The main goals of eIDAS 2.0 are to create a universal, secure, and interoperable digital identity system across the European Union. While the original eIDAS regulation focused primarily on electronic signatures and public sector identity, eIDAS 2.0 extends that vision to cover every EU citizen, resident, and business, with a strong emphasis on privacy, cross-border usability, and a single digital wallet that works across both public and private services. The sections below unpack each of those goals in plain terms.
What does eIDAS 2.0 actually change compared to the original eIDAS?
eIDAS 2.0 fundamentally expands the scope, reach, and obligations of the original regulation. The original eIDAS, in force since 2016, allowed EU member states to notify and recognise each other’s national electronic ID systems, but it did not require every country to build one, and it left the private sector largely outside its scope. eIDAS 2.0 closes those gaps by making participation mandatory and extending the framework to private organisations.
The most significant structural change is the introduction of the European Digital Identity Wallet, which every member state is legally required to offer to citizens, residents, and businesses by 2026. The original regulation had no equivalent. Beyond the wallet, eIDAS 2.0 also tightens rules around trust services, introduces new categories such as electronic attestations of attributes, and brings private sector relying parties into the regulatory framework for the first time.
In short, eIDAS has moved from being a framework for cross-border recognition to becoming the foundation for a fully interoperable EU-wide digital identity ecosystem.
What is the European Digital Identity Wallet and why is it central to eIDAS 2.0?
The European Digital Identity Wallet (EUDI Wallet) is a secure digital application that allows EU citizens, residents, and businesses to store, manage, and share their identity data and personal documents. It is the primary delivery mechanism for the goals of eIDAS 2.0, which is why it sits at the heart of the regulation.
The wallet can hold a wide range of documents and credentials, including national identity information, mobile driving licences, educational qualifications, health insurance cards, and professional certifications. With a single interaction, users can share only the specific information a service needs, such as confirming their age without revealing their date of birth, or proving nationality without disclosing their full address.
From a regulatory standpoint, the wallet matters because it is the instrument through which eIDAS 2.0 delivers on its core promises: universal access, cross-border functionality, and user control. Member states cannot simply point to an existing national eID and call it done. They must provide a wallet that meets the technical and legal standards set out in the regulation, ensuring consistency across the EU.
Large-scale pilot projects launched in April 2023 have been testing the wallet across 26 member states, Norway, Iceland, and Ukraine, involving more than 350 public and private entities. These pilots cover eleven real-world scenarios, from opening a bank account and signing contracts to claiming prescriptions and accessing social security benefits. The insights gathered are directly shaping the final design, security architecture, and interoperability standards of the wallet.
How does eIDAS 2.0 aim to give citizens more control over their personal data?
eIDAS 2.0 places data sovereignty at the centre of the digital identity framework. Citizens will decide what information they share, with whom, and for how long. The regulation explicitly prohibits unnecessary data sharing: if a service only needs to verify that a user is over 18, the wallet shares that confirmation and nothing else.
This approach addresses a genuine problem with how digital identity has worked until now. Most online services require users to create accounts with full personal details, or to authenticate through large platform providers that collect and retain data for their own purposes. eIDAS 2.0 removes that dependency. Users will be able to access public and private services online without relying on commercial identity platforms and without handing over more personal data than a transaction genuinely requires.
The regulation also requires that users can track which data they have shared and with which organisations. This audit trail gives people visibility and control that is simply not possible with physical documents or fragmented digital credentials. Privacy is not treated as an optional feature but as a design requirement built into the wallet architecture from the ground up.
Which sectors and use cases must accept the EUDI Wallet under eIDAS 2.0?
Under eIDAS 2.0, certain categories of private and public sector organisations are required to accept the EUDI Wallet as a valid means of identification. This obligation applies to sectors where identity verification is already a regulatory or operational necessity, including banking, telecommunications, and transport.
The large-scale pilots have been testing the wallet across eleven concrete use cases that reflect the services Europeans use most regularly:
- Accessing government services such as applying for a passport, filing taxes, or retrieving social security information
- Opening a bank account remotely without repeated document submissions
- SIM card registration to reduce fraud for mobile network operators
- Presenting a mobile driving licence in both online and physical settings
- Signing contracts digitally with qualified electronic signatures
- Claiming prescriptions at pharmacies across borders
- Travelling by presenting passport or visa information at airport security
- Proving you are an authorised representative of an organisation
- Verifying identity when initiating an online payment
- Presenting educational credentials such as diplomas or degrees
- Accessing social security benefits and storing documents like the European Health Insurance Card
For organisations in financial services, government, and healthcare, the wallet acceptance obligation is particularly relevant. These sectors already operate under strict identity verification requirements, and the EUDI Wallet is designed to integrate with and simplify those existing processes rather than replace them entirely.
How does eIDAS 2.0 support cross-border digital identity across EU member states?
eIDAS 2.0 makes cross-border digital identity interoperability a legal requirement rather than a voluntary aspiration. Every wallet issued in one member state must be recognised and accepted by services in all other member states. This creates a single, consistent identity layer across the EU for the first time.
The original eIDAS regulation allowed member states to notify their national eID schemes for mutual recognition, but there was no obligation to do so. This led to significant fragmentation, with some countries having mature digital identity infrastructure and others having very little. eIDAS 2.0 resolves this by requiring every member state to provide a wallet that conforms to a shared Architecture and Reference Framework, developed collaboratively by the European Commission and member states through the European Digital Identity Cooperation Group.
The practical result is that a citizen in the Netherlands can use their EUDI Wallet to access a public service in Spain, open a bank account in Germany, or present their qualifications to an employer in France, all without needing to repeat identity verification steps or navigate incompatible national systems. Cross-border interoperability is not a feature of the wallet; it is the foundational purpose the entire technical architecture is built around.
What do organizations need to do to prepare for eIDAS 2.0 compliance?
Organizations that fall within the scope of eIDAS 2.0 need to assess their current identity infrastructure, understand their obligations as relying parties, and begin integrating wallet-compatible verification flows into their systems. The regulation is already in force, and the obligation for member states to provide wallets applies from 2026, meaning the preparation window for businesses is now.
Key preparation steps include:
- Mapping your compliance obligations: Determine whether your organisation falls into a category required to accept the EUDI Wallet and which use cases apply to your sector
- Reviewing your identity verification processes: Identify where current onboarding, authentication, or document verification flows will need to be updated to accept wallet-based credentials
- Assessing your trust service integrations: Check whether your use of electronic signatures, seals, or timestamps aligns with the updated trust service requirements under eIDAS 2.0
- Following the Architecture and Reference Framework: Stay current with the technical specifications being developed and tested through the large-scale pilots, as these will define what wallet-compatible systems must support
- Engaging with pilot outcomes: The pilot projects running across Europe are producing concrete guidance on interoperability, security, and user experience that organisations can use to inform their own implementation planning
Organizations in regulated sectors such as finance, healthcare, and government face additional complexity because eIDAS 2.0 intersects with existing frameworks like GDPR, AML, KYC, and sector-specific regulations. Preparing for eIDAS 2.0 is therefore not only a technical project but also a compliance and governance challenge that benefits from a structured approach.
How TrustTech helps with eIDAS 2.0 readiness
Understanding the goals of eIDAS 2.0 is one thing. Translating them into a working, compliant digital identity infrastructure is another. That is where TrustTech comes in.
TrustTech helps organisations across regulated sectors prepare for and implement eIDAS 2.0 in a way that is practical, scalable, and built for the long term. Specifically, TrustTech supports your organisation with:
- EUDI Wallet integration: Connecting your onboarding and verification flows to wallet-based identity credentials so you are ready when the obligation kicks in
- Reusable compliance infrastructure: Replacing repeated identity checks with a single, cryptographically verified identity that travels with your customer across every interaction
- Qualified digital signatures: Ensuring your signing processes meet the updated eIDAS 2.0 trust service requirements, with a full audit trail linked to verified identity
- Cross-border interoperability: Building identity flows that work across EU member states, not just within your home market
- Sector-specific guidance: Applying deep expertise in finance, government, healthcare, and other regulated industries to help you navigate where eIDAS 2.0 intersects with your existing compliance obligations
Whether you are just beginning to understand what eIDAS 2.0 means for your organisation or are ready to start building, TrustTech provides the expertise and platform to move forward with confidence. Explore our identity solutions or get in touch with our team to discuss your specific situation.