Businesses verify eIDAS 2.0 wallet credentials by acting as a relying party: they send a credential request to a user’s EUDI Wallet, receive a cryptographically signed response, and validate that response against a trusted issuer registry. The entire exchange happens in seconds, without the business needing to call anyone to confirm the data is genuine. The sections below unpack each part of that process in detail, from the technical standards involved to the legal obligations your organisation takes on.
What happens during the eIDAS 2.0 credential verification process?
During eIDAS 2.0 credential verification, a business sends a presentation request to the user’s EUDI Wallet, the wallet prompts the user to consent and select which credentials to share, and the wallet then returns a cryptographically signed response that the business can verify automatically. No manual document check, no phone call, and no third-party callback is needed.
Here is how the flow works in practice:
- The business sends a presentation request. Using a standardised protocol, the relying party specifies exactly which attributes it needs, for example proof of age, a professional qualification, or a verified address.
- The user reviews and consents. The wallet displays what is being requested. The user decides whether to share it. Nothing leaves the wallet without explicit consent.
- The wallet returns a verifiable presentation. The response is digitally signed by the credential issuer, which could be a government body, a bank, or another trusted institution, and it is bound to the specific transaction.
- The business validates the cryptographic proof. The relying party checks the issuer’s signature against a trusted registry, confirms the credential has not been revoked, and confirms it matches the request. If everything checks out, the verification is complete.
The key advantage here is that the business never stores raw identity documents. It receives only the attributes it asked for, verified by cryptographic proof, which dramatically reduces both fraud risk and data handling obligations.
What types of credentials can businesses request from a wallet?
Businesses can request any credential that has been issued into a user’s EUDI Wallet by a recognised issuer. The most common credential type is the Person Identification Data (PID) attestation, which covers core identity attributes such as name, date of birth, and nationality. Beyond PID, wallets can hold a wide range of electronic attestations of attributes (EAAs).
Practical examples of credentials businesses may request include:
- Age verification (for age-restricted services or products)
- Proof of address
- Professional qualifications or licences
- Mobile driving licences
- Health insurance or social security data
- Academic diplomas or certificates
- Employment status or employer attestations
- KYC-verified identity for financial onboarding
An important principle built into eIDAS 2.0 is selective disclosure. A business may only request the attributes it genuinely needs for a specific purpose. If you only need to confirm someone is over 18, you request an age attestation, not the user’s full date of birth. This protects user privacy and keeps your data footprint small, which also simplifies GDPR compliance.
For organisations in regulated sectors such as financial services, the ability to receive a pre-verified KYC credential from a trusted issuer is particularly powerful. It means a customer who has already completed identity verification at their bank can reuse that credential with your organisation, without starting from scratch. Financial sector organisations stand to gain significantly from this reusable compliance model.
How does a business become a trusted relying party under eIDAS 2.0?
To become a trusted relying party under eIDAS 2.0, a business must register with a recognised trust framework in its Member State and meet the requirements set out in the regulation and its implementing acts. Registration gives the business the right to request credentials from EUDI Wallets and ensures users can see that the requesting organisation is legitimate before sharing any data.
The registration process generally involves:
- Identifying the relevant national authority. Each Member State designates a body responsible for managing relying party registrations within its jurisdiction.
- Submitting an application. The business declares which credential types it intends to request and for what purposes.
- Receiving a relying party certificate. This certificate is embedded in presentation requests so that wallets and users can verify the requester’s identity before any data is shared.
- Maintaining ongoing compliance. Relying parties must continue to meet the requirements of the regulation, including data minimisation, purpose limitation, and security obligations.
From a user experience perspective, registration matters because EUDI Wallets are designed to show users the verified identity of the requesting party before they consent to share anything. An unregistered or unrecognised requester will trigger a warning in the wallet, which is likely to result in the user refusing the request. Becoming a registered relying party is therefore not just a legal requirement; it is a trust signal that directly affects whether users are willing to engage with your service.
What technical standards does eIDAS 2.0 wallet verification rely on?
eIDAS 2.0 wallet credential verification relies on a set of open, interoperable technical standards defined in the Architecture and Reference Framework (ARF) developed by the European Commission and Member States. The two primary credential formats are ISO/IEC 18013-5 (used for mdoc credentials, such as mobile driving licences) and SD-JWT VC (Selective Disclosure JSON Web Tokens for Verifiable Credentials). Both formats support selective disclosure and cryptographic binding.
For the communication protocols used between wallets and relying parties, the framework draws on:
- OpenID for Verifiable Presentations (OID4VP) for online credential presentation flows
- OpenID for Verifiable Credential Issuance (OID4VCI) for issuing credentials into wallets
- ISO/IEC 18013-5 proximity protocols for in-person, offline verification scenarios
Trust registries play a central role in the technical architecture. When a business receives a credential, it needs to verify that the issuer is recognised and that the credential has not been revoked. This is done by checking against a trusted issuer list, which is maintained at national or EU level. The cryptographic signatures on credentials point back to these registries, enabling automated, real-time validation without any human in the loop.
For organisations building or integrating verification infrastructure, understanding these standards is essential. The good news is that compliant wallet SDKs and verification libraries handle much of this complexity, meaning your development team does not need to implement the cryptographic primitives from scratch. What matters most is choosing a platform that is built on these standards from the ground up. You can explore how TrustTech approaches this in its identity solutions.
What are the legal obligations for businesses that verify wallet credentials?
Businesses that verify EUDI Wallet credentials take on a defined set of legal obligations under eIDAS 2.0 and related EU legislation. As a relying party, you are responsible for processing only the data you are authorised to request, using it only for the declared purpose, and protecting it in line with GDPR and applicable sector regulations.
The core legal obligations include:
- Data minimisation: You may only request the attributes strictly necessary for your stated purpose. Requesting more than you need is a breach of both eIDAS 2.0 and GDPR.
- Purpose limitation: Data received through a wallet presentation may only be used for the specific purpose declared at the time of the request.
- Security obligations: You must implement appropriate technical and organisational measures to protect the verified data you receive.
- Transparency to users: Users must be clearly informed about what data you are requesting and why, before they consent.
- Record keeping: Depending on your sector, you may be required to maintain audit trails of verification transactions for compliance and accountability purposes.
- Sector-specific requirements: In regulated sectors such as finance, healthcare, telecoms, energy, and transport, additional obligations from AML, KYC, or sector-specific data regulations may apply on top of the eIDAS 2.0 baseline.
One practical implication worth highlighting: because wallet credentials are cryptographically verified and timestamped, they can serve as strong evidence in an audit. A well-implemented verification flow does not just satisfy a legal requirement; it generates a tamper-proof compliance record that protects your organisation if questions arise later. Organisations in healthcare and government, for instance, will find this audit trail capability particularly valuable. Learn more about how digital identity applies in healthcare contexts and government services.
How TrustTech helps with eIDAS 2.0 credential verification
Implementing wallet credential verification is not just a technical project. It touches compliance, legal, architecture, and user experience at the same time. TrustTech brings together the expertise and infrastructure to help your organisation get this right, whether you are just starting to understand your obligations or ready to build a production-ready verification flow.
Specifically, TrustTech supports organisations with:
- Becoming a registered relying party and navigating national trust framework requirements
- Integrating standards-based credential verification into existing onboarding and compliance workflows
- Enabling reusable identity so customers verify once and reuse across your services
- Building audit-ready evidence trails that satisfy both eIDAS 2.0 and sector-specific regulations such as AML and KYC
- Connecting identity verification, qualification checks, and qualified digital signatures in a single, coherent platform
The result is faster onboarding, fewer compliance gaps, and a digital identity infrastructure that is ready for the regulatory landscape taking shape across Europe. Each EU Member State is required to make at least one certified EUDI Wallet available by 24 December 2026, and public bodies must begin accepting notified wallets as a means of identification from that date. For regulated private-sector organisations — including those in banking, healthcare, telecoms, energy, transport, education, social security, drinking water, postal services, digital infrastructure, digital services, and very large online platforms with more than 45 million users in the EU — a mandatory acceptance obligation applies from 24 December 2027, where strong user authentication is legally or contractually required under Article 5f of the regulation. The 2026 deadline is therefore the point at which wallets become available and private organisations can begin testing acceptance ahead of their own deadline. If your organisation is preparing for eIDAS 2.0 and wants practical guidance on the next steps, get in touch with TrustTech to discuss your situation.