What is a wallet unit attestation in eIDAS 2.0?

Smartphone displaying a glowing security seal resting on marble beside an EU passport, navy and platinum tones with amber accent light.

A wallet unit attestation (WUA) is a cryptographically signed certificate that proves a specific instance of an EU Digital Identity Wallet is genuine, secure, and has not been tampered with. It is issued to each individual wallet installation, not to the user, and it forms the technical foundation for trust in every eIDAS 2.0 transaction. The sections below unpack the most common questions about how wallet unit attestations work in practice.

How does a wallet unit attestation prove a wallet is trustworthy?

A wallet unit attestation proves trustworthiness by providing a cryptographically verifiable statement that a specific wallet instance was created by a certified wallet provider, runs on a secure device, and meets the security requirements defined under eIDAS 2.0. Without this attestation, a relying party has no way to confirm it is interacting with a legitimate wallet rather than a fraudulent imitation.

Think of it as a digital quality seal attached to your wallet installation. When you present credentials from your EUDI Wallet to a service provider, that provider does not just check your identity data. It also checks whether the wallet itself can be trusted. The wallet unit attestation makes this possible by binding the wallet instance to a certified wallet solution and confirming that the underlying hardware and software environment meets defined security standards.

This mechanism protects both users and service providers. For users, it means their wallet cannot be spoofed by malicious software pretending to be a legitimate EUDI Wallet. For service providers, it means they can accept credentials with confidence, knowing the wallet environment has been independently certified.

Who issues wallet unit attestations in eIDAS 2.0?

Wallet unit attestations in eIDAS 2.0 are issued by Wallet Provider Attestation Services, operated by the certified providers who develop and maintain the EUDI Wallet solutions. These providers are typically Member State authorities or private entities officially recognised by a Member State. The issuing service runs as part of the wallet infrastructure and issues a fresh attestation to each wallet instance during installation and at regular intervals thereafter.

The wallet provider is responsible for ensuring that only wallet instances that genuinely meet the required security and conformance criteria receive an attestation. This means the provider must evaluate the device environment, confirm the integrity of the wallet application, and sign the attestation using a key that is itself listed in a trusted registry maintained under the eIDAS trust framework.

This chain of trust is essential. A relying party can verify a wallet unit attestation only because it can trace the issuing provider’s signing key back to a recognised and audited source within the European trust infrastructure.

What information does a wallet unit attestation contain?

A wallet unit attestation contains technical metadata about the wallet instance itself, not about the user. At its core, it includes a public key unique to that wallet instance, the identity of the wallet provider, a validity period, and claims about the security level of the wallet environment. It does not contain any personal data.

More specifically, the attestation typically includes:

  • A cryptographic public key bound to that specific wallet installation
  • The identifier and certification status of the wallet provider
  • The wallet solution name and version
  • The assurance level of the device and software environment
  • An issuance timestamp and expiry date
  • A digital signature from the wallet provider’s attestation service

This structure means the attestation can confirm the technical trustworthiness of a wallet instance without revealing anything about the person using it. Privacy is preserved by design, which aligns with the broader data minimisation principles that underpin eIDAS 2.0 and the EUDI Wallet framework.

What is the difference between a wallet unit attestation and a PID?

A wallet unit attestation and a Person Identification Data (PID) credential serve completely different purposes. A wallet unit attestation describes the wallet itself, confirming it is a certified and trustworthy environment. A PID describes the user, containing verified identity attributes such as name, date of birth, and nationality. One is about the container; the other is about the contents.

The PID is issued by a Member State’s identity authority and stored inside the wallet. It is the credential you present when a service needs to verify who you are. The wallet unit attestation, by contrast, is issued by the wallet provider and travels alongside credential presentations to confirm that the wallet presenting the PID is itself trustworthy.

In practice, a relying party will often check both. They want to know that the identity data they are receiving comes from a legitimate person and that it was presented from a secure, certified wallet. The two components work together but serve distinct roles in the overall trust model. For organisations in financial services or other regulated sectors, understanding this distinction matters when designing verification workflows that need to satisfy both identity assurance and technical trust requirements.

When is a wallet unit attestation verified during an eIDAS 2.0 transaction?

A wallet unit attestation is verified at the moment a relying party receives a credential presentation from an EUDI Wallet. This happens automatically and in real time as part of the presentation protocol. The relying party’s system checks the attestation before accepting any identity data, ensuring the wallet environment meets the required trust level before the transaction proceeds.

The verification process follows these steps:

  1. The user initiates a credential presentation from their EUDI Wallet
  2. The wallet sends the requested credential alongside its wallet unit attestation
  3. The relying party’s system retrieves the wallet provider’s public key from the trusted registry
  4. The signature on the wallet unit attestation is verified against that public key
  5. The system confirms the attestation is still within its validity period and has not been revoked
  6. If all checks pass, the credential data is accepted and the transaction continues

This process is designed to be seamless and invisible to the end user. From a user perspective, the interaction feels no different from presenting a digital document. Behind the scenes, however, a full chain of trust is being verified in seconds.

Can a wallet unit attestation be revoked, and what happens then?

Yes, a wallet unit attestation can be revoked by the wallet provider. Revocation typically occurs when a wallet instance is compromised, when the device it runs on is reported lost or stolen, when a security vulnerability is discovered in the wallet software, or when the user uninstalls the wallet. Once revoked, the attestation is listed in a revocation registry that relying parties can query in real time.

When a relying party checks a wallet unit attestation and finds it has been revoked, the transaction is rejected. The service will not accept credentials from that wallet instance, even if the credentials themselves are valid. This is an important safeguard: it ensures that a stolen device or a compromised wallet cannot continue to be used for identity transactions, even if the attacker still holds valid credentials stored in the wallet.

From a user perspective, revocation of a wallet unit attestation does not mean the loss of credentials permanently. A user can reinstall or re-activate the wallet on a new or restored device, at which point the wallet provider issues a fresh wallet unit attestation for the new instance. The underlying identity credentials, such as the PID, can then be re-issued or re-bound to the new wallet instance through the standard issuance process.

This revocation capability is one of the reasons the EUDI Wallet framework provides a higher level of assurance than many existing digital identity solutions. Organisations exploring how to implement compliant identity solutions will find that support for wallet attestation verification and revocation checking is a core requirement for any eIDAS 2.0-ready integration.

How TrustTech helps with wallet unit attestations

Wallet unit attestations sit at the heart of the eIDAS 2.0 trust model, and getting the implementation right requires both regulatory understanding and technical depth. For many organisations, navigating the architecture of wallet providers, attestation services, trusted registries, and revocation infrastructure is genuinely complex, especially when it needs to connect with existing onboarding, compliance, and signing workflows.

TrustTech helps organisations at every stage of this journey. Whether you are a government body preparing to issue or accept EUDI Wallet credentials, a financial institution building eIDAS 2.0-compliant onboarding, or a healthcare or public sector organisation integrating wallet-based identity into digital services, TrustTech brings the expertise to make it work in practice.

Specifically, TrustTech supports organisations with:

  • Understanding how wallet unit attestations fit into your verification and trust architecture
  • Implementing relying party infrastructure that correctly verifies and validates wallet attestations
  • Connecting wallet-based identity to reusable KYC, qualified signatures, and compliance workflows
  • Preparing for eIDAS 2.0 requirements across onboarding, authentication, and data exchange
  • Navigating sector-specific requirements in finance, government, healthcare, and beyond

TrustTech’s platform is built on European digital identity standards and is eIDAS 2.0-ready by design, so you are not retrofitting compliance onto an existing system. You are building on infrastructure designed for the trust requirements of today and tomorrow. Ready to take the next step? Get in touch with TrustTech to discuss how your organisation can prepare for the EUDI Wallet and wallet unit attestation requirements.