A wallet instance is the actual app installed and running on a user’s device, while a wallet solution is the certified software package that an approved provider makes available for that installation. Think of the wallet solution as the product, and the wallet instance as a single activated copy of that product used by one person.
Under eIDAS 2.0, this distinction is not just technical vocabulary. It has direct implications for certification, liability, and how organizations manage compliance across potentially millions of users. The sections below unpack each concept and explain why the difference matters in practice.
How do wallet instances and wallet solutions relate to each other?
A wallet solution and a wallet instance exist in a parent-child relationship. The wallet solution is the certified, approved software that a wallet provider develops and maintains. A wallet instance is created every time a user installs and activates that solution on their device. One wallet solution can give rise to millions of wallet instances, each belonging to a different individual user.
The wallet solution sets the rules, security architecture, and certified capabilities. The wallet instance inherits those properties but operates independently on the user’s device. Changes to the wallet solution, such as a security update or a new feature, eventually flow down to all active instances, but each instance also has its own lifecycle, including activation, suspension, and revocation.
This layered structure is what allows the European Digital Identity Wallet to scale across an entire country or the whole EU while still being individually controlled by each citizen. The provider manages the solution centrally; the user manages their own instance.
What exactly is a wallet solution under eIDAS 2.0?
A wallet solution under eIDAS 2.0 is the certified software package, including its backend infrastructure, that a recognized wallet provider offers to users. It is the entity that undergoes conformity assessment and receives official certification before it can be made available to the public. Without a valid certification, no wallet solution can be deployed in the EU.
The wallet solution must meet the requirements set out in the Architecture and Reference Framework (ARF), which defines the technical and security standards for all EUDI Wallets. This includes how the wallet handles cryptographic keys, how it communicates with relying parties, and how it protects user data.
Wallet solutions can be provided by governments directly or by private companies that have received official recognition from a Member State. Either way, the solution must demonstrate compliance with eIDAS 2.0 before any instance of it can be issued to users. This certification is what gives relying parties, such as banks, healthcare providers, and government agencies, the confidence to accept presentations from wallet instances built on that solution.
What exactly is a wallet instance under eIDAS 2.0?
A wallet instance under eIDAS 2.0 is the individual, device-bound installation of a certified wallet solution that belongs to a specific user. It is the operational unit: the app on a person’s smartphone that they use to store credentials, prove their identity, and share verified data with services. Each instance is unique to one person and one device.
When a user activates a wallet instance, several things happen:
- A unique cryptographic key pair is generated and bound to that specific device
- The instance receives a wallet unit attestation that confirms it belongs to a valid, certified wallet solution
- The user can then request credentials, such as a digital driving license or a qualified electronic attestation of attributes, to be loaded into their instance
- The instance becomes the user’s personal trust anchor for all subsequent digital interactions
Importantly, the user is in control of their wallet instance. They decide which credentials to store, what data to share, and with whom. This selective disclosure principle is one of the core privacy protections built into the EUDI Wallet framework.
Why does the distinction matter for compliance and implementation?
The distinction between wallet solution and wallet instance matters for compliance because certification applies to the solution, while liability and data control apply at the instance level. Organizations that interact with EUDI Wallets, whether as relying parties or credential issuers, need to understand both layers to design compliant processes.
For relying parties such as financial services firms or healthcare providers, accepting a presentation from a wallet instance is only valid if that instance belongs to a certified wallet solution. This means organizations must be able to verify the solution’s certification status as part of their verification flow.
For organizations issuing credentials into wallets, understanding the instance layer is equally important. A credential is bound to a specific wallet instance. If that instance is revoked or suspended, the credential can no longer be used, even if the underlying wallet solution remains certified. This has direct consequences for credential lifecycle management.
From a broader implementation perspective, the two-layer model also affects how organizations in financial services and other regulated sectors design their onboarding and verification workflows. Systems need to be built to handle both the solution-level trust anchor and the instance-level binding.
Who is responsible for managing wallet instances versus the wallet solution?
Responsibility is split clearly between two parties. The wallet provider is responsible for the wallet solution: its certification, its security, its updates, and its continued compliance with eIDAS 2.0. The user is responsible for their own wallet instance: activating it, keeping the device secure, and managing which credentials are stored and shared.
This division of responsibility has practical consequences for both sides:
- Wallet providers must maintain their certification continuously, push security updates to all active instances, and handle the revocation of instances that have been compromised or reported lost.
- Users must protect their device and authenticate themselves to access the wallet. If a device is lost or stolen, the user can request that their instance be suspended or revoked.
- Member States oversee the recognition and supervision of wallet providers, ensuring that only certified solutions are made available to citizens and businesses.
- Relying parties must verify instance-level attestations at the point of interaction, confirming that the instance they are dealing with belongs to a valid, certified solution.
For organizations in government services that are both issuing credentials and accepting them, understanding where their responsibilities begin and end within this structure is essential for sound governance.
How does wallet attestation connect instances to the solution?
Wallet attestation is the cryptographic mechanism that links a wallet instance back to its certified wallet solution. When a wallet instance is activated, the wallet provider issues a wallet unit attestation (WUA), a signed digital statement confirming that this specific instance was created by a valid, certified wallet solution and that it meets the required security standards.
This attestation serves as the trust bridge in every interaction. When a user presents a credential to a relying party, the relying party does not just verify the credential itself. It also verifies the wallet unit attestation to confirm that the instance presenting the credential is genuine and has not been tampered with or revoked.
The attestation model also enables selective disclosure to work correctly. Because the instance’s keys are cryptographically tied to its attestation, the user can prove specific attributes without revealing unnecessary personal data, and the relying party can trust that the proof comes from a legitimate, certified environment.
For organizations building systems that accept EUDI Wallet presentations, handling wallet attestations correctly is not optional. It is a core part of the verification chain, and getting it right is one of the areas where technical implementation expertise makes a significant difference. Organizations looking at implementation resources will find that attestation handling is consistently highlighted as a critical integration point.
How TrustTech helps with wallet instances and wallet solutions
Understanding the difference between a wallet instance and a wallet solution is one thing. Implementing systems that correctly handle both layers in a compliant, scalable way is another challenge entirely. This is where TrustTech supports organizations across regulated sectors.
TrustTech works with organizations to navigate the full complexity of the EUDI Wallet ecosystem, including:
- Mapping out how wallet solution certification requirements affect your existing compliance framework
- Designing verification flows that correctly validate wallet unit attestations at the instance level
- Building credential issuance processes that account for instance lifecycle events such as revocation and suspension
- Integrating EUDI Wallet interactions into onboarding, authentication, and data exchange workflows
- Preparing teams across compliance, IT, and operations to work confidently within the eIDAS 2.0 trust model
Whether your organization is just beginning to explore what the EUDI Wallet means for your sector or is already working toward a concrete implementation, TrustTech brings the technical depth and practical experience to move from understanding to action. Explore TrustTech’s solutions to see how organizations in finance, government, and healthcare are putting this into practice, or get in touch to discuss your specific situation.