How does eIDAS 2.0 support self-sovereign identity?

Open EU passport held in hand beside a digital identity card on a white surface, representing personal identity documents and data ownership.

eIDAS 2.0 supports self-sovereign identity (SSI) by adopting several of its core principles, most notably user control over personal data, selective disclosure, and the use of verifiable credentials. While eIDAS 2.0 is not a pure SSI framework, it brings European digital identity significantly closer to the SSI model than its predecessor. The sections below explore exactly how this works, where the two approaches align, and what it means for organizations operating in regulated sectors.

What SSI principles does eIDAS 2.0 actually adopt?

eIDAS 2.0 adopts three foundational SSI principles: user control over identity data, selective disclosure of attributes, and the use of cryptographically verifiable credentials. These principles are embedded directly into the architecture of the European Digital Identity Wallet, which every EU Member State is required to provide to citizens, residents, and businesses.

Self-sovereign identity is built on the idea that individuals, not institutions, should control their own identity data. eIDAS 2.0 moves in this direction by giving users a wallet-based environment where they decide what information to share, with whom, and when. The regulation explicitly states that anything not necessary to share will not be shared, which directly reflects the SSI principle of data minimization.

The framework also adopts the SSI concept of portability. Identity attributes stored in the EUDI Wallet can be used across borders and across sectors, from opening a bank account to claiming a prescription. This interoperability is a structural commitment to the idea that identity should travel with the person, not be locked inside a single institution’s system.

What eIDAS 2.0 does not fully adopt from SSI is decentralization in its purest form. The framework still involves government-issued credentials and state-recognized wallet providers, which means there is an element of centralized trust anchoring the system. But within that structure, the user-facing experience and data governance principles are strongly aligned with SSI thinking.

How does the EUDI Wallet give users control over their data?

The EUDI Wallet gives users control by acting as a personal digital container where they store, manage, and selectively share identity attributes and documents. Users can present only the specific information a service requires, such as confirming they are over 18 without revealing their full date of birth, and they retain visibility over what has been shared and with whom.

This is a meaningful shift from how identity works today. In most current digital interactions, users hand over entire identity documents or fill in full personal details, even when only a single attribute is actually needed. The wallet changes this dynamic by enabling attribute-level sharing, which is one of the most practical expressions of SSI principles in a regulated context.

The wallet also removes the need to rely on private platforms for identity verification. Under the current model, many online services require users to log in through social media accounts or other commercial identity providers, which often means trading personal data for convenience. eIDAS 2.0 gives users a government-backed alternative that does not require unnecessary data sharing with third parties.

Large-scale pilot projects have been testing exactly these capabilities across real-world scenarios, including accessing government services, opening bank accounts, signing contracts, and claiming prescriptions. The feedback from these pilots is being used to refine the wallet’s design, ensuring that user control remains practical and not just theoretical.

What is the difference between SSI and the eIDAS 2.0 model?

The key difference between pure SSI and the eIDAS 2.0 model is the role of trusted authorities. In a fully self-sovereign identity system, there is no central issuing authority. Credentials are issued peer-to-peer and verified through decentralized infrastructure, typically using distributed ledger technology. eIDAS 2.0, by contrast, anchors trust in government-issued credentials and officially recognized wallet providers.

This distinction matters because it reflects a deliberate policy choice. The EU framework prioritizes legal certainty, cross-border interoperability, and accountability over pure decentralization. A credential issued through the EUDI Wallet carries legal weight precisely because it is backed by a recognized national identity system, something a purely decentralized credential cannot guarantee in the same way.

That said, the two models share more common ground than they differ. Both give users control over their data. Both use verifiable credentials that can be presented selectively. Both aim to reduce reliance on centralized data silos. The eIDAS 2.0 framework can be understood as a regulated, government-anchored implementation of SSI principles rather than a rejection of them.

For organizations, this distinction is practically important. The EUDI Wallet will not operate on a fully open, permissionless network. Trust relationships are managed within a defined ecosystem of recognized issuers and verifiers. This creates predictability and legal clarity, which is valuable in sectors like finance, healthcare, and government where regulatory compliance is non-negotiable.

How do verifiable credentials work under eIDAS 2.0?

Under eIDAS 2.0, verifiable credentials are digitally signed identity attributes or documents that can be cryptographically verified without contacting the original issuer. A government authority, employer, or educational institution issues a credential to a user’s EUDI Wallet, and the user can then present that credential to any service that needs to verify it, with the cryptographic proof confirming its authenticity.

The process follows a straightforward flow:

  1. Issuance: A recognized authority issues a credential to the user’s wallet. This could be a national ID attribute, a professional qualification, a diploma, or a health document.
  2. Storage: The credential is stored securely in the EUDI Wallet, under the user’s control.
  3. Presentation: When a service requests verification, the user selects which credential or attributes to share and consents to the disclosure.
  4. Verification: The receiving organization verifies the cryptographic signature to confirm the credential is genuine, without needing to call back to the issuer or access a central database.

This architecture has significant implications for privacy. Because verification does not require contacting the original issuer, there is no passive tracking of where or how often a credential is used. The user presents the credential, the verifier checks the signature, and the interaction is complete without leaving a data trail at the source.

eIDAS 2.0 aligns this model with existing qualified trust services, meaning that certain credentials, particularly those tied to electronic signatures and identification, carry the same legal standing across all EU Member States. This makes verifiable credentials under eIDAS 2.0 not just technically sound but legally enforceable.

What does eIDAS 2.0 mean for organizations handling identity data?

For organizations that handle identity data, eIDAS 2.0 means a fundamental shift in how identity verification works. Rather than collecting and storing personal data themselves, organizations will increasingly receive verified, cryptographically signed attributes from users’ EUDI Wallets. This reduces the data burden on organizations, lowers compliance risk, and streamlines onboarding processes.

The practical implications span several areas:

  • Reduced data collection: Organizations only receive the attributes they actually need, rather than full identity documents. This simplifies GDPR compliance and reduces liability.
  • Faster onboarding: Verified credentials can be reused across interactions, meaning customers who have already verified their identity elsewhere do not need to start from scratch.
  • Cross-border recognition: Credentials issued in one EU Member State are recognized across all others, removing friction from cross-border services.
  • Legal certainty: Credentials tied to qualified trust services carry legal weight, which is essential for sectors like banking, healthcare, and pharmaceuticals.
  • New trust relationships: Organizations will need to become recognized verifiers within the EUDI ecosystem, which requires technical integration and compliance with wallet interaction standards.

The shift also requires organizations to rethink their identity infrastructure. Systems built around traditional document checks or password-based authentication will need to evolve to support wallet-based interactions and verifiable credential flows. Organizations in regulated sectors that start this preparation early will be better positioned when full deployment is required.

How TrustTech helps organizations prepare for eIDAS 2.0

Navigating the transition to eIDAS 2.0 and the EUDI Wallet is not straightforward. The regulatory requirements, technical standards, and organizational changes involved are significant, especially for businesses in finance, healthcare, government, and other regulated sectors. TrustTech is built specifically to support this transition.

TrustTech helps organizations move from their current identity infrastructure to an eIDAS 2.0-ready model through a structured, practical approach. Concretely, this means:

  • Implementing verifiable credential flows that connect your onboarding and verification processes to the EUDI Wallet ecosystem
  • Enabling reusable digital identity so customers verify once and that verification is trusted across every subsequent interaction
  • Integrating qualified electronic signatures and trust services that are fully compliant with eIDAS 2.0 standards
  • Supporting cross-sector and cross-border interoperability, so your organization is ready for the full scope of the European digital identity framework
  • Providing guidance tailored to your sector, whether you operate in financial services, healthcare, or government

TrustTech sits between the parties that need to interact, providing the infrastructure to identify, qualify, and sign, without owning any of the parties involved. The platform is designed to be eIDAS 2.0-ready by design, which means your organization does not need to rebuild from scratch. You can explore TrustTech’s solutions to see how each component fits together, or review the TrustTech approach to understand how implementation typically works in practice.

If your organization is ready to take concrete steps toward eIDAS 2.0 compliance and EUDI Wallet readiness, get in touch with TrustTech to discuss where to start.