[{"data":1,"prerenderedAt":727},["ShallowReactive",2],{"eidas2/identity-verification-providers":3},{"id":4,"title":5,"author":6,"body":7,"description":712,"extension":713,"meta":714,"navigation":715,"path":716,"publishedAt":717,"seo":718,"stem":719,"tags":720,"updatedAt":717,"__hash__":726},"eidas2Articles/eidas2/identity-verification-providers.md","eIDAS 2 for Identity Verification Providers: What IDV Vendors Need to Know","Tamino Baumann",{"type":8,"value":9,"toc":685},"minimark",[10,24,32,39,42,47,50,53,81,84,151,153,157,168,224,229,237,240,244,252,256,264,266,270,340,342,345,348,352,368,372,381,399,402,406,409,413,416,436,439,441,445,448,486,488,492,495,536,545,547,551,554,578,581,585,603,623,626,652,665,667,671,675,678,682],[11,12,13,18,19,23],"p",{},[14,15,17],"a",{"href":16},"/eidas2","eIDAS 2"," (Regulation (EU) 2024/1183) requires every EU Member State to provide a certified ",[14,20,22],{"href":21},"/eidas2/eudi-wallet","EU Digital Identity Wallet (EUDI Wallet)"," by the end of 2026, and requires businesses to accept it for user authentication and identification by the end of 2027.",[11,25,26,27,31],{},"The wallet holds a ",[28,29,30],"strong",{},"Person Identification Data (PID)"," credential issued at Level of Assurance High alongside any number of further credentials: driving licences, diplomas, proof of address, company representation powers, bank-issued authentication credentials.",[11,33,34,35,38],{},"Next to this, the regulation formalises a role that identity verification providers are best placed to fill: the ",[28,36,37],{},"intermediary",", a registered party that connects to wallets on behalf of their clients who want to be verifiers (relying parties).",[40,41],"hr",{},[43,44,46],"h2",{"id":45},"what-eidas-2-changes-for-identity-verification-providers","What eIDAS 2 changes for identity verification providers",[11,48,49],{},"eIDAS 2 entered into force on 20 May 2024 and obliges every EU Member State to provide at least one certified EUDI Wallet to citizens and residents by the end of 2026.",[11,51,52],{},"The four most important changes eIDAS 2 brings for identity verification providers:",[54,55,56,63,69,75],"ol",{},[57,58,59,62],"li",{},[28,60,61],{},"A new verification method."," Where a customer holds an EUDI Wallet, identity proofing becomes a single credential presentation: the user shares their PID, and the verifier validates it cryptographically in seconds.",[57,64,65,68],{},[28,66,67],{},"Customer demand from every regulated sector."," The banks, telecoms, insurers, platforms and public services that make up the IDV customer base must accept the wallet by the end of 2027 (public sector: end of 2026). This brings a great chance for the IDV provider to provide the solution.",[57,70,71,74],{},[28,72,73],{},"A formal role in the trust ecosystem."," eIDAS 2 defines intermediaries — parties that interact with wallets on behalf of relying parties. An IDV provider that verifies wallet credentials for its clients can operate inside the regulation as a registered intermediary.",[57,76,77,80],{},[28,78,79],{},"Verification beyond identity — and issuance."," The wallet carries far more than the PID, and each attribute can be verified for a fraction of the cost of a document check. At the same time, the clients that hold verified customer data — banks, insurers, employers, universities — gain the ability to issue credentials of their own, and will need someone to build it.",[11,82,83],{},"The compliance timeline is compact:",[85,86,87,103],"table",{},[88,89,90],"thead",{},[91,92,93,97,100],"tr",{},[94,95,96],"th",{},"Date",[94,98,99],{},"Milestone",[94,101,102],{},"Relevance for IDV providers",[104,105,106,118,129,140],"tbody",{},[91,107,108,112,115],{},[109,110,111],"td",{},"20 May 2024",[109,113,114],{},"Regulation (EU) 2024/1183 enters into force",[109,116,117],{},"Legal framework established",[91,119,120,123,126],{},[109,121,122],{},"5 December 2025",[109,124,125],{},"TS12 v1.0 published",[109,127,128],{},"Wallet-based Strong Customer Authentication specified — the first large issuance use case for bank clients",[91,130,131,134,137],{},[109,132,133],{},"End of 2026",[109,135,136],{},"Member States must provide certified wallets",[109,138,139],{},"Wallet holders appear in customer onboarding flows",[91,141,142,145,148],{},[109,143,144],{},"End of 2027",[109,146,147],{},"Acceptance deadline for regulated private-sector businesses",[109,149,150],{},"IDV customers must accept the wallet",[40,152],{},[43,154,156],{"id":155},"the-roles-identity-verification-providers-can-play-under-eidas-2","The roles identity verification providers can play under eIDAS 2",[11,158,159,160,164,165,167],{},"Every digital identity ecosystem has three actors — issuer, verifier, and wallet provider. An IDV provider rarely plays any of them for itself. It plays them ",[161,162,163],"em",{},"on behalf of its clients"," — and for the verifier role, eIDAS 2 gives that position a name: the ",[28,166,37],{},".",[85,169,170,183],{},[88,171,172],{},[91,173,174,177,180],{},[94,175,176],{},"Role",[94,178,179],{},"What it means for an IDV provider",[94,181,182],{},"Relevance",[104,184,185,198,211],{},[91,186,187,192,195],{},[109,188,189],{},[28,190,191],{},"Verifier (Intermediary)",[109,193,194],{},"Verify credentials from every wallet for every client",[109,196,197],{},"Core role",[91,199,200,205,208],{},[109,201,202],{},[28,203,204],{},"Issuance enabler for clients",[109,206,207],{},"Help clients issue their own credentials (e.g. a bank's SCA attestation) into customer wallets",[109,209,210],{},"Strategic",[91,212,213,218,221],{},[109,214,215],{},[28,216,217],{},"Wallet provider",[109,219,220],{},"Offer a certified wallet or embed wallet capabilities in a client's app",[109,222,223],{},"Optional",[225,226,228],"h3",{"id":227},"intermediary-the-core-role","Intermediary: the core role",[11,230,231,232,236],{},"As an intermediary, an IDV provider performs the ",[14,233,235],{"href":234},"/eidas2/verifier","verifier"," role for its clients: it registers with a national registrar, holds the access certificates wallets use to authenticate it, registers each client and their intended uses, sends presentation requests to wallets, and validates the credentials that come back. Under Article 5b(10) of the regulation, intermediaries acting on behalf of relying parties are deemed to be relying parties themselves.",[11,238,239],{},"Two things make this the core role. First, it is exactly what an IDV provider already is for its clients — the party that takes the verification problem off their hands — transposed into the wallet ecosystem. Second, it is use-case-independent: the same verification solution can be used from the verification of a PID for a bank's onboarding, an \"over 18\" proof for a gaming platform, a driving licence for a mobility operator, and an SCA attestation for a payment.",[225,241,243],{"id":242},"issuance-enabler-the-strategic-role","Issuance enabler: the strategic role",[11,245,246,247,251],{},"Under eIDAS 2, any business can become an ",[14,248,250],{"href":249},"/eidas2/issuer","issuer"," — and many IDV clients will have to. Wallet-based Strong Customer Authentication only works once a bank has issued an SCA attestation into the customer's wallet; insurers will issue proof of cover; universities will issue diplomas; employers will issue staff credentials.",[225,253,255],{"id":254},"wallet-provider-the-optional-role","Wallet provider: the optional role",[11,257,258,259,263],{},"As a ",[14,260,262],{"href":261},"/eidas2/wallet-provider","wallet provider",", an IDV provider offers the wallet itself, either as a standalone certified EUDI Wallet or as wallet capabilities embedded in a client's app.",[40,265],{},[43,267,269],{"id":268},"core-eidas-2-use-cases-for-idv-providers-at-a-glance","Core eIDAS 2 use cases for IDV providers at a glance",[85,271,272,288],{},[88,273,274],{},[91,275,276,279,282,285],{},[94,277,278],{},"Use case",[94,280,281],{},"What the EUDI Wallet enables",[94,283,284],{},"Provider's role",[94,286,287],{},"Driver",[104,289,290,307,323],{},[91,291,292,298,301,304],{},[109,293,294],{},[14,295,297],{"href":296},"#wallet-based-identity-verification","Wallet-based identity verification",[109,299,300],{},"PID presentation replaces document capture, liveness and video identification for wallet holders",[109,302,303],{},"Intermediary",[109,305,306],{},"Customer demand; mandatory acceptance for clients by end of 2027",[91,308,309,315,318,320],{},[109,310,311],{},[14,312,314],{"href":313},"#beyond-identity-the-attribute-verification-market","Attribute verification at wallet economics",[109,316,317],{},"Age, address, entitlements, licences and company powers verified for fractions of a cent",[109,319,303],{},[109,321,322],{},"New TAM",[91,324,325,331,334,337],{},[109,326,327],{},[14,328,330],{"href":329},"#issuance-for-your-clients-the-strategic-play","Issuance for clients",[109,332,333],{},"Build the issuer side for banks (SCA), insurers, employers and others",[109,335,336],{},"Issuance enabler",[109,338,339],{},"Required for SCA; strategic across sectors",[40,341],{},[43,343,297],{"id":344},"wallet-based-identity-verification",[11,346,347],{},"Today's remote verification chains together document capture, authenticity checks, liveness detection, biometric matching, and often a video call or manual review. With the EUDI Wallet, the same outcome is a single credential presentation.",[225,349,351],{"id":350},"what-the-pid-is","What the PID is",[11,353,354,355,361,362,367],{},"The PID is the core identity credential every certified wallet must hold. It is issued by a designated PID provider in each Member State, which — under Commission Implementing Regulation (EU) 2024/2977 — must verify the user's identity at Level of Assurance High before issuance. Receiving the PID is what activates the wallet. The PID contains the user's name, date of birth, place of birth and nationality, among other attributes, is issued in the mandated formats — ",[14,356,360],{"href":357,"rel":358},"https://docs.walt.id/concepts/digital-credentials/sd-jwt-vc",[359],"nofollow","SD-JWT VC"," and ",[14,363,366],{"href":364,"rel":365},"https://docs.walt.id/community-stack/concepts/digital-credentials/mdoc-mdl-iso",[359],"ISO/IEC 18013-5 (mdoc)"," — and is cryptographically bound to the wallet's secure keys.",[225,369,371],{"id":370},"how-a-verification-works","How a verification works",[11,373,374,375,380],{},"The verifier sends a presentation request over ",[14,376,379],{"href":377,"rel":378},"https://docs.walt.id/concepts/data-exchange-protocols/openid4vp",[359],"OID4VP"," (or ISO/IEC 18013-7 for remote mdoc flows), stating which attributes it needs. The wallet shows the user who is asking and for what, the user approves, and the wallet returns a presentation. The verifier then checks that:",[382,383,384,387,390,393,396],"ul",{},[57,385,386],{},"the credential was signed by an issuer on the EU trusted lists,",[57,388,389],{},"it has not been revoked or suspended,",[57,391,392],{},"it is bound to this wallet and was presented by its holder (holder binding),",[57,394,395],{},"the wallet itself is genuine and not revoked (Wallet Unit Attestation), and",[57,397,398],{},"the disclosed attributes match what was requested.",[11,400,401],{},"All of this is cryptographic. There is no document to inspect, no face to match against a photo, and no human in the loop. Because the PID was issued at Level of Assurance High, the result meets the identification requirements of the EU Anti-Money Laundering Regulation (Regulation (EU) 2024/1624), which recognises eIDAS-based electronic identification.",[225,403,405],{"id":404},"selective-disclosure-and-data-minimisation","Selective disclosure and data minimisation",[11,407,408],{},"The wallet lets the user share only the attributes a process requires — a date of birth without an address, or an \"over 18\" confirmation without a date of birth at all. For IDV providers this aligns wallet-based flows with GDPR data minimisation by default, and reduces the personal data the provider needs to handle.",[225,410,412],{"id":411},"what-the-wallet-does-not-replace","What the wallet does not replace",[11,414,415],{},"Wallet-based verification covers identity establishment for users who hold a wallet and are on a channel where they can present it. It does not replace:",[382,417,418,424,430],{},[57,419,420,423],{},[28,421,422],{},"Document-based verification"," for users without a wallet, non-EU customers, or channels where a wallet presentation is not possible — a fallback every provider will need for years.",[57,425,426,429],{},[28,427,428],{},"Fraud and risk signals"," around the transaction.",[57,431,432,435],{},[28,433,434],{},"Screening and monitoring"," — sanctions and PEP screening, risk scoring, and ongoing due diligence remain the relying party's obligation.",[11,437,438],{},"The practical picture is a verification platform with the wallet as a new method among several, selected per user and per channel.",[40,440],{},[43,442,444],{"id":443},"beyond-identity-the-attribute-verification-market","Beyond identity: the attribute verification market",[11,446,447],{},"At today's price per verification, a large class of checks is simply not done: they are cheaper to skip, self-declare, or accept the risk on. With a wallet presentation those checks become viable at a price point an order of magnitude lower:",[382,449,450,456,462,468,474,480],{},[57,451,452,455],{},[28,453,454],{},"Age assurance"," for gambling, alcohol, adult content, social platforms and age-restricted deliveries — an \"over 18\" proof without any identity data, repeatable on every transaction.",[57,457,458,461],{},[28,459,460],{},"Proof of address"," from the PID or a residence attestation, replacing utility bills and bank statements.",[57,463,464,467],{},[28,465,466],{},"Driving entitlement"," — categories and validity from the mobile driving licence, for rental, mobility and delivery platforms.",[57,469,470,473],{},[28,471,472],{},"Professional licences and qualifications"," — medical registration, diplomas, certifications — verified at hiring or on every engagement.",[57,475,476,479],{},[28,477,478],{},"Company representation powers"," — who is entitled to act for which legal entity, from business-wallet credentials, for B2B onboarding and contract signing.",[57,481,482,485],{},[28,483,484],{},"Coverage, entitlement and membership"," — proof of insurance cover, student status, employment — issued by one party and verified by another.",[40,487],{},[43,489,491],{"id":490},"issuance-the-strategic-play","Issuance: the strategic play",[11,493,494],{},"The clients of an identity verification provider hold some of the most rigorously verified personal and financial data in the economy. Under eIDAS 2 that data becomes issuable, and in several sectors issuance is not optional:",[382,496,497,512,518,524,530],{},[57,498,499,502,503,506,507,511],{},[28,500,501],{},"Banks"," must issue an ",[28,504,505],{},"SCA attestation"," into the customer's wallet before any wallet-based Strong Customer Authentication can take place; TS12 specifies the credential and the credential format. A bank offering wallet-based SCA is an issuer and a verifier at the same time. Beyond SCA, banks might issue account-ownership and KYC attestations. See the ",[14,508,510],{"href":509},"/eidas2/financial-services","eIDAS 2 guide for financial services"," for the full picture.",[57,513,514,517],{},[28,515,516],{},"Insurers"," can issue revocable proof of cover directly into customer wallets.",[57,519,520,523],{},[28,521,522],{},"Telecoms"," can issue subscriber and contract credentials that support cross-border sign-up and SIM-swap protection.",[57,525,526,529],{},[28,527,528],{},"Universities and employers"," issue diplomas, micro-credentials, student status and staff credentials.",[57,531,532,535],{},[28,533,534],{},"Public bodies"," issue official documents as PuB-EAAs with the legal weight of the paper original.",[11,537,538,539,544],{},"Every one of these clients faces the same build: register as an issuer in the trust infrastructure, issue via ",[14,540,543],{"href":541,"rel":542},"https://docs.walt.id/concepts/data-exchange-protocols/openid4vci",[359],"OID4VCI"," in the mandated formats, validate credential data against the applicable schema or rulebook, and operate revocation. Most will not build it themselves and that's where the opportunity lies.",[40,546],{},[43,548,550],{"id":549},"build-vs-buy-how-to-add-eudi-wallet-support-to-an-idv-platform","Build vs buy: how to add EUDI Wallet support to an IDV platform",[11,552,553],{},"Many aspects of an IDV platform — the SDKs, the workflow engine, the UX, the case management, the risk signals, the client integrations — are where a provider differentiates and will always be built in-house. The identity layer underneath the wallet — credential formats, exchange protocols, trust-list and wallet-authenticity validation, certificate lifecycle, revocation — is standardised by definition and changes every time the EU specifications evolve. For that layer, there are three possible implementation paths:",[382,555,556,566,572],{},[57,557,558,561,562,565],{},[28,559,560],{},"Build apps, buy infrastructure"," ",[161,563,564],{},"(recommended)"," — keep the platform, and embed a proven, standards-compliant identity layer for wallet issuance and verification. Fastest time to market, lowest regulatory and technical risk.",[57,567,568,571],{},[28,569,570],{},"Build apps, own infrastructure"," — use open-source identity infrastructure to retain full control of the stack, while still avoiding implementing the credential formats, protocols and trust validation from scratch.",[57,573,574,577],{},[28,575,576],{},"Build everything in-house"," — implement and maintain the full stack internally, and keep it current as the specifications evolve. Viable only for providers with a dedicated protocol engineering team.",[11,579,580],{},"Most providers choose one of the first two paths. The deadlines are fixed, engineers with deep experience in these protocols are scarce, and the underlying specifications are still moving.",[225,582,584],{"id":583},"the-waltid-solution","The walt.id solution",[11,586,587,588,592,593,597,598,602],{},"walt.id covers both of the first two paths. The ",[14,589,591],{"href":590},"/community-stack","walt.id Community Stack"," provides open-source issuer, verifier and wallet infrastructure for providers that want to own their stack; the ",[14,594,596],{"href":595},"/enterprise-stack","walt.id Enterprise Stack"," is the enterprise-grade platform on top of it — built on open-source technology used by more than ",[599,600],"developer-count",{"format":601},"long"," developers, governments and businesses. For identity verification providers specifically:",[382,604,605,611,617],{},[57,606,607,610],{},[28,608,609],{},"Verifier"," — verify PID and any other wallet-held credential as an intermediary on behalf of clients, with trust-list resolution, revocation, holder-binding and Wallet Unit Attestation checks handled automatically.",[57,612,613,616],{},[28,614,615],{},"Issuer"," — issue credentials on behalf of clients — SCA attestations, proof of cover, diplomas and more — in all mandated formats (SD-JWT VC, ISO/IEC 18013-5, W3C VC), with revocation built into the issuance workflow.",[57,618,619,622],{},[28,620,621],{},"Wallet"," — offer a certified wallet or embed wallet capabilities into a client's app, for providers that pursue the optional wallet-provider path.",[11,624,625],{},"In addition, the walt.id solution:",[382,627,628,634,640,646],{},[57,629,630,633],{},[28,631,632],{},"Works across countries and wallets"," — any certified EUDI Wallet. In every Member State.",[57,635,636,639],{},[28,637,638],{},"Works across industries and use cases"," — one deployment serves a bank, a mobility platform and an insurer alike, without a separate build per client or sector.",[57,641,642,645],{},[28,643,644],{},"Multi-tenant by design"," — hundreds of clients run as isolated tenants in a single Enterprise Stack deployment, each with its own keys, certificates and configuration.",[57,647,648,651],{},[28,649,650],{},"Fits the existing platform"," — API-first services that slot behind your existing SDK, workflow, case-management systems and integrate with different types of KMS/HSM solutions, storage solutions, and cloud providers.",[11,653,654,655,659,660,664],{},"A role-by-role compliance breakdown is available in the ",[14,656,658],{"href":657},"/white-paper/eidas2-implementers-guide","eIDAS 2 Implementers Guide",", or ",[14,661,663],{"href":662},"/contact","reach out to our team"," to discuss embedding walt.id in your platform.",[40,666],{},[43,668,670],{"id":669},"frequently-asked-questions","Frequently asked questions",[225,672,674],{"id":673},"what-is-an-intermediary-under-eidas-2","What is an intermediary under eIDAS 2?",[11,676,677],{},"Under eIDAS 2, an Intermediary is a special category of Relying Party that connects other organizations (which want to be a verifier) to EUDI Wallets on their behalf, essentially acting as a bridge that absorbs the technical, legal, and operational complexity of wallet interactions. Per Article 5b(10), Intermediaries are legally prohibited from storing any data about the transaction content — they must process and forward user attributes statelessly, deleting everything immediately after passing it to the end-Relying Party. Operationally, they're also responsible for presenting their own Access Certificate alongside the specific Registration Certificate of the end-Relying Party they're serving in each transaction, so the wallet can show the user both who is asking and why.",[225,679,681],{"id":680},"what-does-an-idv-provider-need-to-build-to-support-the-eudi-wallet","What does an IDV provider need to build to support the EUDI Wallet?",[11,683,684],{},"For verification: The solution must send credential presentation requests via OID4VP or ISO/IEC 18013-7, and validate returned credentials — in SD-JWT VC, ISO/IEC 18013-5, and W3C VC formats — against the EU trusted lists, including revocation status, holder binding, and Wallet Unit Attestation checks. For issuance: Providers must additionally support OID4VCI or ISO/IEC 18013-7, using the same credential formats, and manage the revocation status for any credentials they issue.",{"title":686,"searchDepth":687,"depth":687,"links":688},"",2,[689,690,696,697,703,704,705,708],{"id":45,"depth":687,"text":46},{"id":155,"depth":687,"text":156,"children":691},[692,694,695],{"id":227,"depth":693,"text":228},3,{"id":242,"depth":693,"text":243},{"id":254,"depth":693,"text":255},{"id":268,"depth":687,"text":269},{"id":344,"depth":687,"text":297,"children":698},[699,700,701,702],{"id":350,"depth":693,"text":351},{"id":370,"depth":693,"text":371},{"id":404,"depth":693,"text":405},{"id":411,"depth":693,"text":412},{"id":443,"depth":687,"text":444},{"id":490,"depth":687,"text":491},{"id":549,"depth":687,"text":550,"children":706},[707],{"id":583,"depth":693,"text":584},{"id":669,"depth":687,"text":670,"children":709},[710,711],{"id":673,"depth":693,"text":674},{"id":680,"depth":693,"text":681},"How eIDAS 2 and the EUDI Wallet change identity verification: wallet-based verification at Level of Assurance High, the intermediary role, new attribute-based use cases, helping clients become issuers, and how to add EUDI Wallet support to an IDV platform.","md",{},true,"/eidas2/identity-verification-providers","2026-09-02",{"title":5,"description":712},"eidas2/identity-verification-providers",[721,722,723,724,725],"eidas2 identity verification","eidas2 idv","eidas2 intermediary","eudi wallet verification","attribute verification","Zs1Fge4cX1FDwJMPL4JLCWz5cB7WScTCrSDoKpkL9rg",1789059003053]