Editorial explainer · official sourcesmedium
eIDAS 2: Europe's digital identity wallet, and why it is a security matter
With Regulation (EU) 2024/1183, Europe rewrites eIDAS and introduces the European Digital Identity Wallet: an app in which citizens hold identity and attestations and present them selectively. The roadmap requires each Member State to offer at least one certified wallet by the end of 2026. This is not just a matter of bureaucratic convenience: an app that becomes the key to public and private services is, by definition, an extremely high-value target. An explainer on what the rules say, with the dates that matter and why security is at its core.
What it is, in one sentence
Regulation (EU) 2024/1183, in force since 20 May 2024, amends the old eIDAS framework and introduces the EUDI Wallet, the European digital identity wallet. The idea in one sentence: an app, on the citizen's phone, in which to hold a digital identity and a set of attestations — from a driving licence to a diploma — and with which to identify oneself to public and private services across the Union. The roadmap is precise: after the implementing acts were adopted on 28 November 2024, Member States are required to make at least one certified wallet available by the end of 2026. Each State can build it directly, mandate a party to do so, or recognise a private-sector solution.
- 20 May 2024Entry into force
Regulation (EU) 2024/1183 amends eIDAS
- 28 November 2024Implementing acts
functions, data, interfaces and certification
- End of 2026The wallets
each State offers at least one certified wallet
Why a cybersecurity site covers it
Because a single, widespread digital identity is not just a convenience: it is an attack surface. The moment an app becomes the key that opens public services, bank accounts and healthcare, the stakes of its compromise grow in proportion. A regulatory framework that pushes hundreds of millions of people towards a single identity tool must, of necessity, put security at the centre — and the rules do so in two ways.
The first is certification: the wallet is not just any app; it must reach a high assurance level and pass conformity assessments, in line with the European work on cybersecurity certification coordinated by ENISA. The second is a privacy-favouring design principle: selective disclosure. Instead of handing over a whole document to prove a single fact — age, residence — the wallet lets you show only the required attribute, under the user's control. It is privacy by design applied to identity: the less data circulates, the less there is to steal.
What it is not, to avoid confusion
It is worth clarifying the limits, because a lot of confusion surrounds digital identity. On paper the wallet is voluntary for the citizen: it is a tool made available, not an obligation to hold one. The obligations, if anything, fall downstream: the roadmap foresees that by 2027 various actors — regulated sectors such as banking, healthcare and telecoms, and very large online platforms — must accept the wallet as a means of identification where the user chooses to use it. The EU's stated long-term horizon is ambitious: 80% of European citizens equipped with a digital identity by 2030.
Two cautions, said honestly. Actual availability dates depend on implementation in individual Member States and may slip against the European deadline: the "by end of 2026" target is the one set by the framework, not a guarantee about every single country's calendar. And the success of the whole approach will depend on the real robustness of the implementations: a security principle written into the regulation is worth only as much as its technical delivery. But the direction is clear, and it is the right one for anyone looking at this from the security side: to build digital identity by making protection and user control not a final add-on, but the foundation.