A wallet provider is an organisation that issues and operates a digital identity wallet, giving users a secure app or platform to store, manage, and share their identity data and credentials. Under eIDAS 2.0, every EU Member State must make a wallet available to its citizens, residents, and businesses, either by building one directly or by certifying a private organisation to do so. This article unpacks the wallet provider role in detail, from who can become one to what it means for your organisation.

What does a wallet provider actually do?

A wallet provider issues and operates a digital identity wallet that allows users to store verified credentials, prove who they are, and selectively share personal data with third parties. The provider is responsible for the technical infrastructure behind the wallet, the security of the data stored in it, and the overall user experience of managing digital identity.

In practical terms, this means a wallet provider builds and maintains the application that sits on a user’s device, connects it to the trust infrastructure that makes credentials verifiable, and ensures it works across different services and borders. Users rely on the wallet to do things like open a bank account online, access government services, share a diploma, or present a mobile driving licence, without handing over more personal data than is strictly necessary.

The wallet itself does not store credentials on a central server owned by the provider. Instead, the user holds their own credentials, and the wallet provider supplies the secure environment in which those credentials live and can be presented. This distinction matters a great deal for privacy and data sovereignty.

Who is allowed to become a wallet provider under eIDAS 2.0?

Under eIDAS 2.0, both public authorities and private organisations can become wallet providers, provided they meet the certification requirements set by their Member State and comply with the technical standards defined in the Architecture and Reference Framework. A private company cannot simply launch a wallet and call it an EUDI Wallet; it must be officially recognised by the relevant national authority.

Member States are required to provide at least one certified wallet to all citizens, residents, and businesses by 24 December 2026. They can fulfil this obligation by building a government-operated wallet or by certifying one or more private providers. This opens the door for banks, telecoms, and technology companies to operate wallets, as long as they pass the required conformity assessments and security certifications.

The certification process is designed to ensure a consistent baseline of trust across the EU. A wallet certified in one Member State must be recognised and accepted in all others, which is one of the core goals of the regulation. This interoperability requirement places significant technical and compliance demands on any organisation seeking to become a wallet provider.

What is the difference between a wallet provider and an identity provider?

A wallet provider gives users a secure container to hold and present credentials, while an identity provider authenticates users and issues identity assertions. The key distinction is that a wallet provider does not necessarily verify who you are; it provides the infrastructure for you to carry and use credentials that have already been verified by authoritative sources.

An identity provider, in the traditional sense, sits between a user and a service and confirms that the user is who they claim to be, typically through a login process. The identity provider issues a token or assertion in real time. The wallet model works differently: a trusted authority issues a verifiable credential once, the user stores it in their wallet, and they can then present it to any relying party without the original issuer needing to be involved in every transaction.

In the EUDI Wallet ecosystem, a single organisation could play both roles. A government agency might issue a national identity credential and also operate a wallet. But conceptually, and often practically, these are separate functions. The wallet provider manages the user-facing application and the secure presentation of credentials; the issuer is the authority that produced and signed those credentials in the first place.

What responsibilities does a wallet provider have toward users?

A wallet provider is responsible for the security, privacy, and reliability of the wallet environment. This includes protecting stored credentials from unauthorised access, ensuring users retain full control over what data is shared and with whom, and maintaining the technical integrity of the wallet so that credentials remain valid and tamper-evident.

Beyond the technical obligations, wallet providers have clear responsibilities under eIDAS 2.0 and related data protection rules:

  • Data minimisation: The wallet must be designed so users can share only the specific attributes a service needs, not an entire document or identity record.
  • User control: Users must be able to see which credentials they hold, which parties they have shared data with, and revoke access where applicable.
  • Transparency: The provider must be clear about how the wallet works, what data it processes, and under what conditions.
  • Security certification: The wallet solution must meet the assurance levels required by the regulation and pass conformity assessments.
  • Availability and continuity: Users depend on the wallet for access to critical services, so providers must ensure the application remains available and functional over time.

These responsibilities make wallet provision a serious undertaking. It is not simply a software product; it is a trusted piece of infrastructure that people rely on for access to healthcare, financial services, government benefits, and more.

How does a wallet provider fit into the broader trust ecosystem?

A wallet provider is one of three core roles in the EUDI Wallet trust ecosystem, alongside credential issuers and relying parties. The provider sits in the middle: it receives credentials from issuers, holds them securely on behalf of the user, and enables the user to present them to relying parties in a way that those parties can cryptographically verify.

This ecosystem only works when all three roles operate within a shared trust framework. Issuers, such as government agencies, universities, or healthcare authorities, must be registered and recognised. Relying parties, such as banks, employers, or online platforms, must be able to verify that a credential is genuine and has not been tampered with. The wallet provider connects these parties through standardised protocols and certified infrastructure.

The large-scale pilot projects launched across Europe have been testing exactly this kind of end-to-end ecosystem in real-world scenarios, from cross-border payments to digital travel credentials and healthcare prescriptions. The insights from these pilots are shaping the final technical specifications that all wallet providers will need to meet. Organisations working in financial services or government are particularly affected, as these sectors are among the first to integrate wallet-based interactions into their services.

What should organisations look for when selecting a wallet provider?

When selecting a wallet provider, organisations should prioritise certification status, interoperability, security architecture, and the provider’s ability to support integration with existing systems. A wallet that is not certified under the eIDAS 2.0 framework will not be accepted by relying parties across the EU, which makes compliance the baseline requirement before anything else.

Beyond compliance, consider the following when evaluating wallet providers:

  1. Certification and recognition: Is the wallet officially recognised by a Member State? Does it meet the required assurance levels under eIDAS 2.0?
  2. Interoperability: Does the wallet support the technical standards in the Architecture and Reference Framework, ensuring it works across borders and with different issuers and relying parties?
  3. Security model: How does the wallet protect credentials? Is security tied to the device, or is there a backend architecture that provides resilience and flexibility?
  4. User experience: Will the wallet be easy for your end users or customers to use? Adoption depends heavily on simplicity and reliability.
  5. Integration support: Can the provider help you connect the wallet to your existing identity infrastructure, onboarding flows, or service delivery systems?
  6. Sector-specific expertise: Does the provider understand the regulatory and operational context of your industry, whether that is healthcare, finance, or another regulated sector?

Choosing the right wallet provider is a strategic decision, not just a technical one. The provider you work with will shape how your organisation participates in the European digital identity ecosystem for years to come.

How TrustTech helps with wallet provider readiness

TrustTech helps organisations navigate every dimension of the wallet provider landscape, from understanding the regulatory framework to implementing the technical infrastructure that makes wallet-based interactions work in practice. Whether your organisation is evaluating whether to become a wallet provider, integrating with an existing wallet solution, or preparing your systems to accept wallet-based credentials as a relying party, TrustTech brings the expertise to move from strategy to production.

Here is what TrustTech offers in this space:

  • Regulatory and compliance guidance: Translating eIDAS 2.0 requirements into concrete steps your organisation needs to take.
  • Technical implementation: Building and integrating the trust infrastructure, verifiable credentials, and interoperability layers your solution requires.
  • Sector-specific expertise: Deep experience in finance, government, healthcare, and pharmaceuticals, where wallet adoption is moving fastest.
  • Reusable trust layers: Helping you build infrastructure that works once and can be applied across multiple services and use cases.
  • Production-proven results: TrustTech works with organisations that need solutions that actually work at scale, not just in pilots.

If your organisation is preparing for the EUDI Wallet and wants practical guidance on where to start, get in touch with TrustTech to discuss your situation and next steps.