eIDAS 2 Industries

eIDAS 2 for Telecommunications

What Operators Need to Know

Tamino BaumannUpdated August 21, 2026

Wallet acceptance by end of 2027, cross-border sign-up, and reducing SIM-swap and porting fraud.

By the end of 2027, eIDAS 2 will require telecom operators to accept the EUDI Wallet for customer authentication where strong user auth is required. Beyond compliance, its trusted digital credentials can replace document scans, security questions, and manual checks across SIM swaps, number porting, contract sign-ups, and customer support. The result is stronger fraud prevention, faster customer journeys, and less pressure on support teams. This guide covers the deadline, the technical implications, and where wallet-based verification can generate the greatest return.


What eIDAS 2 changes for telecom operators

  1. Wallet acceptance by the end of 2027. Telecommunications is explicitly named as a sector that must accept the EUDI Wallet where strong user authentication is used.
  2. Onboarding stops needing document capture. Contract sign-up and SIM registration can be completed with a single credential presentation, online or in store, verified in seconds.
  3. Cross-border sign-up becomes straightforward. A customer from another Member State presents the same credential as a domestic one, and it verifies the same way.
  4. The weakest checks get replaced. SIM swap, porting and call-centre authentication stop depending on security questions and staff judgement.

The timeline:

DateMilestoneRelevance for operators
20 May 2024Regulation (EU) 2024/1183 enters into forceLegal framework established
End of 2026Member States must provide walletsCustomers begin holding wallets
End of 2027Acceptance deadline for telecommunicationsThe deadline for operators

The roles operators play

RoleWhat it means for an operatorObligation
Verifier (relying party)Accept wallets for contract sign-up, SIM registration, account access, SIM swap and portingBy end of 2027
IssuerIssue credentials into customer walletsOptional
Wallet providerOffer a certified walletOptional

Verifier: the role with the deadline

As a verifier, an operator requests and checks credentials from customer wallets. This means registering as a relying party with the national registrar, declaring exactly which data each service will request, and being able to check that every credential received is genuine, still valid, and belongs to the person presenting it.

This is the role the end-of-2027 deadline attaches to.

Note: The deadline applies only where strong user authentication is legally required. Strong user authentication means verifying a user’s identity using at least two independent factors, such as a password and a phone or biometric authentication.

Issuer: optional

As an issuer, an operator can place credentials into customer wallets — for example a confirmation of an active subscription, phone number ownership, or a customer entitlement. Nothing in eIDAS 2 requires this, still, it is worth knowing the option exists as it could further enhance various user journeys.

Wallet provider: optional

Providing a certified wallet means meeting the EU's highest security requirements and passing a formal conformity assessment. Every Member State must provide at least one, so customers will already have a wallet available to them. If wanted, operators can also provide the wallet.


Core telecom use cases at a glance

Use caseWhat the EUDI Wallet enablesOperator's roleDriver
Onboarding and SIM registrationIdentity verified in seconds, online or in store, without document captureVerifierMandatory role; highest volume
Cross-border customersCustomers from other Member States verified with the same process as domestic onesVerifierHigh value
SIM swap and portingVerification that cannot be socially engineeredVerifierHigh value; fraud
Account access and supportWallet-based authentication across app, web, retail and call centreVerifierMandatory
Business customersCompany identity and signing authority verified for B2B contractsVerifierOptional

Onboarding and SIM registration

In many Member States, activating a mobile subscription requires the operator to verify who the customer is. Today that usually means a document scan and a selfie, an in-store ID check, or both.

The costs. Verification vendor fees on every sign-up. A manual review queue for the cases automation cannot clear. Customers who abandon the process partway through. And a store of identity documents the operator has to keep, secure and eventually delete.

What changes. The customer presents an identity credential from their wallet. The operator verifies it cryptographically in seconds — same process online, in store, and through a partner or reseller. No photographs, no document authentication step, no review queue for the cases it could not handle.

Selective disclosure keeps the data footprint small. Most telecom processes need less than a full identity. Confirming a name, an age threshold and a country of residence is often the whole requirement. The wallet lets the operator request precisely those attributes, which means less personal data collected in the first place, and less to protect.


Cross-border customers

Cross-border onboarding is one of the clearest use cases for the EUDI Wallet.

A customer from another Member State walks into a shop or signs up online. Their ID document is in a language and format the operator's verification process may not handle well, the checks that work domestically often do not apply, and the result is either a manual exception process or a lost customer.

Wallets remove the distinction. Identity credentials from any Member State are issued at the same assurance level, verified against the same trust framework, and presented in the same format. An operator that can verify a domestic customer can verify any EU customer.

The opportunity is particularly relevant for operators with cross-border footprints or large numbers of mobile EU citizens and new residents. In these environments, wallet-based verification can reduce manual reviews, simplify onboarding, and prevent avoidable customer drop-off.


SIM swap and number porting

Why the current checks fail. Security questions can be researched. Forged identity documents can defeat manual inspection, and staff-controlled exception paths create an opening for social engineering. Even strong procedures can fail when back-end systems do not technically require successful authentication before completing the swap.

What changes. The customer authorises the change with a credential bound to their verified identity and to their device's secure hardware. This removes subjective staff judgement from the normal process, although secure recovery and tightly controlled fallback procedures are still required.


Account access, retail and the call centre

The acceptance obligation applies wherever an operator uses strong user authentication — which can be the app, the web account, and other assisted channels.

Four things are involved:

  • Register as a relying party with the national registrar, and declare which data each service will request. Wallets check requests against this registration.
  • Support the standard protocols and formats. Credentials are presented over OID4VP and in the required formats SD-JWT VC and ISO/IEC 18013-5.
  • Validate what comes back. Check the signature, check the credential is still valid, and check it belongs to the person presenting it.
  • Keep the alternatives. Customers who do not use a wallet must still be able to buy a subscription and manage their account.

Business customers

For B2B contracts, the same infrastructure verifies companies rather than people. A business customer's legal identity, registration details and the signing authority of the person in front of you can be verified from credentials instead of assembled from uploaded documents and register extracts.

This is worth watching alongside the proposed European Business Wallet, which would give companies a wallet of their own for interactions with public administrations and, in time, with suppliers.


Build vs buy: how to build a compliant solution

Whether acting as verifier, issuer, or both, an operator faces the same decision as every other organisation in the ecosystem: how much of the solution to build, and how much to buy. The customer-facing applications — the app, the web account, the retail journey — are where an operator differentiates and will always be built in-house or with existing partners. The identity layer underneath — credential formats, exchange protocols, trust checks, key management, revocation — is standardised by definition and changes every time the EU specifications evolve. For that layer, there are three possible implementation paths:

  • Build apps, buy infrastructure (recommended) — build only the customer-facing applications and use a proven, standards-compliant provider for the identity layer. Fastest time to market, lowest regulatory and technical risk.
  • Build apps, own infrastructure — use open-source identity infrastructure to retain full control of the stack, while still avoiding implementing the credential formats, protocols, and trust validation from scratch.
  • Build everything in-house — implement and maintain the full stack internally, and keep it current as the specifications evolve. Viable only for organisations with a dedicated identity engineering team.

The walt.id solution

walt.id covers both of the first two paths. The walt.id Community Stack provides open-source issuer, verifier, and wallet infrastructure for organisations that want to own their stack; the walt.id Enterprise Stack is the managed offering on top of it — built on open-source technology used by more than +55.000 developers, governments, and businesses. For telecommunications specifically:

  • Verifier — accept the EUDI Wallet for onboarding, SIM registration, account access, SIM swap and porting, across digital, retail and assisted channels, with trust, revocation and wallet-authenticity checks handled automatically and results passed to existing CRM and fraud systems during verification.
  • Cross-border by default — the same verification works for customers from every Member State.
  • Issuer — where an operator does want to issue credentials into customer wallets, in all mandated formats (SD-JWT VC, ISO/IEC 18013-5, W3C VC), with revocation built into the issuance workflow.
  • Wallet — where an operator or authority does want to embed wallet capabilities into an existing app, with flexible key management from on-device to HSM-backed.

A role-by-role compliance breakdown is available in the eIDAS 2 Implementers Guide or reach out to our team to learn more.


Frequently asked questions

When do telecom operators have to accept the EUDI Wallet?

By the end of 2027. eIDAS 2 (Regulation (EU) 2024/1183) names telecommunications among the sectors whose private relying parties must accept the EUDI Wallet where they are required to use strong user authentication.

Can we use the wallet for SIM registration?

Yes. A wallet presentation can be used, works identically online and in store, and handles customers from other Member States without a separate process.

What does accepting the wallet actually involve?

Registering as a relying party with the national registrar and declaring which data each service will request; supporting the standard presentation protocol and mandated credential formats; validating that credentials received are genuine, valid and belong to the person presenting them; and keeping existing routes available for customers who do not use a wallet.

How does it handle customers from other Member States?

The same way as domestic ones. Identity credentials from every Member State are issued at the same assurance level, verified against the same trust framework and presented in the same format.

Do operators have to issue credentials as well as accept them?

No. eIDAS 2 requires acceptance, not issuance. Issuing credentials into customer wallets is possible but optional.

Do we need to become a wallet provider?

No. The obligation to provide a wallet sits with Member States, and each must provide at least one. Becoming a certified wallet provider is optional.

What about customers who don't use a wallet?

They must still be able to buy a subscription and manage their account. Wallet acceptance is an additional option, never a replacement for existing routes.


Build a compliant eIDAS 2 solution for telecommunications

Accept the EUDI Wallet for onboarding, SIM registration, account access and porting — for customers from every Member State — with trust, certificate, and revocation management handled for you. EU trusted. Standard & regulatory compliant. Gov & enterprise proven.