eIDAS 2.0: company obligations for the EUDI Wallet by 2027
7
Min
•
21.07.2026
In short: the eIDAS 2.0 regulation (Regulation (EU) 2024/1183) creates a European digital identity wallet, the EUDI Wallet. Each member state must offer at least one to its citizens by 24 December 2026. Then, from 24 December 2027, a large number of regulated companies will be required to accept this wallet when a user wants to use it to prove their identity. This obligation is not optional, it is not limited to a single channel, and it is not satisfied by accepting another digital identity instead.
Here is what this means concretely for your company, and how to prepare for it without rebuilding everything.
What eIDAS 2.0 says
eIDAS 2.0 is the common name for Regulation (EU) 2024/1183, which revises the European framework on electronic identification and trust services. Its central contribution: the European Digital Identity Wallet (EUDI Wallet).
The idea is simple to state. Every citizen, resident and company in the Union will be able to have a digital wallet, free and interoperable across the EU, to store and present proofs of identity and verified attributes (name, date of birth, diploma, licence, professional mandate, etc.). The user stays in control: they decide which information they share, with whom, and for what purpose.
To fully understand how the wallet itself works, its use cases and its architecture, you can read our pillar article: eIDAS 2.0: the European digital identity wallet, what you need to know.
The point that directly concerns companies lies elsewhere: the regulation does not just create a tool, it requires certain players to accept it.
Who is concerned (and from when)
This is the question that comes up most often: does my company have to accept the European wallet, and when?
The regulated sectors directly targeted
The acceptance obligation targets primarily players in sectors deemed essential, where proving one's identity reliably is a daily issue. The following are concerned:
- banking and financial services;
- healthcare;
- telecoms;
- energy;
- transport;
- education.
To this list are added the very large online platforms, that is, those with more than 45 million users in the Union.
Players subject to strong authentication
The scope does not stop at the sectors listed. Any private player required to carry out strong customer authentication (SCA), whether through a legal obligation or a contractual obligation, also falls within the scope of mandatory acceptance. In other words, if your activity already requires robust verification of your customers' identity, you must ask yourself the question starting today.
The date that matters: 24 December 2027
The timeline rests on two milestones. First, each member state must offer at least one interoperable wallet to its citizens by 24 December 2026. This is the phase of making the tool available.
Then, acceptance becomes mandatory for regulated players by 24 December 2027, that is 36 months after the implementing acts enter into force. It is by this deadline that the company concerned must be able to receive and verify a wallet presented by a user.
Three important clarifications, because these are the most frequent misunderstandings:
- the obligation is not optional;
- it is not limited to customer channels (it may concern journeys other than the simple purchase journey);
- it is not satisfied by accepting another digital identity instead. Offering your own identification solution does not exempt you from accepting the European wallet when the user chooses to use it.
What "accepting the wallet" means concretely
Accepting the wallet is not ticking a box. It is becoming what the regulation calls a relying party and integrating a new building block into your journeys. Here are the four aspects to anticipate.
1. Becoming a relying party
Your company must be able to request a proof of identity or an attribute via the wallet, and to receive the user's response. Technically, this means integrating the exchange protocols provided by the European framework into your onboarding, login or signature journeys.
2. Receiving and verifying attributes
Receiving information is not enough: you must verify its authenticity and validity. The wallet presents attributes cryptographically signed by trusted issuers. Your system must be able to check these signatures, ensure that the attribute has not been revoked, and reject an invalid presentation. This is the natural extension of an identity verification approach already in place in many companies: see our complete KYC guide.
3. Managing consent
The wallet puts the user at the centre. Each attribute sharing rests on their explicit consent. Your journey must therefore clearly display which data you request and why, obtain the person's agreement, and keep a record of this consent in an auditable way.
4. Registering in your member state
Private relying parties must register in their member state of establishment. This registration means declaring the purpose pursued and the data requested. It is an administrative step not to be underestimated, because it conditions the right to query the wallet.
To this is added a cross-cutting principle: minimisation. You must only request the attributes strictly necessary for your purpose. If a proof of majority is enough, you should not require the full date of birth. This principle protects the user and reduces your own exposure in the event of an incident.
The timeline to remember
Two dates structure your roadmap.
2026: making the tool available
By 24 December 2026, each member state makes at least one interoperable wallet available. This is the window during which you must frame your project, identify the journeys concerned and launch your integration work.
2027: mandatory acceptance
By 24 December 2027, acceptance becomes mandatory for regulated players. By this date, your company must be operational: able to receive, verify and process a wallet presentation, with proper registration and compliant consent management.
Between the two, there is therefore only a window of around twelve months to move from making the tool available to an integration truly in production. That is short for a company whose project cycles are counted in quarters.
How to prepare without breaking everything
The good news: accepting the European wallet does not mean throwing away your existing systems. It consists of adding a trusted identity channel alongside what you already do. Here is a pragmatic trajectory.
- Map your journeys. Identify where you verify an identity today: customer onboarding, account opening, login, signature, sensitive operations. These are your priority integration points.
- Confirm your status. Determine whether you fall within a targeted regulated sector or a strong authentication obligation. In case of doubt, treat the subject as if you were concerned.
- Prepare the registration. Anticipate the declaration of your purposes and the data requested with your member state, applying the principle of minimisation from now on.
- Strengthen your verification foundation. The wallet brings trusted attributes, but it does not replace fraud risk analysis, the checking of companies and their beneficial owners, or the assessment of solvency.
This is precisely where the wallet and a platform like Meelo complement each other. The wallet proves who the person is; fraud detection and KYB assess the risk associated with the transaction and its context. Meelo relies on more than 400 signals, behavioural analysis and device analysis to produce a decision in 2 to 5 seconds, documented and auditable: discover our approach to fraud score and identity verification.
For a detailed step-by-step roadmap, also read our article eIDAS 2.0: how to prepare.
In conclusion
eIDAS 2.0 is not a distant reform. The European wallet arrives at the end of 2026, and its acceptance becomes mandatory for many regulated players from 24 December 2027.
The obligation is clear: it is neither optional, nor limited to a channel, nor circumventable by offering another digital identity. The companies concerned have every interest in acting now: mapping their journeys, confirming their status, preparing their registration and strengthening their verification foundation.
Accepting the wallet is not rebuilding everything, it is adding a trusted identity channel and complementing it with solid risk analysis. Those who start early will turn a regulatory constraint into an operational advantage.
Sources: Regulation (EU) 2024/1183 (eIDAS 2.0); European Commission, European Digital Identity Wallet.
Accept the European wallet without rebuilding everything
National ID, European Wallet, NFC chip or document: Meelo picks the right check and plugs into your existing journeys.


.png)
.png)