eIDAS 2 Industries
eIDAS 2 for Very Large Online Platforms
What Platforms Need to Know
What the wallet acceptance obligation actually requires, and what platforms can do with it beyond compliance — verified accounts, age assurance and trader verification.
eIDAS 2 requires very large online platforms to accept the EUDI Wallet. This guide covers the requirements and the benefits the EUDI wallet provides for platforms beyond compliance.
Under eIDAS 2 (Regulation (EU) 2024/1183), a very large online platform that requires users to authenticate must also accept the EUDI Wallet as one of the ways they can do it. In practice that is a login option.
What is more interesting is what becomes possible once it exists. The same connection that signs a user in can confirm that an account really belongs to the person or company it names, that a user is above an age threshold, or that a trader is a registered business.
What changes for platforms
- Wallet acceptance becomes mandatory. Where a very large online platform requires authentication, it must accept the EUDI Wallet if a user chooses to use it.
- Account verification stops being a manual review. Whether an account really belongs to the person or company it names can be checked against authoritative credentials.
- Age can be checked without an ID document. Not required by eIDAS 2, but available.
- Companies and traders can be verified instantly. Business credentials replace uploaded registration documents.
| Date | Milestone | Relevance for platforms |
|---|---|---|
| 20 May 2024 | Regulation (EU) 2024/1183 enters into force | Legal framework established |
| End of 2026 | Member States must provide wallets | The point from which the acceptance obligation can apply |
A note on the date. eIDAS 2 gives private companies in named regulated sectors — banking, transport, telecoms and others — a three-year transition ending at the end of 2027. Very large online platforms are covered by a separate provision, and no equivalent transition appears in it. The practical trigger is therefore wallet availability at the end of 2026.
The roles very large online platforms play under eIDAS 2
| Role | What it means for a platform | Obligation |
|---|---|---|
| Verifier (relying party) | Accept wallets for authentication, and check credentials such as age or company details | Mandatory for auth; Optional otherwise |
| Issuer | Issue credentials into user wallets | Optional |
| Wallet provider | Offer a certified wallet | Optional |
Verifier: the role with the obligation
As a verifier, a platform requests and checks credentials from user wallets. This means registering as a relying party with the national registrar, declaring which data each service will request, and being able to check that credentials received are genuine, still valid, and belong to the person presenting them.
Issuer: optional
As an issuer, a platform can place credentials into user wallets.
Wallet provider: optional
As a wallet provider, a platform would offer the wallet itself. This means meeting the EU's highest security requirements and passing a formal conformity assessment.
Core platform use cases at a glance
| Use case | What the EUDI Wallet enables | Platform's role | Driver |
|---|---|---|---|
| Wallet login | Users authenticate with their wallet instead of a password | Verifier | Mandatory |
| Verified accounts and checkmarks | Confirm an account really belongs to the named person or company | Verifier | Optional; high value |
| Age assurance | Prove a user is over an age threshold | Verifier | Optional |
| Trader and seller verification | Verify companies against registration credentials, not uploaded PDFs | Verifier | Optional |
Wallet login
A user chooses to sign in with their wallet, the platform requests the minimum data it needs, and the user approves.
Four things are involved:
- Register as a relying party with the national registrar, and declare which data each service will request.
- Support the standard protocols and formats. Credentials are presented over OID4VP, in the mandated formats, SD-JWT VC or ISO/IEC 18013-5.
- Validate what comes back. Check the signature, check the credential is still valid, and check it belongs to the person presenting it.
- Keep the alternatives. Users are under no obligation to use a wallet and must not be restricted if they do not.
Verified accounts and checkmarks
Most large platforms offer some form of verified account — a checkmark confirming that an account really belongs to the person or organisation it names. It addresses a real problem: impersonating public figures, brands and businesses.
Today, account verification often relies on platform-specific document and evidence checks that can involve manual review.
Credentials make the check easy, automatable, and instantly verifiable:
For individual accounts, a user presents their identity credential and the platform confirms the account against a verified identity. No document upload and no review queue.
For business accounts, the platform can verify two things rather than one: that the company exists and is registered, and that the person operating the account has authority to act for it.
For marketplaces, the business half of this overlaps with trader verification below, and the same company credential covers both.
Age assurance
With the EUDI Wallet, very large online platforms can ask users to verify their age during onboarding or at a later stage. Because wallet credentials support selective disclosure, the platform does not need to request the user’s full credential or exact date of birth. Instead, it can request only confirmation that the user meets a specific age threshold, such as being over 18.
Trader and seller verification
For marketplaces, there is a second problem the same infrastructure solves.
Platforms that let traders sell to consumers have to know who those traders are, and today that mostly means collecting scanned registration documents and checking them by hand or through a vendor.
A company credential replaces it. A trader presents a credential attesting to their legal identity and registration, issued from an authoritative source, and the platform verifies it cryptographically. The same approach covers the signing authority of the person acting for the company — useful wherever a platform needs to know that the individual in front of it can bind the business.
This becomes more relevant as the proposed European Business Wallet advances, which would give companies a wallet of their own.
What the wallet does not replace
- Content moderation and platform safety. Knowing who holds an account says nothing about what they post. Moderation, risk assessment and safety obligations are entirely unaffected.
- Other obligations to minors. Age assurance is one measure among several. Design, defaults, reporting tools and recommender behaviour sit alongside it.
- Access for users without wallets. Users are under no obligation to hold a wallet and must not be restricted or hindered if they do not. Wallet-based options are additional routes, never the only one.
Build vs buy: how to build a compliant solution
Platforms face the same decision as every other organisation in the ecosystem: how much of the solution to build, and how much to buy. The user-facing experience — the sign-in flow, the account model, how checks are presented — is where a platform differentiates and will always be built in-house. The identity layer underneath — credential formats, exchange protocols, trust checks, revocation — is standardised by definition and changes every time the EU specifications evolve. For that layer, there are three possible implementation paths:
- Build apps, buy infrastructure (recommended) — build only the user-facing experience and use a proven, standards-compliant provider for the identity layer. Fastest time to market, lowest regulatory and technical risk.
- Build apps, own infrastructure — use open-source identity infrastructure to retain full control of the stack, while still avoiding implementing the credential formats, protocols, and trust validation from scratch.
- Build everything in-house — implement and maintain the full stack internally, and keep it current as the specifications evolve. Viable only for organisations with a dedicated identity engineering team.
Most organisations choose one of the first two paths. Platforms are among the few that could take the third, and the question is whether keeping credential formats and trust validation current is the best use of those engineers when the same result is available without it.
The walt.id solution
walt.id covers both of the first two paths. The walt.id Community Stack provides open-source issuer, verifier, and wallet infrastructure for organisations that want to own their stack; the walt.id Enterprise Stack is the managed offering on top of it — built on open-source technology used by more than +55.000 developers, governments, and businesses. For platforms specifically:
- Verifier — accept the EUDI Wallet for authentication, and verify identity, age and company credentials, with trust, revocation and wallet-authenticity checks handled automatically, and selective disclosure so each flow requests only what it needs.
- Cross-border by default — the same verification works for users and traders in every Member State, without country-by-country integration.
- Open source — privacy claims that can be inspected are easier to defend, to regulators and to users, than ones that cannot.
A role-by-role compliance breakdown is available in the eIDAS 2 Implementers Guide or reach out to our team to learn more.
Frequently asked questions
What does eIDAS 2 require very large online platforms to do?
Where a platform requires users to authenticate, it must also accept the EUDI Wallet as one of the ways they can do it.
Can the wallet be used for verified account badges?
Yes, for both individual and business accounts. For an individual, an identity credential confirms the account belongs to the named person. For a business, a company credential confirms the organisation is registered and that the person running the account has authority to act for it.
Is age verification required under eIDAS 2?
No. eIDAS 2 does not require age verification. Obligations around protecting minors come from separate EU rules, and age assurance is one way of meeting them. What eIDAS 2 provides is a better method: a proof of age that reveals nothing beyond the fact that a user is above a threshold.
Can platforms verify companies and traders this way?
Yes. A trader presents a credential attesting to their legal identity and registration, verified cryptographically against the issuing source, instead of uploading registration documents for manual review. The same approach can confirm that an individual has authority to act for the company.
What about users who don't have a wallet?
They must not be restricted or hindered. Wallet-based options are an additional route alongside whatever else a platform offers, never a replacement for it.
Continue exploring eIDAS 2
Build a compliant eIDAS 2 solution for online platforms
Accept the EUDI Wallet for authentication, verify accounts for people and businesses, and check age and company credentials — with trust, certificate, and revocation management handled for the platform. EU trusted. Standard & regulatory compliant. Gov & enterprise proven.