eIDAS 2.0 supports decentralized identity architectures by shifting control of identity data away from central brokers and toward individuals themselves. Instead of relying on a single authority to verify and share identity information, the regulation introduces the European Digital Identity Wallet, which lets users hold, manage, and selectively share their own verified credentials. The sections below unpack how this works technically, what standards it relies on, and what organizations should do to prepare.

What makes eIDAS 2.0 architecturally different from eIDAS 1.0?

The fundamental difference is that eIDAS 1.0 was built around centralized national identity schemes, while eIDAS 2.0 introduces a user-controlled wallet model that distributes identity data to the edges of the network. Under the original framework, Member States could notify their national eID systems for cross-border recognition, but there was no obligation to do so, and the private sector was largely excluded. This created a fragmented landscape where recognition varied widely across borders.

eIDAS 2.0 addresses this directly. Every Member State is now legally required to offer citizens, residents, and businesses a European Digital Identity Wallet. Rather than routing identity verification through a central broker or a government portal, the wallet sits on the user’s device and acts as a personal identity hub. Verified attributes, such as a driving license or professional qualification, are stored as digital credentials that users can present directly to relying parties.

This architectural shift has real consequences for organizations. Previously, a service provider in one country might need to integrate with multiple national identity systems to serve users across the EU. Under eIDAS 2.0, a single integration point with the wallet ecosystem is sufficient. The result is a more interoperable, scalable, and privacy-respecting infrastructure across the entire European Union.

How does the EUDI Wallet enable decentralized identity?

The EUDI Wallet enables decentralized identity by acting as a personal data store that sits under the user’s control, rather than on a server managed by a government or platform. When a user wants to prove their age, nationality, or professional status, they present a cryptographically verified credential directly from their wallet to the requesting party, without a central authority needing to mediate the transaction in real time.

This model is sometimes described as a “verify once, present anywhere” approach. A government authority or trusted institution issues a credential into the wallet. From that point forward, the user can share that credential with any service that accepts it, across borders and sectors, without going back to the original issuer each time.

The wallet also gives users granular control over what they share. Rather than handing over a full identity document, a user can disclose only the specific attribute a service needs. Proving you are over 18 does not require revealing your exact date of birth. This principle of selective disclosure is central to the decentralized identity model and is a core design requirement of the EUDI Wallet.

Large-scale pilot projects are currently testing these capabilities across sectors including financial services, healthcare, education, and transportation. These pilots, involving over 350 entities from 26 Member States, are collecting real-world feedback on usability, security, and interoperability to refine the wallet before full deployment.

What are verifiable credentials and how do they fit into eIDAS 2.0?

Verifiable credentials are digitally signed statements issued by a trusted authority that can be cryptographically verified by anyone without contacting the original issuer. They are the building blocks of the EUDI Wallet ecosystem and the mechanism through which eIDAS 2.0 makes decentralized identity work in practice.

Think of a verifiable credential as the digital equivalent of a stamped certificate, except that the stamp cannot be forged and the verification happens instantly. An employer, university, government body, or regulated institution issues a credential that gets stored in the user’s wallet. When that user presents the credential to a bank, healthcare provider, or online platform, the receiving party can verify its authenticity and integrity without calling the issuer.

Within the eIDAS 2.0 framework, verifiable credentials can represent a wide range of identity attributes and documents:

  • National identity documents and passports
  • Academic qualifications and diplomas
  • Professional licenses and certifications
  • Employment records and KYC data
  • Healthcare credentials and prescriptions
  • Payment credentials and financial compliance records

For organizations in regulated sectors such as finance, healthcare, and government, verifiable credentials open up the possibility of reusing trusted identity data across processes. A customer who has already completed identity verification at their bank could present that same verified credential when onboarding with an insurer or a healthcare provider, eliminating redundant checks and reducing friction on both sides.

How does eIDAS 2.0 handle trust without a central identity broker?

eIDAS 2.0 replaces the central broker model with a trust framework built on cryptographic proof and a network of recognized issuers and verifiers. Trust is established not by routing identity data through a single authority, but by ensuring that every credential in the ecosystem has been issued by a party whose identity and authority can be independently verified.

The Architecture and Reference Framework (ARF), developed by the European Digital Identity Cooperation Group, defines the technical and governance rules that make this possible. It specifies how wallets must be certified, how credentials must be structured and signed, and how relying parties can verify that a credential is genuine and has not been tampered with.

At the heart of this model is the concept of a trust registry. Trusted issuers, such as government agencies, banks, universities, and qualified trust service providers, are listed in registries that relying parties can consult to confirm that a credential source is legitimate. This means a hospital in Spain can trust a professional qualification credential issued by a Dutch authority, because both operate within the same governed framework.

This approach distributes trust across the ecosystem rather than concentrating it in one place. It is more resilient, more scalable, and more privacy-preserving than architectures that require every identity transaction to pass through a central node.

Which standards and protocols does eIDAS 2.0 rely on?

eIDAS 2.0 relies on a combination of open standards for credential formats, cryptographic signing, and wallet communication protocols. These standards ensure that wallets, issuers, and verifiers from different countries and technology providers can interoperate reliably across the EU.

The Architecture and Reference Framework specifies the technical foundations that all EUDI Wallet implementations must follow. Key standards and components include:

  1. ISO/IEC 18013-5 for mobile driving licenses and similar document-based credentials, defining how credentials are structured and presented from a device.
  2. W3C Verifiable Credentials Data Model, which provides the standard format for expressing and exchanging verifiable credentials in a machine-readable way.
  3. OpenID for Verifiable Credential Issuance (OID4VCI) and OpenID for Verifiable Presentations (OID4VP), which define how credentials are issued to wallets and how they are presented to verifying parties.
  4. Qualified Electronic Signatures (QES) under the existing eIDAS trust service framework, which remain central to legally binding digital signing under eIDAS 2.0.
  5. SD-JWT (Selective Disclosure JSON Web Tokens), which enables the selective disclosure of individual credential attributes without revealing the full document.

The open-source nature of the EUDI Wallet reference implementation means that Member States and private providers can build on a shared, publicly vetted codebase. This accelerates adoption and reduces the risk of fragmentation across national implementations.

What should organizations do now to prepare for eIDAS 2.0 compliance?

Organizations should start preparing for eIDAS 2.0 by assessing which of their processes involve identity verification, credential exchange, or electronic signing, and then mapping those processes against the requirements of the new framework. With Member States legally required to make wallets available by 2026, the timeline for compliance is already active.

Preparation does not need to be overwhelming. A structured approach helps organizations move from awareness to action without overextending their teams. Practical steps include:

  • Reviewing current identity verification and onboarding flows to identify where EUDI Wallet integration will be required or beneficial
  • Assessing existing digital signature infrastructure against eIDAS 2.0 qualified signature requirements
  • Engaging with the Architecture and Reference Framework to understand technical specifications relevant to your sector
  • Evaluating interoperability requirements, particularly for organizations operating across multiple EU Member States
  • Identifying which credentials your organization may need to issue, accept, or verify under the new framework

Organizations in financial services face particular urgency, given the overlap between eIDAS 2.0 requirements and existing AML, KYC, and PSD2 obligations. Similarly, organizations in healthcare and government will need to align their identity infrastructure with wallet-based credential exchange early. The TrustTech resources section offers further guidance on sector-specific preparation.

How TrustTech helps with eIDAS 2.0 and decentralized identity

Navigating the shift to decentralized identity and eIDAS 2.0 compliance is complex, especially when your organization also needs to meet existing regulatory requirements across multiple jurisdictions. TrustTech provides the expertise and infrastructure to make this transition manageable and effective.

Working with TrustTech, organizations can:

  • Implement EUDI Wallet-ready identity verification that works across onboarding, authentication, and signing workflows
  • Replace repeated identity checks with reusable, cryptographically verified credentials that travel with the user
  • Issue and accept verifiable credentials in formats aligned with the Architecture and Reference Framework
  • Connect identity, qualification, and signing processes into a single, auditable workflow
  • Reduce compliance risk and onboarding friction at the same time, turning regulatory requirements into a competitive advantage

TrustTech’s platform is built on European digital identity standards and designed to be eIDAS 2.0-ready from the ground up. Whether your organization is just starting to assess its exposure or is ready to begin implementation, TrustTech brings both the technical depth and the regulatory knowledge to move forward with confidence. Explore the TrustTech solutions or get in touch to discuss your specific situation.