sg

51.79.143.61

Back
Blogs

EUDI Wallet: What eIDAS 2.0 actually requires of you before 2027

EUDI Wallet: What eIDAS 2.0 actually requires of you before 2027
Madiha Khatoon JULY 2, 2026 9 minutes read

The EUDI Wallet is not a KYC shortcut. eIDAS 2.0 requires regulated firms to register as a wallet-relying party, accept wallet credentials by December 2027, and keep running every AML check they run today.

December 2027 is when the EU Digital Identity (EUDI) Wallet stops being optional for regulated firms. That is the deadline eIDAS 2.0, the April 2024 regulation that updated the EU’s 2014 eIDAS Regulation, sets for banks, telecoms and others to accept a wallet credential as valid identification. The clock started on 24 December 2024, when the implementing acts setting the wallet’s technical rules entered into force.

Most teams see this as a win for onboarding, since a customer who shares a verified credential never has to photograph a passport. That part is true, but the rest is not. 

You must register with your member state before a wallet will share anything. And every anti-money-laundering check you run today still runs after the credential arrives. This post covers what you register, what you must accept, and what the wallet does not do for your KYC file.

What is the EUDI Wallet under eIDAS 2.0?

The EUDI Wallet is a mobile app, issued or approved by each EU member state, that stores a person’s verified identity details and shares only the ones a service actually needs. It is the eIDAS 2.0 digital identity wallet created by Regulation (EU) 2024/1183, which updated the EU’s original 2014 eIDAS Regulation.

What the wallet stores and what it shares

The wallet holds government-issued identity data such as name, date of birth and nationality, alongside other credentials a trusted body has confirmed, for example, a driving licence or a professional qualification. The holder taps to share a credential rather than photographing a passport at signup.

The wallet can also confirm one fact without revealing the rest, which the regulation calls selective disclosure. An online gambling operator can be told the user is over 18 without ever receiving a date of birth, so you store less personal data and have less to lose in a breach.

Why a wallet from one country works in another

A wallet issued in Spain has to be accepted by a regulated service in Germany, at the same level of assurance, with no separate agreement between the two countries. If you operate in several EU markets, that means one acceptance path instead of a separate integration for every national eID scheme.

What are the EUDI Wallet deadlines, and which one applies to you?

The table below separates the government duty from the ones you carry.

Obligation Legal basis Who it applies to Date
Offer at least one EUDI Wallet, free of charge Article 5a, Regulation (EU) No 910/2014 as amended The 27 member states 24 months from 24 December 2024, so December 2026
Register before requesting data from a wallet Article 5b, with Implementing Regulation (EU) 2025/848 Any business that wants to use wallet data Rules in force since 27 May 2025
Accept the EUDI Wallet as a means of identification Article 5f, consolidated eIDAS text Named regulated sectors, excluding micro and small enterprises 36 months from 24 December 2024, so December 2027

December 2026 is the government’s deadline

The end of 2026 is when member states must make a wallet available. It creates no duty for you. What it does create is a supply of wallet-carrying customers about a year before you are legally required to serve them. Early-adopting markets will produce those users first, so a signup flow with no wallet option will hand them a document upload they don’t even need.

December 2027 is the deadline for regulated firms

The regulation does not name a date. Article 5f sets a countdown instead. It runs 36 months from the day the implementing acts entered into force, which was 24 December 2024. That puts the deadline in December 2027. When people refer to the EUDI Wallet deadline of 2027, this is the date they mean.

The article lists the sectors covered, including banking, financial services, telecommunications, transport, energy, health and education, and it exempts microenterprises and small enterprises. If you sit in one of those sectors, wallet acceptance stops being a product decision and becomes a compliance requirement on a date you do not set.

What is a wallet-relying party, and why do you have to register?

A wallet-relying party is any business that wants to request data from an EUDI Wallet. Under Article 5b you cannot simply build an integration and start asking. You register first, in the country where your business is established, and the wallet checks that registration before it releases anything.

What wallet-relying party registration involves

Implementing Regulation (EU) 2025/848, in force since 27 May 2025, requires every member state to run at least one national register of wallet-relying parties. Your entry has to carry the details listed in the regulation’s Annex I. That includes your legal name, a plain name a citizen will recognise on a consent screen, and an official identifier such as your national business register number or your legal entity identifier. You also state what service you provide and which identity data you intend to request.

You Have to Register Once

Registration happens in the country where you are established, not in each market you serve. That saves considerable work for firms operating across the EU. It also explains why the declared data list matters, because what you register sets the ceiling on what a wallet will later release to you. Under-declare and you close off use cases you may need in 2027.

What happens if you skip registration

Registration comes before the build, not after it. A wallet checks the register before it releases data, so until your entry is live, an integration is not of any use. Put it at the front of your EUDI Wallet readiness plan rather than at the end.

eIDAS 2.0 timelineDoes the EUDI Wallet replace KYC?

No. The wallet changes how identity evidence reaches you, and what you have to do with that evidence once it arrives stays the same.

What the wallet gives you

A presented credential answers the identification question with high confidence, because a trusted issuer already verified the data at a high level of assurance and signed it digitally so any later tampering shows up. Most of the forensic work in a document flow, such as image quality checks, security feature detection and manipulation analysis, drops out of that route.

What the wallet does not give you

Identification is only one input into a customer due diligence file. You still have to confirm the credential came from a trusted issuer, screen the holder against sanctions, politically exposed person and adverse media lists, apply your risk scoring, and keep monitoring the relationship afterwards. A credential tells you who somebody is, and you still have to decide whether you are allowed to onboard them.

EUDI Wallet KYC compliance in practice

Treat the wallet as a new way for customer data to arrive, feeding the decisioning layer you already run. EUDI Wallet KYC compliance usually fails when the wallet route grows its own screening rules, its own thresholds and its own record format, because you can then no longer show a regulator that one policy governed every customer.

Two mistakes that break EUDI Wallet readiness plans

Most systems will read a wallet credential without much trouble. The problems show up around it, where wallet users and everyone else meet the same signup flow. Two mistakes account for most of them.

Mistake one: the wallet replaces the document route instead of joining it

The mistake is rebuilding onboarding around the wallet alone. Most of your customers will not have a wallet for years. EU citizens are not required to hold one, national rollouts will take time, and customers outside the EU will never have one at all. A signup flow built only for wallets turns all of those people away.

The fix is to run the wallet as a second route. Accept a credential when the customer offers one, and fall back to document and biometric verification when they do not.

Mistake two: the two routes end up as separate systems

The mistake is treating wallet onboarding and document onboarding as two separate builds. Some customers will always decline the wallet. A tourist, a new resident, or someone who does not want the app still needs to open an account. If those customers run through a system that shares no logic and no records with your wallet flow, you end up with two sets of rules and two sets of evidence.

A supervisor will eventually ask a simple question. Which risk policy applied to this customer? You need one answer, backed by one audit trail, whichever route the customer took.

How Shufti helps you get EUDI Wallet ready

From December 2027, EU onboarding has to do two things at once. You have to accept a wallet credential from the customers who carry one and keep verifying everyone who does not, without running two disconnected systems and two sets of records.

Shufti’s electronic identity verification layer handles both routes through one integration. It authenticates natively at eIDAS Level of Assurance High and is EUDI Wallet compatible ahead of the December 2027 enforcement date, so a wallet credential and a document upload are decided by the same layer and leave one audit trail. The document route runs on Shufti’s own liveness engine, which holds iBeta Level 3 conformance under ISO/IEC 30107-3.

Map your wallet acceptance path against a live flow rather than a slide deck, then book a demo.

Frequently Asked Questions

Q: Is the EUDI Wallet mandatory for citizens?

No. Member states must offer a wallet free of charge, but using one is voluntary for the individual. Adoption will therefore be partial for years, which is why businesses still need a document-based route for every customer who does not present a wallet.

Q: When do banks have to accept the EUDI Wallet?

By December 2027. Article 5f gives private businesses the regulation names, including banking and financial services, 36 months from the entry into force of the eIDAS 2.0 implementing acts on 24 December 2024. Microenterprises and small enterprises are exempt.

Q: What is a wallet-relying party?

Any business that wants to request data from an EUDI Wallet. Under Article 5b of the eIDAS Regulation it must register in the country where it is established, state which identity data it will request, and appear in a national register before any wallet releases data to it.

Q: Does Shufti support qualified electronic signatures under eIDAS 2.0?

Yes. Shufti's QES flow verifies the signer, then issues a qualified certificate through an EU Trusted List qualified trust service provider, producing a signature legally recognised across all 27 member states. That infrastructure is also designed to accept EUDI Wallet credentials for certificate issuance.

Disclaimer: The information provided here is for general informational purposes only and should not be treated as legal, regulatory, or business advice. Shufti Pro Limited accepts no liability for decisions or actions taken in reliance on this information.

Join the
Shufti Sphere Newsletter

Get the latest trends, insights, and expert opinions on KYC, AML, fraud prevention, and more, straight to your inbox.

    Pitch a piece and get a verified byline in the Media room.

    Partnership Inquiries?
    Email us at [email protected]

    iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
    Copyright © 2026 Shufti. All rights reserved.