On this page
- Regulatory basis
- Core functions
- Rollout timeline
- Who is mandated to accept the wallet
- Ecommerce and checkout impact
- Payment authentication (SCA)
- Fast checkout and onboarding economics
- Age verification / age-gating
- Technical integration requirements
- Fraud and security concerns
- Liability
- New large-scale pilots (active 2025–)
- Dangling frontiers (not yet written)
EUDI Wallet
EUDI Wallet (EU Digital Identity Wallet)
The EUDI Wallet is a technical and legal standard established by the eIDAS 2.0 Regulation (Regulation (EU) 2024/1183, entered into force 20 May 2024) that entitles every EU citizen and resident to a certified digital wallet for storing, sharing, and signing with verified identity attributes. It is not a single application — multiple compliant wallets will co-exist from both public and private issuers. For ecommerce, the wallet creates a new authentication and identity-verification layer that can be used for checkout, age-gating, KYC onboarding, and Strong Customer Authentication (SCA / PSD2) for regulated payment flows.
Regulatory basis
Baker McKenzie (2026-03-27) reports that eIDAS 2.0 refers to "the technical and legal standard established by eIDAS 2.0 Regulation," not a single app, and that private parties may create their own wallets if they meet technical standards and complete an official recognition process. The base regulation is Regulation (EU) No 910/2014 (original eIDAS), consolidated 2024-10-18 and amended by the European Digital Identity Regulation entering into force May 2024.
Gataca (2026-03-26) reports that Regulation (EU) 2024/1183 is the specific legislative number for eIDAS 2.0.
The governing technical document is the Architecture Reference Framework (ARF), currently at version 2.9.0 (published 21 May 2026 by the European Commission DG CNECT), covering Technical Specifications TS1–TS12 (as-of 2026-05-21).
Core functions
Ravelin (2026-02-16) reports the EUDI Wallet's four core functions are "authenticate, share, store, and sign," covering KYC, payment authorisation, cross-border transactions, document storage (passports, visas), and retail B2C and B2G payment acceptance.
Gataca (2026-03-26) reports the wallet supports selective disclosure, allowing users to prove specific attributes (e.g., being over 18) without sharing their full date of birth or name — a core privacy feature of eIDAS 2.0. This is governed by ARF TS4 (zero-knowledge proofs).
The ARF defines wallet ecosystem roles including: Wallet Provider, PID Provider (Person Identification Data), Attestation Provider, Relying Party, and Wallet Unit. Wallet Unit Attestations (WUAs) are specified in TS3 for issuance of PIDs and attestations (eudi.dev, 2026-05-21).
Rollout timeline
| Milestone | Date | Source |
|---|---|---|
| eIDAS 2.0 entered into force | May 2024 | Gataca 2026-03-26 |
| Technical implementing acts published | 4 December 2024 | Baker McKenzie 2026-03-27 |
| ARF v2.9.0 published | 21 May 2026 | eudi.dev |
| Implementing Regulation on wallet enrollment published | 8 April 2026 | deepidv.com 2026-05-18 |
| All 27 Member States must offer at least one certified wallet | December 24, 2026 | deepidv.com 2026-05-18 |
| VLOPs and public-sector services must accept wallet | December 2026 | Signicat 2026-04-13 |
| Regulated private sectors (banks, financial services) mandatory acceptance | December 2027 | Signicat 2026-04-13 |
| AMLR obligations (KYC/AML via eIDAS-compliant identity) apply | July 10, 2027 | IDnow/FIBE 2026-04-30 |
| EC target: 80% of EU citizens equipped with wallet | 2030 | Gataca 2026-03-26 (as-of 2026-03-26) |
Early national implementations: Gataca (2026-03-26) reports France (France Identité), Austria (eAusweise), and Italy (IT-Wallet) have launched implementations ahead of the December 2026 deadline. Germany's official EUDI Wallet is expected "by early 2027" (Baker McKenzie 2026-03-27).
EIC 2026 speakers from Politecnico di Milano's Digital Identity and Wallet Observatory reported that fewer than one-third of Member States meet the readiness benchmark as of June 2026 (as-of 2026-06). As of April 2026, only Denmark, France, Germany, and Ireland had public sandbox environments (eideasy.com 2026-04-06, as-of 2026-04-06).
Who is mandated to accept the wallet
Signicat (2026-04-13) reports Article 5f of eIDAS 2.0 as the specific legal source of the acceptance obligation, with three sections:
- Section 1 — Public sector services: effective December 2026
- Section 2 — Regulated private industries with mandatory SCA: effective December 2027
- Section 3 — Very Large Online Platforms (VLOPs under DSA, 45M+ EU users): effective from wallet launch in December 2026
Baker McKenzie (2026-03-27) reports that because "there are currently no VLOPs which function without authentication," the acceptance requirement "in practice applies to all VLOPs" — including marketplaces, app stores, major search engines, social media, and large digital content services.
Baker McKenzie (2026-03-27) also reports the obligation extends to "any private party with a contractual obligation to use strong user authentication" regardless of sector — including parties bound by B2B agreements, insurance requirements, industry SLAs, or GDPR technical and organisational measures.
Scope of merchant mandate: eIDEasy (2026-02-03) states that for most standard retailers not in regulated sectors and not subject to a legal or contractual SCA obligation, "accepting it is optional — organisations can choose to accept it but face no acceptance mandate." Ravelin (2026-02-16) states "by 2027, merchants who serve EU-based customers will have to accept EUDI Wallets as a way of authenticating customers" without the same qualification. The legal sources (deepidv.com 2026-05-11) confirm general ecommerce retailers not qualifying as VLOPs and not operating in regulated sectors are NOT subject to mandatory acceptance obligations — Ravelin's framing is imprecise.
Exemptions (Ravelin, 2026-02-16): microenterprises (fewer than 50 employees and annual turnover below €10 million) are exempt from the acceptance obligation, and low-value transactions already exempt under PSD2 SCA rules are also exempt.
Ecommerce and checkout impact
Payment authentication (SCA)
Signicat (2026-04-13) reports that under eIDAS 2.0, financial institutions will be legally required to accept EUDI Wallets for Strong User Authentication (the SCA equivalent) — covering login, payment approval (including dynamic linking of the authentication to specific amount and payee), and account onboarding — and must support all 27+ EU member state wallets cross-border.
The SCA implementation model from large-scale pilots (Signicat, 2026-04-13): payment service providers issue a device-bound SCA attestation into the user's wallet after authenticating via an existing PSD2-compliant method; the wallet then cryptographically signs transaction-specific data (amount, payee) to enable dynamic linking — with the PSP retaining full responsibility as both issuer and verifier.
ARF Technical Specification TS12 specifically covers SCA implementation with the wallet, and the EBA is mandated under Article 89 of the Payment Services Regulation (PSR) to develop a new RTS on SCA that will repeal the existing PSD2 RTS (Signicat, 2026-04-13).
Fast checkout and onboarding economics
EWC large-scale pilot data (dock.io, 2025-12-03): 49 bank-led production payment transactions and 12 merchant-captured fast-checkout transactions were executed using live EUDI Wallet infrastructure (as-of 2025-12-03). 80% of participants found wallet-based fast checkout easier than traditional banking checkout. App-switching friction remains an unresolved UX issue.
EIC 2026 presenter Petra Krizan (The Blockhouse Technology) quantified onboarding economics: live video identity onboarding costs roughly 70–100 EUR per customer, versus 3–8 EUR per customer when automated through wallet-based identity (as-of 2026-06).
Age verification / age-gating
Baker McKenzie (2026-03-27) identifies age-gating via EUDI Wallet as a significant ecommerce revenue opportunity, specifically naming gambling services, 18+ digital content and video games, and sellers of alcohol, tobacco, and adult media — all able to complete age verification "in seconds" without country-specific workarounds.
Amazon's Principal PM for Identity Services (Paul Grassi, Dock Labs webinar 2025-03-12) stated Amazon is exploring accepting EUDI Wallet credentials for age-restricted purchase flows where the wallet shares only an "Over 18?" boolean without exposing full date of birth, and for address verification and account recovery.
Amazon/Dock Labs webinar (published 2025-03-12) — included because it is the only publicly available statement from a major ecommerce retailer on specific EUDI integration plans. No 2026 update found.
A demo published August 2025 showed EUDI Wallet used for a ferry ticket purchase: proving identity, applying age-based discounts, paying, and receiving a boarding pass and e-receipt — all within a single wallet-mediated flow (as-of 2025-08-08).
Demo video published August 2025. Included as the clearest available illustration of the checkout flow. No 2026 equivalent found.
Technical integration requirements
Gataca (2026-03-26) reports the EUDI Wallet is built on W3C Verifiable Credentials and ISO/IEC 18013-5 standards. Relying parties must:
- Register on Member States' national registers of wallet-relying parties (Ravelin, 2026-02-16)
- Receive an access certificate before using EUDI Wallets for their services
- Familiarise with the ARF (currently v2.9.0) to understand integration requirements
Ravelin (2026-02-16) reports EUDI Wallets use "industry-standard APIs and protocols allowing for easier integration" and that merchants should continue offering existing authentication options (e.g., 3D Secure) alongside EUDI Wallet support.
Known implementation gaps (as-of 2026-04-13, Signicat):
- Several national wallet implementations have indicated they will not support 3rd-party issuing into wallets from the start (required for certain payment flows)
- W3C Digital Credential (DC) APIs "are not yet finalised and not fully mature enough to be supported across platforms and ecosystems"
- A "gap between the intended scope of acceptance and the practical challenges of meeting the SCA requirements laid down in PSD2" — specifically a lack of dynamic linking capability in current implementations (Dutch Payment Association, cited by Ravelin)
The Smart Payment Association concludes "the EUDIW must not attempt to create its own payment rails" and that "existing payment instruments and solutions should be integrated into the wallet" (Ravelin, 2026-02-16).
Germany's sandbox: EIC 2026 speakers from SPRIND reported approximately 115 organizations and 150 use cases were active after 6 months of Germany's EUDI sandbox operation, with relying-party onboarding — not technology — as the dominant bottleneck (as-of 2026-06).
Fraud and security concerns
Ravelin (2026-02-16) reports that a central security risk is that verified credentials stored in the EUDI Wallet represent "a potential single point of vulnerability to cybercrime," including PID (Person Identification Data) cloning and wallet hijacking enabling account takeover and bank account access.
Ravelin (2026-02-16) reports that credential use is not trackable by design for privacy reasons, which could be exploited by cybercriminals, and that there is currently no defined dispute/chargeback mechanism for illegitimate EUDI Wallet use equivalent to card chargebacks (as-of 2026-02-16).
Fraud reduction of 96–98% was observed in Scandinavian markets where national eIDs are integrated with payment flows — cited as the indicative potential of wallet-linked payment authentication (dock.io, 2025-12-03, as-of 2025-12-03).
Attestation: security necessity vs. digital autonomy capture. Hacker News developer community (May–July 2026) is split. One camp argues hardware attestation by Google/Apple is "a direct consequence of existing laws/regulations regarding making IDs forgery safe" and an inevitable result of >90% Android/iOS market share. The opposing camp argues ZKP and device-bound keys could achieve equivalent security without mandating Google/Apple approval of operating systems — and that Italy's IO app refusal of GrapheneOS support constitutes de facto exclusion of privacy-conscious users. Sources: HN 48086778 (May 2026) and HN 48730729 (July 2026).
Liability
Liability frameworks for wallet-based payment authentication remain unresolved as of the pilot conclusions (dock.io, 2025-12-03, as-of 2025-12-03). It is unclear who bears responsibility when wallet-based SCA fails across banks, wallet providers, and relying parties.
Enforcement penalties: Ravelin (2026-02-16) states non-compliance penalties are "expected to be up to €500,000 or 1% of global annual turnover." Signicat (2026-04-13) states the European Commission will apply penalties "similar to those for trust services — €5 million or 1% of the annual turnover." These figures diverge by 10x on the fixed cap. Signicat's figure is more recent; neither cites a formally published enforcement model.
New large-scale pilots (active 2025–)
Two new pilot consortia launched September 2025 (biometricupdate.com, 2025-09): APTITUDE and WE BUILD. WE BUILD focuses on B2B, B2G, and B2C payment and business interactions.
Dangling frontiers (not yet written)
- ARF (Architecture Reference Framework) — technical spec for EUDI Wallet interoperability
- Age Verification — ecommerce-specific use cases and regulation
- PSR (Payment Services Regulation) — PSD3 successor, SCA RTS under Article 89
- AMLR (Anti-Money Laundering Regulation) — July 2027 identity obligation
- eIDAS — original regulation this amends
- Verifiable Credentials (W3C) — underlying credential standard
- Zero-Knowledge Proofs (ZKP) — selective disclosure implementation