eIDAS 2 Industries

eIDAS 2 for the Public Sector

What Governments Need to Know

Tamino BaumannUpdated August 19, 2026

eIDAS 2 (Regulation (EU) 2024/1183) requires public authorities to accept the EU Digital Identity Wallet (EUDI Wallet) as soon as wallets are available which is at the end of 2026. This guide covers the deadline, the roles public authorities play under eIDAS 2, issuing official documents as digital credentials, and how to build a compliant solution.


What eIDAS 2 changes for the public sector

eIDAS 2 entered into force on 20 May 2024. For public authorities, three changes matter most:

  1. Wallet acceptance, from the end of 2026. Every online public service that already uses electronic identification must also accept the EUDI Wallet once wallets are available.
  2. Every Member State becomes a wallet provider. Each Member State must provide at least one certified EUDI Wallet by the end of 2026.
  3. Official documents become digital credentials. Birth certificates, residence permits, tax IDs, driving licences, diplomas: authorities can issue these into citizens' wallets, where they carry the same legal weight as the paper original.

The compliance timeline:

DateMilestoneRelevance for public authorities
20 May 2024Regulation (EU) 2024/1183 enters into forceLegal framework established
19 November 2025European Business Wallet proposedA possible second acceptance obligation for company interactions; Still under development
End of 2026Member States must provide wallets and public services must accept themThe deadline for the public sector
End of 2027Acceptance deadline for the private sectorBanks, telcos, energy and other regulated sectors follow

The roles public authorities play

Most organisations under eIDAS 2 pick one or two roles. The public sector is different: it is regulator, infrastructure provider and user at the same time. In practice a national administration will end up covering most of the table below, though rarely in the same department.

RoleWhat it means for a public authorityObligation
Verifier (relying party)Accept wallets for login, onboarding and access to online public servicesMandatory, from the end of 2026
Wallet providerProvide at least one certified EUDI Wallet to citizens and residentsMandatory for Member States
PID providerIssue the core identity credential that activates every walletMandatory for Member States
Issuer of official documentsIssue certificates, permits, licences and other official documents into walletsOptional, but the highest-value opportunity
Registrar and supervisorRegister issuers and verifiers, publish trusted lists, supervise the ecosystemMandatory for Member States

Verifier

As a verifier, an authority requests and checks credentials from citizens' wallets. If a service already requires an eID login today, it has to accept the wallet as an option too.

This means registering as a relying party with the national registrar, declaring exactly which data the service will request, and building the technical ability to check that every credential received is genuine, still valid, and actually belongs to the person presenting it.

Wallet provider

Every Member State must provide at least one certified EUDI Wallet. There are three ways to do it: build and operate it directly, mandate an organisation to do it, or recognise a wallet built independently. The wallet must meet the EU's highest security level and pass a formal certification audit.

PID provider

Every wallet needs a Person Identification Data (PID) credential to be activated and usable. The PID credential holds the citizen's core identity — name, date and place of birth, nationality — verified at the EU's strictest assurance level (level of assurance high).

PIDs are issued by PID providers, which are organisations appointed by each Member State.

Issuer of official documents

Public authorities sit on the most rigorously verified data in the economy, and eIDAS 2 makes it issuable. A public body responsible for an official register can issue its documents into citizens' wallets as PuB-EAAs — attestation types that carry the same legal value as the paper original.

Civil registries, immigration and residence authorities, tax authorities, social security agencies, driver licensing authorities and public universities all fall into this category. A citizen who holds their residence permit, tax ID and driving licence in a wallet can present any of them, anywhere in the EU, in seconds.

Registrar and supervisor

Member States register the issuers and verifiers operating in their territory, publish the trusted lists that let everyone check each other's credentials, and designate the supervisory bodies that enforce the rules. This role has no commercial dimension, but it is a prerequisite for everything else in the ecosystem working.


Core public sector use cases at a glance

The table below summarises the main use cases; the sections that follow cover them in detail.

Use caseWhat the EUDI Wallet enablesAuthority's roleDriver
Access to online public servicesCitizens log in to any public service with one wallet, nationally and across bordersVerifierMandatory from end of 2026
Issuing official documentsCertificates, permits and licences issued into wallets with the legal value of the paper originalIssuerHigh value; optional
Signing applications and formsCitizens sign applications and declarations from the wallet, free of chargeVerifierHigh value; optional
Business interactionsCompanies identify, file documents and receive official notifications digitallyVerifierProposed, not yet law

Accepting the wallet for online public services

If a public service already asks people to identify themselves electronically today — a tax portal, a benefits application, a permit request, a municipal account — that service has to offer the EUDI Wallet as one of the ways to do it.

Why the public sector deadline comes first

The regulation treats public and private services differently. Private companies in regulated sectors were given a three-year transition, which lands at the end of 2027. For public services, wallet acceptance is written as a condition rather than a date: where a public authority requires electronic identification for an online service, it must also accept the wallet.

That condition can only be met once wallets exist, and wallets must exist by the end of 2026. So in practice the public sector deadline is the end of 2026.

What accepting the wallet actually involves

Four things:

  • Register as a relying party with the national registrar, and declare which data each service will request. Wallets check requests against this registration — asking for more than was registered will cause the wallet to warn the user and may cause it to refuse.
  • Support the standard protocols and formats. Presentation requests works via OID4VP. The credential formats for most attesations types are SD-JWT VC and ISO/IEC 18013-5, though some might also use W3C VCs.
  • Validate what comes back. Check the signature, check the credential is still valid, and check it genuinely belongs to the person presenting it.
  • Keep the alternatives. People who do not use a wallet must still be able to access the service. Wallet acceptance is an additional option, never a replacement for existing methods.

Selective disclosure works in your favour

The wallet lets citizens share only the data a process actually needs — proof of age without a full date of birth, residence in a municipality without a street address. For public authorities this is not just a privacy feature: it shrinks the amount of personal data a service collects and stores, which makes data protection compliance meaningfully easier.


Issuing official documents as digital credentials

Every authority that maintains an official register is sitting on data that citizens currently have to request, wait for, print and carry. eIDAS 2 turns that data into credentials citizens hold in their digital wallets.

Common examples:

  • Civil registries — birth, marriage and death certificates
  • Immigration and residence authorities — residence permits, visas
  • Tax authorities — tax IDs, income statements
  • Social security agencies — insurance numbers, health cards
  • Driver licensing authorities — driving licences, vehicle registrations
  • Public universities — degrees and diplomas

Credentials are delivered into wallets over OID4VCI, the standard issuance protocol. The authority registers as an issuer, signs its attestations with a qualified certificate, and operates a revocation mechanism so a credential can be invalidated when circumstances change.


Signing applications and forms

Every certified EUDI Wallet lets its holder create a Qualified Electronic Signature (QES) — the only electronic signature that carries the same legal effect as a handwritten signature across all EU Member States. For citizens signing for non-professional purposes, it must be available free of charge.

For public authorities this replaces a long tail of paper: applications, declarations, consents, appeals, contracts. The authority presents the document, the wallet creates the signature, and the authority receives a signed document it can validate cryptographically. Because the citizen's identity was already verified at the highest assurance level when their wallet was activated, there is no separate identity check for each signature.

Public bodies also have to be able to recognise advanced electronic signatures and seals in defined formats — a smaller obligation, but one that sits alongside this.


What is coming: the European Business Wallet

In November 2025 the Commission proposed a second wallet, aimed at companies rather than citizens. The European Business Wallet would let businesses identify themselves, submit documents and receive legally binding notifications from public administrations.

The most important point for public authorities:

  • Using it would be voluntary for companies, but accepting it would not be voluntary for public administrations. As proposed, public bodies would have 24 months from entry into force to accept business wallets for core functions.

Nothing here is settled, but it is worth knowing that the same infrastructure built for citizen wallets might also come for businesses.


What the wallet does not replace

Three things stay the responsibility of the authority:

  • Alternative access methods. Citizens cannot be required to use a wallet, and services must remain accessible to people who do not.
  • Your registers. The wallet is a way for citizens to carry and present data. It is not a replacement for the authentic sources that data comes from, which remain the authority's to maintain.
  • Your legal basis for processing. A citizen approving a data request in their wallet is not the same as a lawful basis under GDPR. Authorities still need their own, and still need to run data protection impact assessments where required.

It is also worth being clear about what the wallet is not: it does not replace national eID schemes. Existing notified schemes continue to work, and the framework was deliberately designed to build on them rather than start over.


Build vs buy: how to build a compliant solution

Whether acting as verifier, issuer, wallet provider, or all three, a public authority faces the same decision as every other organisation in the ecosystem: how much of the solution to build, and how much to buy. The citizen-facing applications — the portal, the service journeys, the wallet's look and feel — are where an authority differentiates and will always be built in-house or with existing partners. The identity layer underneath — credential formats, exchange protocols, trust checks, key management, revocation — is standardised by definition and changes every time the EU specifications evolve. For that layer, there are three possible implementation paths:

  • Build apps, buy infrastructure (recommended) — build only the citizen-facing applications and use a proven, standards-compliant provider for the identity layer. Fastest time to market, lowest regulatory and technical risk.
  • Build apps, own infrastructure — use open-source identity infrastructure to retain full control of the stack, while still avoiding implementing the credential formats, protocols, and trust validation from scratch.
  • Build everything in-house — implement and maintain the full stack internally, and keep it current as the specifications evolve. Viable only for institutions with a dedicated identity engineering team.

The walt.id solution

walt.id covers both of the first two paths. The walt.id Community Stack provides open-source issuer, verifier, and wallet infrastructure for institutions that want to own their stack; the walt.id Enterprise Stack is the managed offering on top of it — built on open-source technology used by more than +55.000 developers, governments, and businesses. For the public sector specifically:

  • Wallet — launch a certified citizen wallet or embed wallet capabilities into an existing government app, with flexible key management from on-device to HSM-backed, plus everything needed for the certified wallet-provider path.
  • Issuer — issue PIDs, LPIDs and official documents as PuB-EAAs in all mandated formats (SD-JWT VC, ISO/IEC 18013-5, W3C VC), with credential data validated against the official schemas, connections to authentic sources, and revocation built into the issuance workflow.
  • Verifier — accept the EUDI Wallet for login, onboarding and cross-border access, with trust, revocation, and wallet-authenticity checks handled automatically, and results passed to existing case management or registry systems during verification.

A role-by-role compliance breakdown is available in the eIDAS 2 Implementers Guide or reach out to our team to learn more.


Frequently asked questions

When do public authorities have to accept the EUDI Wallet?

As soon as wallets are available, which means the end of 2026. eIDAS 2 (Regulation (EU) 2024/1183) requires any online public service that already asks people to identify themselves electronically to also accept the EUDI Wallet.

Does the EUDI Wallet replace our national eID scheme?

No. Notified national eID schemes continue to operate, and eIDAS 2 was designed to build on them rather than replace them. The wallet is an additional option that authorities must accept alongside what they already offer.

Does every public authority need to build its own wallet?

No. The obligation to provide a wallet sits with the Member State, not with individual authorities, and each Member State only has to provide at least one. Individual authorities need to be able to accept wallets, which is a much smaller undertaking than providing one.

Can our registry issue official documents into citizens' wallets?

Yes. A public body responsible for an official register can issue its documents as PuB-EAAs — attestations that carry the same legal value as the paper original.

Do we still need to serve citizens who don't use a wallet?

Yes. Citizens cannot be required to use a wallet, and authorities must keep appropriate alternative solutions available. Accessibility requirements apply to wallet-based journeys as they do to any other public service channel.

What is the European Business Wallet and does it apply to us?

It is a proposed second wallet, for companies rather than citizens, published by the Commission in November 2025. If adopted as proposed, public administrations would have to accept it within 24 months of entry into force, while use by companies would remain voluntary. It is still going through the European Parliament and Council, so no authority should plan against a fixed date yet.

Build a compliant eIDAS 2 solution for the public sector

Accept the EUDI Wallet for citizen login and cross-border access, issue official documents into wallets, and launch a certified wallet — with trust, certificate, and revocation management handled for you. EU trusted. Standard & regulatory compliant. Gov & enterprise proven.