the EUDI Wallet have confirmed practical use cases across several document types, including:

  • Mobile driving licences (mDL): Used for both roadside checks and online age or identity verification
  • Travel documents: Digital representations of passports and visas for use at border crossings and airport security
  • Social security and health documents: Including the European Health Insurance Card, supporting cross-border healthcare access
  • Educational credentials: Diplomas, degrees, and certificates stored as verifiable digital attestations
  • Organisational identity documents: Credentials that prove a person is an authorised representative of a business

The common thread is that all of these documents must be issued by a recognised authority, stored securely in the wallet, and presented in a way that allows the receiving party to verify their authenticity without contacting the original issuer in real time.

What technical standards must mobile ID documents meet under eIDAS 2.0?

Mobile ID documents under eIDAS 2.0 must conform to internationally recognised technical standards to ensure interoperability across EU Member States. The most important standard for mobile driving licences is ISO 18013-5, which defines how an mDL is stored, transmitted, and verified in both online and proximity-based interactions.

ISO 18013-5 specifies the data model, the communication protocols for device-to-device transfer (such as Bluetooth Low Energy and NFC), and the cryptographic mechanisms used to protect the credential. This means a mobile driving licence issued in one Member State can be verified by a reader in another Member State using the same technical process.

For the broader EUDI Wallet ecosystem, mobile ID documents must also align with the Architecture and Reference Framework (ARF) developed by the eIDAS Expert Group. This framework defines the technical building blocks that all wallet implementations must support, including:

  • Selective disclosure, so users can share only the specific attributes needed for a transaction
  • Cryptographic binding between the credential and the wallet device
  • Support for both online and offline presentation scenarios
  • Interoperability with qualified trust services as defined in the eIDAS trust framework

Organisations that plan to accept mobile ID documents must ensure their verification infrastructure supports these standards. Relying parties cannot simply check a visual representation; they need to validate the cryptographic signature attached to the credential.

What assurance level is required for mobile ID documents under eIDAS 2.0?

Mobile ID documents used in regulated interactions under eIDAS 2.0 must meet the High assurance level as defined in the regulation. This is the highest level in the eIDAS framework, meaning the identity behind the credential has been verified through a rigorous process that provides strong confidence in the person’s claimed identity.

High assurance requires that the original identity proofing was carried out using reliable and verifiable sources, typically involving in-person verification or remote identification with equivalent security guarantees. The credential itself must be bound to a secure element or trusted execution environment on the user’s device, making it resistant to cloning or unauthorised transfer.

For context, eIDAS defines three assurance levels: Low, Substantial, and High. Most cross-border public services and regulated private sector use cases, such as opening a bank account or accessing government benefits, require at least Substantial assurance. However, for mobile ID documents that serve as legal equivalents to physical identity documents, the High level is the expected baseline.

This has direct implications for wallet providers and document issuers. The identity verification process used to issue a mobile ID document must itself meet High assurance requirements, which means organisations in sectors like financial services or government need to review their existing onboarding and verification processes to confirm they qualify.

How does the EUDI Wallet handle mobile ID document verification?

The EUDI Wallet verifies mobile ID documents through a combination of cryptographic proof and selective disclosure. When a user presents a mobile ID, the wallet generates a cryptographically signed response that proves the credential was issued by a trusted authority and has not been altered, without necessarily revealing the full document to the verifier.

The verification process works differently depending on whether the interaction is online or in person. In an online context, the wallet communicates with the relying party’s system through a secure protocol, and the relying party’s infrastructure validates the credential against the issuer’s public key. In a physical context, such as a traffic stop where a driver presents their mobile driving licence, the exchange happens device-to-device using proximity protocols like NFC or Bluetooth, without requiring an internet connection.

A key feature of this architecture is that the issuing authority does not need to be contacted during the verification. The cryptographic signature embedded in the credential is sufficient to confirm its authenticity. This protects user privacy and prevents the issuer from tracking where and when a credential is used.

The four large-scale pilot programmes running across 26 Member States have been testing exactly these verification flows across real-world scenarios, from airport check-in to SIM card registration, generating practical feedback that is shaping the final technical specifications.

What are the privacy requirements for mobile ID documents in eIDAS 2.0?

eIDAS 2.0 places strong privacy requirements at the centre of mobile ID document design. The regulation requires that mobile ID documents support selective disclosure, meaning users must be able to share only the specific attributes required for a transaction rather than their full identity document.

For example, when proving age for an online service, a user should be able to confirm they are above a certain age without revealing their date of birth, name, or any other personal data. This principle of data minimisation is not optional; it is a core technical requirement that all compliant mobile ID documents and wallet implementations must support.

The privacy framework also prohibits the issuing authority from tracking how and where credentials are used. Each presentation of a mobile ID document must be unlinkable to other presentations, so that neither the issuer nor any third party can build a profile of a user’s activity based on their credential use.

Users retain full control over what they share and with whom. The EUDI Wallet is designed so that nothing is shared without the user’s explicit consent for that specific interaction. This gives individuals sovereignty over their personal data in a way that physical documents cannot provide, since a physical document reveals everything on it whenever it is shown.

For organisations operating in healthcare or other sensitive sectors, these privacy requirements also intersect with GDPR obligations, reinforcing the need for data minimisation and purpose limitation in every identity interaction.

What do organisations need to do to accept eIDAS 2.0-compliant mobile IDs?

To accept eIDAS 2.0-compliant mobile ID documents, organisations need to register as a relying party within the EUDI Wallet ecosystem and implement the technical infrastructure required to verify cryptographically signed credentials. This is not simply a software update; it requires a structured approach to compliance, integration, and governance.

The practical steps organisations should work through include:

  1. Understand which use cases apply: Identify the identity interactions in your services where mobile ID documents could replace or complement existing verification methods.
  2. Register as a relying party: Complete the formal registration process that allows your organisation to request and verify identity attributes from EUDI Wallets.
  3. Implement compliant verification infrastructure: Integrate the technical protocols required to validate ISO 18013-5 credentials and other wallet-based attestations.
  4. Update your data minimisation practices: Ensure your systems request only the attributes genuinely needed for each transaction, in line with selective disclosure requirements.
  5. Review your existing assurance level requirements: Confirm that the assurance levels your services currently require align with what the EUDI Wallet can provide.
  6. Train relevant teams: Compliance, legal, IT, and customer-facing teams all need to understand what eIDAS 2.0-compliant mobile IDs mean for their processes.

Organisations that already handle identity verification at scale, such as banks, insurers, or public service providers, will likely need to update their onboarding flows and back-end validation logic. Those starting from a lower baseline of digital identity maturity may need to invest more significantly in new infrastructure. Either way, the timeline for preparation is narrowing. By 24 December 2026, every EU Member State must have at least one certified EUDI Wallet available for citizens, residents, and businesses, and public sector bodies must accept notified wallets as a means of identification from that date. Regulated private sector organisations — including those in banking, financial services, healthcare, telecoms, energy, transport, education, social security, drinking water, postal services, digital infrastructure, digital services, and very large online platforms with more than 45 million users in the EU — must accept the EUDI Wallet by 24 December 2027, where strong user authentication is legally or contractually required under Article 5f of the regulation. Reviewing your implementation approach now is the practical next step.

How TrustTech helps with eIDAS 2.0 mobile ID compliance

Preparing for eIDAS 2.0 mobile ID requirements involves navigating technical standards, regulatory obligations, and integration challenges at the same time. TrustTech helps organisations cut through that complexity with a clear, structured path from assessment to implementation.

Working with TrustTech, organisations can expect:

  • Readiness assessment: A clear picture of where your current identity infrastructure stands relative to eIDAS 2.0 requirements for mobile ID documents
  • Relying party integration: Technical support to connect your systems to the EUDI Wallet ecosystem, including ISO 18013-5 and ARF-compliant verification flows
  • Selective disclosure implementation: Ensuring your data requests are scoped correctly so you only ask for what you need, keeping you compliant with both eIDAS 2.0 and GDPR
  • Sector-specific guidance: Tailored advice for regulated industries including finance, government, and healthcare, where identity assurance requirements are highest
  • End-to-end platform support: From first verification through to qualified digital signatures, TrustTech’s platform covers the full identity lifecycle in a single, eIDAS 2.0-ready environment

If your organisation is working through what eIDAS 2.0 mobile ID compliance means in practice, the right time to act is now. Get in touch with TrustTech to discuss your specific situation and find out how we can help you move forward with confidence.