The EUDI Wallet is the European digital identity wallet created by Regulation (EU) 2024/1183. Every member state must offer it to its citizens by 24 December 2026, and obliged private relying parties — large and medium-sized companies in regulated sectors — must accept it by 24 December 2027. Getting ready does not require rebuilding processes: it requires identity and signature to be configurable steps of your flows, and registering as a relying party declaring exactly which data you will request.
What the EUDI Wallet is (and what it is not)
The European Digital Identity Wallet is an application every member state must make available to its citizens, residents and businesses. It holds two things: the person's verified identity, issued at high assurance level, and a set of verifiable credentials — electronic attestations of attributes, in the regulation's language — that another body has certified: a qualification, a professional registration, a permit, a company power of representation.
What it gives the party on the other side of the digital counter is a difference in kind, not in degree. Today, to know whether someone is who they claim to be, you ask for a scan of their ID and run a video identification, or you demand a digital certificate half the population has never installed. With the wallet, the person presents the specific attribute and your system verifies it cryptographically against its issuer. No scans to file, no verification calls.
And there is a second piece that is easy to overlook: the wallet includes the ability to sign electronically with a qualified signature, free of charge for non-professional use. That instantly widens the number of people who can sign a contract with the highest legal validity without having gone through a certification authority first.
What it is not: it is not mandatory for citizens — use is voluntary, and they can keep identifying themselves with digital certificates, national eID or existing national schemes — it does not replace what you already have, and it is not a central registry where somebody watches your transactions. The regulation is explicit that the person controls what they share and with whom.
The real timeline: two dates that are not the same
Almost all the confusion about the EUDI Wallet comes from mixing two separate deadlines. The clock started with the implementing acts adopted by the Commission on 28 November 2024, which entered into force on 24 December 2024. From there:
| Date | What happens | Who it affects |
|---|---|---|
| 24 Dec 2024 | Implementing acts setting the common technical specifications enter into force. | Issuers, technology providers and certification bodies. |
| 24 Dec 2026 | +24 months: every member state must offer at least one wallet to its citizens and residents. | Public administrations: must accept it wherever they require electronic identification. |
| 24 Dec 2027 | +36 months: obliged private relying parties must accept the wallet at the user's request. | Large and medium-sized companies in the Article 5f sectors, plus very large online platforms. |
| Meanwhile | National pilots and integration testing. Several member states already distribute a wallet in test phase. | Any company that wants to arrive prepared. |
Translated into planning: 2027 is the compliance date, but 2026 is the decision date. Once the wallet is on millions of phones, customers will start trying to use it at onboarding before any law obliges you to accept it — and the experience of someone who tries and cannot is the same as a form that fails. For the full regulatory detail, see our eIDAS2 guide.
Is your company obliged to accept it?
Article 5f of Regulation (EU) 2024/1183 draws a fairly specific perimeter. You are obliged if all three conditions hold at once:
- Size: you are a large or medium-sized private relying party. Micro and small enterprises are expressly excluded.
- Strong authentication requirement: a legal rule or a contract requires you to authenticate the user strongly in order to provide your online service.
- Sector: you operate in transport, energy, banking and financial services, social security, health, drinking water, postal services, digital infrastructure, education or telecommunications.
On top of that, by their own route, come the public sector — obliged to accept it wherever it requires electronic identification for access to online services — and the very large online platforms designated under the digital services rules.
Even if your company is not on the list, the obligation can reach you through contracts. If you are a supplier, outsourcer or technology partner of an obliged entity, your client will pass the requirement down its supply chain — exactly as happened with GDPR and is happening with NIS2. It is worth reviewing 2027 tenders and contract renewals with that in mind.
And then there is the argument that appears in no article: whoever accepts the wallet earlier will cut their onboarding friction. Onboarding that completes by presenting a verified credential, with no ID photos to upload and no manual review to wait for, converts better than onboarding that does not.
What almost nobody looks at: you must register as a relying party
The conversation about the wallet usually stops at "when do I have to accept it". But the regulation includes a prior requirement with more operational consequences: to request data from a wallet you must be registered as a relying party in the member state where the company is established.
That registration is not a mere administrative formality. You must declare:
- Who you are, with the official data that lets wallets identify and authenticate you.
- How to contact you, so that users and authorities know where to complain.
- Which data you will request and for what intended use. And here comes the important part: you may not request data from users other than what you declared.
The registered information is published in a machine-readable, electronically signed format, so the wallet itself can check, before handing anything over, whether the party asking has the right to ask. It is data minimisation applied automatically: the old habit of asking for the full ID document "just in case", when all you need to know is whether the person is of age, stops being possible.
The practical consequence is that before integrating anything you need an inventory: which data each of your onboarding forms asks for, what it is really used for and which fields are surplus. It is the same exercise GDPR demands, except that now it is declared publicly and checked technically.
The three processes where the wallet will show up first
If you are wondering where to start, look at where your company spends the most time today checking who somebody is:
- Customer onboarding and KYC. The flagship use case. A verified identity credential replaces document uploads, video identification and the manual review that follows. The process goes from hours or days to seconds, and the file ends up with better evidence than a scan.
- Contracting and document signature. With a qualified signature available in the wallet itself, the universe of people who can sign with the highest guarantee — with no prior paperwork — widens sharply. If you have already measured the return on electronic signature versus paper, this is the next step up.
- Access, representation and professional attributes. The most underestimated part: proving that somebody holds a company mandate, a qualification or membership of a professional body. Today that is handled with certificates, extracts and emails; with the wallet it is a verifiable attestation, on the spot.
Note that none of the three is "an identity project". All three are business processes in which one step changes. Which is why the right question is not "which identity provider do I pick?" but "can my processes change identity method without touching anything else?".
How Dokuflex handles it: identity and signature as process steps
Whether you reach 2027 with a configuration change or with a project depends on an architectural decision taken today: whether identification lives inside each application or is a step of the workflow.
In Dokuflex, onboarding, contracting and authorisation processes are modelled in low-code BPM, and inside them:
- The identification and signature method is configurable. Digital certificate, biometric signature, advanced or qualified signature coexist in the same flow; adding a new method means changing a step's configuration, not rewriting the process.
- Evidence is filed with the case. Who identified whom, with which method, when and on which document stays in the process history — exactly what an audit or a dispute will ask you for.
- The data you request is declared in the process form, not scattered across integrations. That makes the "what do I ask for and why" inventory — the one you need to register as a relying party — a query rather than an archaeological dig.
- Your own people's access is identity too. Corporate SSO and passkeys cover the internal side while the wallet covers the external one.
Put plainly: getting ready for the EUDI Wallet does not mean buying an EUDI Wallet. It means no longer having identity welded into your processes — and that pays off from day one, long before December 2027.
Book a demo and we will walk through your onboarding process step by step →
Checklist: six things you can do this quarter
- Decide whether you are obliged — and write it down. Size, sector and strong authentication requirement. If the answer is "no", still check whether your obliged customers will require it contractually.
- Inventory what you ask for at each onboarding. Field by field, with its purpose. It is the input for relying party registration and, incidentally, three or four fields nobody has used in years almost always turn up.
- Find where identity is hard-wired. How many different systems identify a customer today? Each one is a place where the wallet will have to be integrated unless you centralise.
- Measure your current onboarding. Time to effective activation, share of files needing manual review, drop-off at the identification step. Without that "before", you will not be able to demonstrate the "after".
- Talk to your signature and identity provider. Ask about their European wallet roadmap and whether their integration forces you to change the process or only the configuration. The answer tells you a lot.
- Pilot with a small process. An internal onboarding, a supplier authorisation. The goal is not to be wallet-ready: it is to verify that you can change a process's identity method without opening a project.
Frequently asked questions
What is the EUDI Wallet and what is it for in a business context? +
The EUDI Wallet is the European Digital Identity Wallet created by Regulation (EU) 2024/1183 (eIDAS2). It is an application every member state must offer, allowing a person to identify themselves at high assurance level, present verified credentials (identity, qualifications, professional registration, powers of representation) and sign electronically across the EU. For a company, it is a way to check who is on the other side and with which attributes, without asking for ID scans or running video identification.
When does accepting the EUDI Wallet become mandatory? +
The regulation's implementing acts entered into force on 24 December 2024. Two clocks then run: 24 months for each member state to offer at least one wallet to its citizens (24 December 2026) and 36 months for obliged private relying parties to accept it (24 December 2027). The public sector must accept it wherever it requires electronic identification for online services.
Is my small company obliged to accept the European wallet? +
Probably not directly. Article 5f expressly excludes micro and small enterprises and limits the obligation to large and medium-sized private relying parties that are subject to a legal or contractual requirement for strong user authentication and operate in transport, energy, banking and financial services, social security, health, drinking water, postal services, digital infrastructure, education or telecommunications. That said, if you supply those companies, the requirement will reach you contractually even though the law does not name you.
What does a company have to do to be able to request data from the wallet? +
Register as a relying party in the member state where it is established, declaring who it is, how to contact it and which data it intends to request. That registration is published in a machine-readable, electronically signed format, and the regulation prohibits asking users for data other than what was declared. In practice it forces a data minimisation exercise before you connect anything.
Does the EUDI Wallet replace digital certificates or national eID schemes? +
It does not replace them: it adds to them. Digital certificates, national eID cards and existing national identification schemes remain valid, and for citizens the wallet is voluntary. What changes is that obliged entities will not be able to refuse it when a user chooses to use it, so it is best treated as one more identification and signature method inside your processes, not as a migration.
Do we have to rebuild onboarding and signing processes to accept the wallet? +
Only if identification and signature are hard-wired inside each application. If your onboarding, contracting and signature flows are orchestrated in a BPM and the identity method is a configurable step of the process, adding the wallet is a configuration change: it appears as an option alongside the digital certificate or biometric signature, and the evidence is filed exactly as before.
Official sources
- Regulation (EU) 2024/1183 — amends Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework (Articles 5a, 5b and 5f).
- EU Digital Identity Wallet — European Commission technical space with the architecture and reference framework and the relying party programme.
Make changing the identity method configuration, not a project
Book 30 minutes: we review your onboarding and signature processes, see where identity is hard-wired today and leave with a plan so that accepting the European wallet — or any new method — is a matter of configuring one step.