Who is required to accept the EUDI Wallet in 2026?

European passport and bank card on a government office desk beside a smartphone displaying a digital wallet interface.

Under eIDAS 2.0, certain categories of organisations are legally required to accept the European Digital Identity Wallet. Public sector bodies must comply by 24 December 2026, while regulated private sector service providers have until 24 December 2027. This article breaks down exactly who must accept the EUDI Wallet, what that acceptance means in practice, and how organisations can start preparing today.

Which sectors are legally required to accept the EUDI Wallet?

Public sector bodies across all EU Member States are required to accept the EUDI Wallet for digital services that already require identity verification, with that obligation applying from 24 December 2026. Beyond government services, eIDAS 2.0 extends mandatory acceptance to specific private sector categories from 24 December 2027, including banking and financial services, telecoms, transport, energy, healthcare, education, social security, drinking water, postal services, digital infrastructure and digital services, and very large online platforms with more than 45 million users in the EU.

The logic behind this scope is straightforward: the regulation targets sectors where identity verification is already a standard part of the service. If a bank must verify a customer’s identity to open an account, or a healthcare provider must confirm a patient’s identity before sharing medical records, those same interactions must be able to accept the EUDI Wallet as a valid identity instrument once the relevant deadline applies.

More specifically, the sectors covered under the mandatory acceptance rules include:

  • Government and public administration — any public service that currently requires identification online (deadline: 24 December 2026)
  • Banking and financial services — for customer onboarding, account access, and regulated transactions
  • Telecommunications — for SIM registration and identity-verified services
  • Healthcare — for patient identification and access to health records
  • Transport — for ticketing, licensing, and identity-dependent services
  • Energy utilities — for customer account services that require verified identity
  • Education — for identity-verified access to educational services
  • Social security — for benefit access and identity-dependent administrative services
  • Drinking water — for customer account services requiring verified identity
  • Postal services — for identity-verified service interactions
  • Digital infrastructure and digital services — where strong user authentication is legally or contractually required
  • Very large online platforms — those with more than 45 million users in the EU, as defined under the Digital Services Act

For private sector organisations in the sectors listed above, the mandatory acceptance deadline is 24 December 2027, which is twelve months after the wallet issuance and public sector acceptance deadline. Organisations operating in financial services and government are among those with the most immediate obligations, given that identity verification is already deeply embedded in their operations.

What does ‘required to accept’ actually mean under eIDAS 2.0?

Being required to accept the EUDI Wallet means that an organisation must technically support the wallet as a valid means of identity verification when a user presents it. In practice, this means building or integrating the technical infrastructure to receive, validate, and process identity attributes and credentials presented through an EUDI Wallet.

Acceptance does not mean the wallet becomes the only accepted method. Organisations are not required to abandon existing login or verification methods. What the regulation requires is that the EUDI Wallet is a supported and recognised option alongside whatever else the organisation currently uses.

In technical terms, this involves connecting to the EUDI Wallet ecosystem as a relying party. A relying party is any service provider that requests and receives identity data from a wallet holder. To become a relying party, organisations must register with the relevant national authority, implement the required protocols and interfaces, and ensure their systems can verify the cryptographic integrity of the credentials they receive.

This is not a trivial integration. It requires alignment with the Architecture and Reference Framework (ARF) developed under eIDAS 2.0, which defines the technical standards for how wallets and relying parties communicate. The obligation for regulated private sector organisations applies from 24 December 2027, but the technical integration timeline is not short, and preparation should begin well in advance.

Are private companies also required to accept the EUDI Wallet?

Yes, certain private companies are required to accept the EUDI Wallet, but not all of them. The obligation applies to private sector organisations in the sectors listed under eIDAS 2.0 that provide services requiring strong identity authentication, particularly where the service falls under regulated activities or reaches a significant scale. The mandatory acceptance deadline for these private sector parties is 24 December 2027, as set out in Article 5f of the regulation.

The regulation specifically targets very large online platforms with more than 45 million users in the EU, and private service providers in regulated sectors. For example, a large bank offering digital account opening is required to accept the wallet. A small independent web shop is not.

The distinction matters because many organisations are unsure whether they fall within scope. A useful way to assess this is to ask two questions:

  1. Does your service require users to verify their identity as part of accessing or using it, in a context where strong authentication is legally or contractually required?
  2. Is your organisation operating in one of the regulated sectors covered by eIDAS 2.0, or classified as a very large online platform under the Digital Services Act?

If the answer to both is yes, mandatory acceptance almost certainly applies. If you are uncertain, this is exactly the kind of question a structured compliance assessment can help resolve.

Private healthcare providers, insurers, and pharmaceutical companies with digital patient or customer-facing services should also pay close attention. The healthcare sector is explicitly within scope, and the line between optional and mandatory acceptance can be narrow depending on the nature of the service.

What happens if an organisation doesn’t comply by the applicable deadline?

Organisations that fall within the mandatory acceptance scope and fail to comply by the applicable deadline risk enforcement action from national supervisory authorities. eIDAS 2.0 empowers Member States to impose penalties on non-compliant relying parties, and the severity of those penalties will depend on national implementation choices.

Beyond formal penalties, non-compliance carries real operational and reputational risks. As EUDI Wallet adoption grows among citizens and businesses, organisations that cannot accept wallet-based credentials will face friction in their customer journeys. Users who expect to verify their identity using their national digital wallet will encounter a dead end, which damages trust and can drive them to competitors who have completed the integration.

There is also a procurement and partnership dimension. Public sector contracts and cross-border business relationships increasingly require demonstrated compliance with EU digital identity standards. Organisations that lag behind may find themselves excluded from tender processes or unable to meet the identity assurance requirements of their partners.

The practical advice is not to wait for enforcement. The technical integration timeline for becoming a compliant relying party is not short. Public sector bodies face a deadline of 24 December 2026, and regulated private sector organisations must comply by 24 December 2027. Organisations that have not started should prioritise a readiness assessment now.

How should organisations start preparing for EUDI Wallet acceptance?

Preparing for EUDI Wallet acceptance starts with understanding whether your organisation falls within scope, followed by a structured technical and compliance assessment of what changes are needed. The earlier this process begins, the more manageable the implementation becomes.

A practical starting path looks like this:

  1. Determine your scope: Identify which of your services require identity verification and whether they fall under the regulated sectors covered by eIDAS 2.0, and which deadline applies to your organisation.
  2. Map your current identity infrastructure: Understand how you currently verify user identity and where EUDI Wallet acceptance needs to be integrated.
  3. Register as a relying party: Engage with your national authority to understand the registration requirements and begin that process.
  4. Implement the required technical standards: Align your systems with the protocols and interfaces defined in the Architecture and Reference Framework.
  5. Test and validate: Use available reference implementations and pilot environments to validate your integration before go-live. The period following 24 December 2026 — when wallets become available to citizens — provides an important window for private sector organisations to test acceptance ahead of their own 2027 deadline.

Organisations should also monitor the implementing regulations being published under eIDAS 2.0, as these define the detailed technical and procedural requirements for relying parties. Staying current with these developments is essential for getting the integration right the first time.

You can find additional guidance and practical resources on the TrustTech resources page to support your preparation process.

How TrustTech helps with EUDI Wallet acceptance

TrustTech supports organisations across regulated sectors in preparing for and implementing EUDI Wallet acceptance. Whether you are just beginning to assess your obligations or are already working through a technical integration, TrustTech provides the expertise to move forward with confidence.

Concretely, TrustTech can help you with:

  • Scope and compliance assessment — determining whether your organisation is required to accept the EUDI Wallet, under which conditions, and by which deadline
  • Relying party registration — guiding you through the registration process with national authorities
  • Technical integration — implementing the protocols, interfaces, and credential verification flows required under eIDAS 2.0
  • Regulatory monitoring — keeping your implementation aligned as implementing regulations continue to be published
  • Sector-specific guidance — tailored support for finance, government, healthcare, and other regulated industries

The deadlines under eIDAS 2.0 are fixed: 24 December 2026 for public sector bodies, and 24 December 2027 for regulated private sector organisations. If your organisation has not yet started preparing for EUDI Wallet acceptance, the time to act is now. Contact TrustTech to discuss your situation and find out what your next steps should be.