The EUDI & Wallet Playground: test real wallet flows in your browser for free. Try it now
Olga Mędraś
Olga Mędraś

How eIDAS 2.0 affects private relying parties and SCA | Authologic Legal Analysis

Last updated: 17 August 2026

eIDAS 2.0 obliges private relying parties from the Art. 5f sectors to accept the EUDI Wallet wherever the law requires strong user authentication - from December 24, 2027, one year after every Member State must provide at least one wallet.

This Authologic analysis covers what that means in practice: the registration duty, the shift from PSD2 to PSR, free qualified signatures for citizens, and the architectural choices the deadline forces.

eIDAS 2.0 and SCA legal analysis title card with a map of Europe

Key takeaways

  • Two deadlines define the transition: by December 24, 2026 every Member State must provide at least one EUDI Wallet; from December 24, 2027 private relying parties from the Art. 5f sectors must accept it wherever the law requires strong user authentication, if the user wants to use it.
  • The acceptance mandate defines only the minimum: the Commission expects wallet infrastructure, once built, to spread into use cases far beyond the mandatory catalog.
  • Relying parties should be registered in their Member State of establishment, declaring the purpose of use and the data they will request.
  • By 2027, SCA in payments will be governed mainly by the Payment Services Regulation (PSR) in combination with eIDAS 2.0 - not by PSD2.
  • "One wallet per country" is the floor: both governments and accredited private entities can issue wallets, so integration planning should assume a minimum of 27 national wallets plus commercial ones.

The calculated bet on EUDI Wallet adoption

There is a clear logic behind the eIDAS 2.0 framework that redefines digital security.

One of its primary objectives is to ensure that Strong Customer Authentication (SCA) is used wherever secure identification is essential.

In simplified terms, the EU legislator requires high-assurance authentication whenever SCA is mandated under Union law, national law, or contractual obligations.

EU Digital Identity Wallet logo

To ensure this SCA is accessible to everyone, the relevant entities will be obliged to accept electronic identification via European Digital Identity (EUDI) Wallets.

Why?

Because the Wallet is inherently secure and carries the highest level of assurance. Consequently, in the specific sectors outlined in the regulation (see: Art. 5f of eIDAS 2.0), the mechanism is mandatory; elsewhere, it remains optional.

At the same time, eIDAS 2.0 defines only the minimum use cases in which the EUDI Wallet must be accepted.

This reflects a broader regulatory strategy: once organisations build the infrastructure required to support wallet-based authentication, they may begin to use it in other digital processes as well.

The wallet is intended to combine a high level of assurance with a superior user experience compared with many traditional verification methods, making it attractive for wider use.

EUDI Wallet as an adoption catalyst

The European Commission describes this mechanism as a "catalyst for broad deployment." How widely it is adopted will depend on how the wallet evolves and what additional credentials are integrated over time.

In the early stages, the EUDI Wallets will primarily contain the Personal Identification Data (PID). On its own, the PID might not be attractive enough to trigger mass adoption, and there is no single legal provision to force that momentum.

Yet, the true potential lies in what we integrate into advanced processes later.

This will entice entities outside the mandatory catalog - and in areas beyond those explicitly mentioned in eIDAS 2.0 - to join the ecosystem.

As a result, not only the electronic identity system but the entire landscape of remote transactions, underpinned by a secure wallet, will experience exponential growth.

Key objectives of eIDAS 2.0

Let us just imagine a world where the friction of managing dozens of passwords, physical cards, and fragmented accounts simply vanishes.

In its place is a single, secure digital wallet on your smartphone - your gateway to logging in, identifying yourself, and managing your most sensitive credentials with total control.

This is the core idea behind the EUDI Wallet.

With the introduction of the EUDI Wallet, your smartphone becomes a secure hub for your digital identity.

From official documents to private services, the EUDI Wallet ensures seamless, secure access and data sharing throughout the European Union.

Practical implications of the new infrastructure

Area

What changes

User autonomy

Member States provide a mobile wallet storing identity data and credentials (diplomas, licences); users decide what to share and keep control over their information

SCA processes

The wallet can be used for online identification and SCA where required by EU law, national law or contract; it must support high-assurance authentication

Issuers and verifiers

Issuers (public authorities or authorised entities) place credentials in the wallet; verifiers must accept the wallet when a user chooses to present it

Data minimisation

Verifiers may request only data necessary and proportionate for the service; users can share selected attributes and, where allowed, use pseudonyms

Sectoral obligations

Providers in the Art. 5f sectors (banking, telecom, energy, transport, education, health and others) must accept EUDI Wallets when strong authentication is legally required

Interoperability

Wallets and relying systems work across all Member States under common standards - no separate national setups for cross-border use

Oversight

Each Member State appoints bodies supervising compliance and managing trust lists, with cross-border coordination

Digital wallets vs payment wallets - is market consolidation inevitable? 

One could even go so far as to say that we are witnessing a reversal of the expected trend:

Payment wallets may gradually be absorbed into identity wallets, rather than the other way around

Payment wallets may gradually be absorbed into identity wallets, rather than the other way around. Identity wallets will start as tools for secure identification, but over time their functionality and accepted credentials may expand to include payments and other services.

This transition will take time, though, and users are likely to have several wallet options available, from which they may choose a single solution covering both identity verification and payments.

In practice, it signals the need for large-scale technical and regulatory overhauls for entities mandated to apply Strong Customer Authentication (SCA).

What are the two critical eIDAS 2.0 deadlines?

December 24, 2026

By December 24, 2026, the mandate to introduce at least one EUDI Wallet per Member State will come into effect.

It is intended to be an electronic identification at the "high" level of assurance (LoA), fulfilling security requirements, built on open-source licenses, provided free of charge, and capable of issuing qualified electronic signatures.

December 24, 2027

Subsequently, on December 24, 2027, the obligation for certain private relying parties to accept the EUDI Wallet will take effect.

Taking as an example the payment service sector, this would mean that payment service providers will essentially become "private relying parties" within the meaning of eIDAS 2.0, meaning a natural or legal person that relies upon electronic identification or a trust service.

Date

Obligation

Who it binds

December 24, 2026

At least one EUDI Wallet per Member State: assurance level "high", free of charge, open-source based, capable of qualified electronic signatures

Member States

December 24, 2027

Acceptance of the EUDI Wallet wherever the law requires strong user authentication, upon the voluntary request of the user

Private relying parties from the Art. 5f sectors

What that obligation changes for customer due diligence under the AMLR is covered in How Will the EUDI Wallet Change KYC?.

What is the relying party registration duty?

What is also crucial?

Private relying parties will be subject to the obligation to register in the Member State of establishment as a relying party accepting the EUDI Wallet (including a statement of the purpose for which they use the EUDI and the data to be obtained through the EUDI).

The obligation itself follows from eIDAS 2.0; the implementing rules govern how the register works. Commission Implementing Regulation (EU) 2025/848 applies from December 24, 2026 and requires every Member State to run a national register of wallet-relying parties - available through a website and a common API, in human-readable and machine-readable form. The registered scope matters in practice: it defines the data a relying party has declared it will request.

Importantly, the EUDI is to support common protocols and interfaces, among others, for the purpose of transmitting and presenting data to the relying party, authenticating relying parties through the implementation of authentication mechanisms, or verifying the authenticity and validity of the EUDI by relying parties.

To check your own position across both regimes, use the SCA & AMLR Readiness Checklist.

Free QES for all citizens - a major step toward universal digital accessibility

The EUDI Wallet also changes how natural persons can use Qualified Electronic Signatures (QES) for non-professional purposes.

QES accessible by default and free of charge

Individuals who hold a European Digital Identity Wallet can create a QES by default and free of charge, without having to undergo additional administrative procedures.

The Wallet also enables the signing or sealing of personal statements and verified attributes.

This broader availability of QES will definitely affect the current market for qualified trust service providers.

As the only digital format legally equivalent to a handwritten signature, the QES is the gold standard for agreements, the EUDI Wallet transforms this experience by offering a frictionless way to trigger a QES.

Who should keep a close eye on eIDAS 2.0?

Wheel of nine EUDI transition sectors: banking and finance, telecoms, powers of attorney, HR and recruitment, insurance, healthcare, logistics, education, age-restricted retail and digital platforms

Sector

What the wallet enables

Art. 5f acceptance mandate?

Banking & finance

Remote account opening and simplified Customer Due Diligence with notified eID means and integrated QES

Yes

Telecoms

Zero-friction identity checks for instant SIM registration and service agreements

Yes

Healthcare

Secure, tamper-proof exchange of verified medical data, prescriptions and patient authorisations

Yes (health)

Education

Digital diplomas and academic credentials, instantly verifiable across Member States

Yes

Transport & logistics

Real-time identity management and digital authorisation for drivers, staff and site access

Transport: yes; private logistics operations: outside the catalog

Age-restricted retail & digital platforms

Automated, privacy-first age verification through attestation of selected attributes

Not in the catalog (age-verification duties arise from separate rules); VLOPs under the DSA are covered where they require user authentication

Insurance

Compliant digital claims and applications with seamless identity proofing

Not listed explicitly (may fall under financial services)

HR & recruitment

Legally binding digital employment contracts and cross-border onboarding

No - voluntary adoption

Powers of attorney

Electronic attestations of attributes with the legal effect of paper documents, verifiable cross-border

Cross-cutting capability, not a sector

Why is early adoption key?

A further question arises:

How will payment service providers adapt to accepting not only the 27 mandatory EU national wallets but also, inevitably, numerous other identity solutions?

The fact that each Member State is required to implement its own national EUDI wallet, it does not mean:

  • There will be only one wallet available per country;
  • It excludes the development of commercial ID wallets (in fact, the opposite is true).

Given that these wallets are not limited to the public sector, they may be issued by both government authorities and accredited private entities, one must be prepared to integrate with a minimum of 27 national wallets across the EU, alongside an unlimited number of accredited commercial wallets coming soon.

How to prepare for that multiplication without rebuilding is covered in The simplest way to implement the EUDI Wallet is the one you don't rebuild later.

Universal EUDI integration: 27+ national Member State wallets versus an unlimited number of accredited private wallets

On top of that, eIDAS 2.0 sets deadlines, while many countries will be ready before those deadlines. Our study of eID app adoption shows how far that process has already gone.

Therefore, it is important to realize that adoption has already started.

Simplifying it: the first deadline is set for the end of December 2026, and every EU member state should release their wallet by that date.

12 months later, another deadline kicks in: to accept wallets.

Ultimately, it is a matter of internal strategy: companies must decide whether to embrace these wallets as they launch or risk falling behind more agile competitors.

EUDI Wallet integration and the new PSR rules

It is worth bearing in mind that by 2027, Strong Customer Authentication (SCA) will no longer be governed by the Revised Payment Services Directive (PSD2), but mainly by the Payment Services Regulation (PSR), in combination with eIDAS 2.0.

The legal framework for payment authentication will therefore be directly applicable across Member States and closely linked to the European Digital Identity (EUDI) infrastructure.

Consumers will have the right to use the EUDI Wallet to perform SCA, particularly for remote account access and electronic payment initiation.

From PSD2 to PSR: mandatory EUDI integration for remote SCA

Banks, selected fintech companies, and payment service providers will need to ensure that their authentication systems support wallet-based SCA, including building secure and convenient cross-application authentication flows in mobile environments.

It is important to note that this obligation applies only to remote scenarios.

The requirement to accept the EUDI Wallet for SCA does not extend to in-person transactions at point-of-sale terminals or ATMs. Existing SCA methods remain applicable in those contexts.

The complexity lies in the implementation phase.

Particularly in aligning EUDI-based authentication with PSR requirements such as secure credential storage and mandatory dynamic linking.

Architectural choices for 2027 compliance

And one more thing:

While users remain free to choose whether to authenticate through the wallet or through existing channels, regulated entities must ensure that the wallet option is available wherever Strong Customer Authentication is required.

In practice, this means that architectural design, system integration, and compliance alignment must be completed in advance, as readiness will ultimately depend on technical implementation rather than policy declarations. The EUDI Wallet Readiness Checklist turns that readiness into 20 concrete questions.

The vocabulary of those choices - routing, fallback, eID-native architecture - is defined in the Identity Orchestration Glossary.

FAQ

When does EUDI Wallet acceptance become mandatory?

From December 24, 2027, for private relying parties from the Art. 5f sectors, wherever the law requires strong user authentication and the user wants to use the wallet. Member States must provide wallets a year earlier, by December 24, 2026.

Which sectors does the acceptance mandate cover?

The Art. 5f catalog: among them transport, energy, banking and financial services, social security, health, drinking water, postal services, digital infrastructure, telecommunications and education - plus very large online platforms designated under the DSA, where they require user authentication.

Does the acceptance mandate cover in-person payments?

Not in payments. The requirement to accept the EUDI Wallet for strong customer authentication applies to remote scenarios, so in-person point-of-sale and ATM transactions are out of scope and existing SCA methods remain applicable there. This is a payments-specific limit rather than a general rule: the wallet can also be used in offline and in-person contexts where Union or national law provides for it.

Do relying parties have to register?

Yes. From December 24, 2026, relying parties should be registered in their Member State of establishment, declaring the intended use of wallet data and the exact data they will request.

How does Authologic help relying parties prepare?

Authologic's orchestration platform connects EUDI Wallets alongside 91 identity methods across 84 providers (as of August 2026) through a single API - with relying party certificate handling, routing and fallback managed by the platform, so wallet acceptance is a configuration, not a rebuild.


Changelog

  • 17 August 2026 - Added key takeaways, milestone, practical implications and sector tables, FAQ, registration details under CIR (EU) 2025/848, and links to related resources.
  • March 5, 2026 - Initial publication.

Share article

Text of this article
Media in this article

Press Contacts