eIDAS 1.0 and eIDAS 2.0 are both EU regulations for digital identity, but they differ significantly in scope, ambition, and who they apply to. The original regulation, in force since 2016, focused mainly on cross-border recognition of national eID schemes for public services. eIDAS 2.0, which updated the framework in 2024, goes much further by introducing the European Digital Identity Wallet, extending rules to the private sector, and creating a unified standard that every Member State must meet. This article walks through the key differences and what they mean for your organisation.
What changed when eIDAS 2.0 replaced eIDAS 1.0?
eIDAS 1.0 created a legal framework for recognising national electronic identity schemes across EU borders, but it left Member States largely free to decide whether and how to participate. eIDAS 2.0 replaces that optional approach with binding obligations, a new wallet infrastructure, and a much broader scope that includes private sector services for the first time.
Under eIDAS 1.0, the rules were straightforward but limited. Member States could notify their national eID schemes to the European Commission, and once notified, other Member States were required to accept them for access to public services. In practice, however, many countries did not notify their schemes, and those that did often had systems that worked quite differently from one another. The result was a patchwork of digital identity solutions with limited real-world cross-border use.
eIDAS 2.0 addresses this directly. Every Member State is now required to issue a European Digital Identity Wallet to citizens, residents, and businesses. The regulation also sets common technical standards, governance rules, and trust frameworks that apply across the entire EU. Rather than simply recognising existing national systems, eIDAS 2.0 builds a shared infrastructure from the ground up.
What does eIDAS 2.0 include that eIDAS 1.0 did not?
eIDAS 2.0 introduces several entirely new concepts that were absent from the original regulation. The most significant additions are the European Digital Identity Wallet, the framework for verifiable credentials known as Electronic Attestations of Attributes (EAAs), and mandatory acceptance obligations for large online platforms and regulated services.
Here are the key additions eIDAS 2.0 brings to the table:
- European Digital Identity Wallet (EUDI Wallet): A government-backed digital wallet that allows users to store identity data, credentials, and documents in one secure app and share them with public and private services.
- Electronic Attestations of Attributes (EAAs): Verifiable credentials that can confirm specific attributes about a person, such as a professional qualification, a diploma, or a driving licence, without sharing unnecessary personal data.
- Qualified Electronic Attestations of Attributes (QEAAs): A higher-assurance version of EAAs issued by qualified trust service providers, carrying the same legal weight across all Member States.
- Mandatory relying party obligations: Large online platforms and service providers in regulated sectors are required to accept the EUDI Wallet as a means of identification.
- Selective disclosure: Users can share only the specific attributes needed for a transaction, rather than presenting a full identity document, which significantly improves privacy protection.
- Expanded trust services: New categories of qualified trust services, including electronic ledgers and electronic archiving services, are introduced under eIDAS 2.0.
Together, these additions transform eIDAS from a narrow cross-border recognition framework into a comprehensive digital identity ecosystem for the entire EU.
How does the EUDI Wallet differ from eIDAS 1.0 identity schemes?
The EUDI Wallet is fundamentally different from the national eID schemes under eIDAS 1.0. Where eIDAS 1.0 schemes were country-specific systems that other Member States had to recognise, the EUDI Wallet is a single, standardised solution that works across the EU by design, is user-controlled, and can be used with both public and private services.
Under eIDAS 1.0, a national eID such as a government-issued digital identity card or mobile ID app was built around that country’s own infrastructure. If it was notified under eIDAS 1.0, it could be used to access public services in other Member States, but the user experience, the technical standards, and the data it could carry varied considerably. Private sector use was largely outside the scope of the regulation entirely.
The EUDI Wallet takes a completely different approach. Rather than recognising different national systems, it establishes one common wallet format that every Member State must provide. The wallet can hold a wide range of credentials, from a government-issued personal identification data (PID) set to professional qualifications, health documents, and payment credentials. Users decide exactly what they share and with whom, and that selective disclosure is built into the technical architecture itself.
Another important distinction is reusability. With eIDAS 1.0, a user verified their identity once with a national scheme, but that verification rarely carried over to private sector interactions. With the EUDI Wallet, a verified identity can be reused across many services and organisations without the user having to start from scratch each time. This is a significant shift in how digital identity works in practice, and it has real implications for onboarding, compliance, and user experience across industries. Organisations working in financial services or healthcare will feel this shift most directly.
Which organisations are affected by eIDAS 2.0 that were not under eIDAS 1.0?
eIDAS 2.0 significantly expands the range of organisations that have obligations under the regulation. While eIDAS 1.0 primarily affected public sector bodies and a small number of trust service providers, eIDAS 2.0 brings private sector organisations, large online platforms, and regulated service providers firmly within scope.
The most notable new category is relying parties: organisations that accept the EUDI Wallet as a means of identification. Under eIDAS 2.0, certain types of service providers are legally required to accept the wallet. This includes:
- Very large online platforms designated under the Digital Services Act, which must offer EUDI Wallet-based login as an alternative to existing authentication methods.
- Financial institutions such as banks and payment service providers, particularly those performing identity verification for account opening or strong customer authentication under PSD2.
- Healthcare providers and pharmacies accessing or sharing health data across borders through the European Health Data Space.
- Telecommunications providers registering SIM cards, where identity verification is required by law.
- Public administrations offering digital public services, which must accept the wallet for authentication at the appropriate assurance level.
Beyond these mandatory relying parties, any organisation that handles identity verification, issues credentials, or provides trust services will need to assess how eIDAS 2.0 affects their processes. This includes businesses in government services, education, insurance, and any sector where verifying who someone is forms part of the customer or compliance journey.
When do organisations need to comply with eIDAS 2.0?
eIDAS 2.0 entered into force in May 2024, but the compliance timeline is phased. Member States are required to make the EUDI Wallet available to citizens and businesses by 2026, which means organisations that are required to accept the wallet need to have their systems ready by that same deadline.
In 2026, the EUDI Wallet moves from the pilot phase to live deployment. The large-scale pilot programmes that ran across more than 350 organisations and 26 Member States have already tested real-world scenarios including bank account opening, SIM registration, access to government services, and digital travel credentials. The lessons from those pilots are shaping the final technical specifications that organisations will need to implement.
For most organisations, the practical question is not just when the deadline falls, but how much preparation is required to meet it. Integrating the EUDI Wallet into existing onboarding flows, updating compliance frameworks to reflect new trust service categories, and ensuring systems can handle verifiable credentials all take time. Organisations that have not yet started should treat 2026 as an active target, not a distant horizon.
It is also worth noting that eIDAS 2.0 compliance is not a single moment but an ongoing process. The implementing regulations that define the technical details, covering everything from wallet certification to cross-border identity matching and qualified trust service standards, are still being finalised and published. Staying current with those developments is part of what compliance looks like in practice. Exploring the available resources on eIDAS 2.0 can help your team stay informed as the regulatory picture continues to develop.
How TrustTech helps with eIDAS 1.0 vs eIDAS 2.0
Understanding the differences between eIDAS 1.0 and eIDAS 2.0 is one thing. Translating them into concrete actions for your organisation is another. TrustTech is built specifically to help organisations navigate this transition, whether you are just beginning to assess your exposure or already working toward EUDI Wallet integration.
TrustTech supports organisations across the full eIDAS 2.0 journey:
- Identity verification and onboarding: Implement wallet-ready identity flows that reduce drop-off and meet eIDAS 2.0 assurance requirements.
- Reusable compliance: Replace repeated KYC, AML, and onboarding checks with verifiable, cryptographically trusted credentials that carry over across services.
- Qualified digital signatures: Issue and verify signatures that are legally binding across the EU, with full audit trails and identity linked to every action.
- Sector-specific guidance: Deep expertise in finance, government, healthcare, and other regulated sectors where eIDAS 2.0 obligations are most immediate.
- End-to-end platform: One platform connecting identification, qualification, and signing, built for EU compliance from the ground up.
If your organisation is ready to move from understanding eIDAS 2.0 to acting on it, TrustTech can help you get there. Get in touch with our team to discuss your situation and find out what practical next steps look like for you.