The ARF (Architecture Reference Framework) is the central technical blueprint for the European Digital Identity Wallet ecosystem under eIDAS 2.0. It defines exactly how EUDI Wallets must be built, how they communicate with other systems, and what standards all parties in the ecosystem need to follow. In short, it is the shared rulebook that makes interoperability across all EU Member States possible.
For organisations preparing to issue credentials, accept wallet-based verification, or build wallet-compatible services, understanding the ARF is not optional. It shapes every technical and compliance decision involved in EUDI Wallet implementation. The sections below walk through the most important questions surrounding the ARF and what it means in practice.
What does the ARF actually define for EUDI Wallet implementations?
The ARF defines the technical architecture, data formats, protocols, and trust mechanisms that all EUDI Wallet implementations must follow. It sets out how wallets store and present credentials, how relying parties verify them, and how the entire ecosystem maintains security and interoperability across borders and sectors.
Think of the ARF as the technical constitution of the EUDI Wallet ecosystem. Without it, each Member State could build a wallet that works perfectly within its own borders but cannot communicate with systems in other countries. The ARF prevents that fragmentation by establishing a common foundation.
In practical terms, the ARF covers:
- The data models used to represent identity attributes and credentials
- The communication protocols between wallets, issuers, and relying parties
- The trust model, including how trust anchors and trust registries are structured
- Security requirements for wallet applications and backend systems
- Privacy-by-design principles, including selective disclosure and minimal data sharing
- The roles and responsibilities of each actor in the ecosystem
One of the most important concepts the ARF introduces is selective disclosure. Users can share only the specific attributes a service needs, for example, confirming they are over 18 without revealing their full date of birth. This is a fundamental shift from how traditional identity documents work and requires specific technical mechanisms that the ARF specifies in detail.
Who publishes and maintains the ARF?
The ARF is published and maintained by the European Commission, working closely with the eIDAS Expert Group. The document is developed collaboratively and made available as an open repository on GitHub, where Member States, technical experts, and other stakeholders can follow its development and contribute feedback.
This open development model is deliberate. The European Commission wanted the ARF to reflect real-world technical expertise from across the EU, not just a top-down specification. The large-scale pilot projects, which involve over 350 entities from 26 Member States plus Norway, Iceland, and Ukraine, actively feed insights back into the ARF as they test the wallet in real scenarios.
The eIDAS Expert Group plays a central coordinating role. This group brings together representatives from Member States, technical bodies, and industry to review proposals, resolve ambiguities, and ensure the ARF remains technically sound and practically implementable. Updates go through a structured review process before they become part of the authoritative version.
What are the core components of the ARF?
The ARF is structured around several core components that together describe the complete EUDI Wallet ecosystem. These components cover the wallet itself, the parties that interact with it, the credentials it handles, and the trust infrastructure that underpins everything.
The main components are:
- The EUDI Wallet instance — the application running on a user’s device that stores credentials and manages identity interactions
- Wallet providers — the organisations (typically Member States or certified providers) responsible for issuing and maintaining wallet applications
- Credential issuers — organisations that issue verifiable credentials into the wallet, such as government bodies issuing digital driving licences or employers issuing professional qualifications
- Relying parties — organisations that request and verify credentials from wallets to grant access to services
- Trust registries — authoritative lists that confirm which issuers and relying parties are certified to participate in the ecosystem
- The common toolbox — the shared set of technical specifications, protocols, and reference implementations that all parties build on
Each component has defined interfaces and responsibilities. The ARF specifies exactly how these components interact, which standards apply at each interface, and what security requirements each party must meet. This level of detail is what allows a wallet issued in Finland to work seamlessly with a service provider in Spain.
How does the ARF relate to other eIDAS 2.0 technical standards?
The ARF sits at the top of the eIDAS 2.0 technical standards hierarchy. It is the overarching framework that references and coordinates all the more specific standards beneath it. Individual technical specifications, such as those for credential formats, communication protocols, and cryptographic requirements, are defined separately but must align with what the ARF establishes.
For example, the ARF references standards like ISO/IEC 18013-5 for mobile driving licence formats and the W3C Verifiable Credentials Data Model for certain credential types. It also draws on OpenID for Verifiable Credential Issuance (OID4VCI) and OpenID for Verifiable Presentations (OID4VP) as the protocols for credential exchange. None of these standards are invented by the ARF, but the ARF defines how and where they apply within the EUDI Wallet ecosystem.
This relationship matters for organisations building wallet-compatible systems. Compliance with the ARF means compliance with a specific, curated set of underlying standards applied in a particular way. It is not enough to implement a standard correctly in isolation. The implementation must fit within the broader architecture the ARF defines. For organisations navigating these requirements, TrustTech’s digital identity solutions are designed to align with exactly this layered compliance structure.
Which organisations need to comply with the ARF?
Any organisation that participates in the EUDI Wallet ecosystem must comply with the ARF. This includes wallet providers, credential issuers, and relying parties. The scope is broad: financial institutions, healthcare providers, government agencies, educational bodies, and any private sector organisation that wants to accept or issue wallet-based credentials.
Under eIDAS 2.0, certain categories of relying parties will be legally required to accept EUDI Wallets. Large online platforms, banks performing customer identification, and services requiring strong authentication are among those with mandatory acceptance obligations. For these organisations, ARF compliance is not a choice but a regulatory requirement.
Organisations in regulated sectors face the most immediate pressure. A bank that wants to use an EUDI Wallet for customer onboarding needs to register as a relying party, meet the ARF’s security requirements, and integrate with the trust registry. A hospital that wants to issue digital health credentials needs to become a certified credential issuer under the same framework. For organisations in the financial services sector or healthcare sector, these obligations are already shaping technology roadmaps in 2026.
How does the ARF change as eIDAS 2.0 moves toward full implementation?
The ARF is a living document that evolves as eIDAS 2.0 moves from regulation to full deployment. New versions are released as technical decisions are finalised, pilot feedback is incorporated, and implementing acts from the European Commission add further detail. Organisations should treat the ARF as an ongoing reference rather than a fixed specification.
The large-scale pilot projects have been particularly important in driving ARF updates. When pilots uncovered gaps, ambiguities, or practical challenges in earlier versions, those findings fed directly into revisions. This iterative approach means the ARF has become progressively more concrete and implementation-ready over time.
Looking ahead, the ARF will continue to evolve as the Commission issues additional implementing acts and as the first wave of certified wallets enters the market. Organisations that have been tracking the ARF since earlier versions will find that the core architecture remains stable, but the level of detail around specific use cases, credential types, and security requirements continues to grow. Staying current with ARF releases is therefore an ongoing responsibility for any organisation building on the EUDI Wallet ecosystem. The TrustTech resource hub provides regular updates on these developments to help organisations keep pace.
How TrustTech helps you prepare for the ARF and EUDI Wallet requirements
Understanding the ARF is one thing. Translating it into a working implementation that meets regulatory requirements, integrates with existing systems, and delivers a smooth user experience is another challenge entirely. That is where TrustTech comes in.
TrustTech supports organisations across every stage of EUDI Wallet preparation and implementation, from initial assessment to production-ready deployment. Whether your organisation needs to become a compliant credential issuer, integrate wallet-based verification into an onboarding flow, or build the trust infrastructure to support cross-border identity exchange, TrustTech provides the expertise and technology to make it happen.
Specifically, TrustTech helps with:
- Mapping your current identity infrastructure against ARF requirements and identifying gaps
- Implementing verifiable credential issuance and verification in line with the ARF’s technical specifications
- Setting up trust registry integrations and relying party registration
- Enabling reusable, wallet-ready onboarding flows that reduce friction and drop-off
- Ensuring compliance with eIDAS 2.0 across regulated sectors including finance, government, and healthcare
TrustTech’s platform is built for EU compliance by design, with a track record of getting organisations to production in under five months. If your organisation is preparing for the EUDI Wallet and wants a clear path through the ARF requirements, get in touch with TrustTech to discuss your situation and next steps.