1. Confirm your obligation and scope
eIDAS 2 requires private relying parties that must use strong user authentication for online identification, under EU or national law, to accept the EUDI Wallet at the user's request. Banking and financial services are explicitly among the sectors concerned. Map where you identify or authenticate customers online: account opening, log-in, step-up authentication, and contract signing.
Acceptance is mandatory for you, but use is voluntary for customers. Existing onboarding methods can remain alongside the wallet.
2. Decide: build or buy
Most regulated firms will accept the wallet through their identity verification (IDV) or KYC provider, which handles protocols, certificates and wallet interoperability across Member States. Key questions to ask vendors:
- Which national wallets do you support today, and on what roadmap?
- Do you support both PID and electronic attestations of attributes?
- Can the wallet flow sit next to document-and-selfie verification as a fallback?
- How is pricing structured per verification versus current methods?
- How do you handle relying-party registration and access certificates?
Building in-house gives more control but requires sustained effort to keep up with evolving technical specifications.
3. Register as a relying party
Relying parties must register in the Member State where they are established and state the intended use of the wallet, including which data they will request. Wallets show users who is asking and why, and can warn them when a request goes beyond the registered purpose. Prepare the list of attributes you need per use case.
4. Implement the wallet protocols
The wallet ecosystem is defined by implementing acts and the Architecture and Reference Framework (ARF). In practice, remote presentation relies on standards such as OpenID for Verifiable Presentations (OpenID4VP), with credential formats such as ISO/IEC 18013-5 mdoc and SD-JWT VC. Plan for:
- Relying-party access certificates and trust list validation.
- Selective disclosure: requesting only necessary attributes.
- Same-device (mobile app, redirect) and cross-device (QR code) flows.
- Revocation checks and signature verification.
5. Align with AML and GDPR
The EU Anti-Money Laundering Regulation (Regulation (EU) 2024/1624), applicable from 10 July 2027, allows electronic identification means under eIDAS for customer due diligence. Update your AML/KYC policies, risk assessment and record-keeping to reflect wallet-based identification, and complete a data protection impact assessment where required.
6. Redesign the onboarding journey
- Offer "Continue with EU Digital Identity Wallet" as a clear, early option.
- Pre-fill forms with verified attributes and skip unnecessary steps.
- Keep fallbacks for customers without a wallet.
- Measure conversion, time-to-onboard and fraud rates per method.
7. Project plan to December 2027
| Period | Milestone |
|---|---|
| Q4 2026 | Scope assessment, vendor shortlist, budget |
| Q1 2027 | Vendor selection or build decision; relying-party registration |
| Q2 2027 | Integration and testing with available national wallets |
| Q3 2027 | AML policy update (AMLR applies 10 July 2027), pilot with customers |
| Q4 2027 | Full launch before 24 December 2027 |
Implementing acts, technical specifications and national roll-outs continue to develop. We update this guide regularly. This is general information, not legal advice.