EUDI Wallet: December 2026 Deadline - EADTrust
Inicio > EUDI Wallet > December 2026: The Deadline Your Company Cannot Ignore

December 2026: The Deadline Your Company Cannot Ignore

December 2026 EUDI Wallet

Suscríbete:

There is a date in the European regulatory calendar that is not yet on the radar of most Spanish organisations but will affect virtually every company with more than fifty employees providing services in regulated sectors. 24 December 2026 is the deadline established by Regulation (EU) 2024/1183 (eIDAS 2.0) for the European Digital Identity Wallet (EUDI Wallet) to be operational in every Member State and accepted by public administrations as a means of identification. Twelve months later, on 24 December 2027, the obligation to accept it extends to the regulated private sector.

If you are responsible for IT, legal, compliance or digital transformation in a Spanish banking, telecommunications, energy, transport, healthcare, insurance or education company, these two deadlines should already be included in your planning. Not as future dates to assess, but as specific deadlines involving technical and legal obligations that require preparation time. Less than it may seem.

Terms relating to EUDI Wallet deadlines

Implementing act

A regulation adopted by the European Commission establishing the specific technical specifications for implementing the general Regulation. The eIDAS 2.0 implementing acts define the protocols, formats and interfaces that all participants in the EUDI ecosystem must comply with.

Wallet-relying party

A public or private organisation that requests and verifies attributes from users presenting their EUDI Wallet. It must be registered in the national relying-party system and hold the corresponding access certificate.

Relying party access certificate

A certificate issued by an authorised provider that authenticates and validates a relying party to users’ wallets. An essential technical requirement for receiving data from the EUDI Wallet.

Relying-party registry

A national system containing the organisations authorised to request attributes from EUDI Wallet users. Regulated by Implementing Regulation (EU) 2025/848. Before it can operate, an organisation must have completed its registration.

Strong authentication

A level of authentication requiring more than one verification factor. In sectors governed by PSD2, MiFID II or other rules requiring robust customer identification, the obligation to accept the EUDI Wallet is triggered when the process requires strong authentication.

usercentric.id

Directory of relying and attesting parties for the Spanish IDUE Wallet, built by EADTrust. An entry point for organisations seeking to join the EUDI ecosystem as credential issuers or verifiers.

Why the December 2026 deadline is the first one that matters

Article 5a of Regulation (EU) 2024/1183 establishes that Member States must provide at least one European Digital Identity Wallet within twenty-four months of the entry into force of the implementing acts referred to in that article. The first relevant implementing acts were adopted on 28 November 2024 (Implementing Regulations (EU) 2024/2977, 2024/2978, 2024/2979, 2024/2981 and 2024/2982). Based on that starting point, the twenty-four-month period makes 24 December 2026 the deadline for the wallet to become available.

This has three simultaneous consequences on that date:

  • First: all citizens of the Member States have the right to request and receive their EUDI Wallet. The State cannot deny them that right. In Spain, this means that the IDUE Wallet (the Spanish name for the European wallet) must be available and capable of being issued to any citizen who requests it.
  • Second: public administrations must accept the EUDI Wallet as a means of electronic identification for their services. Electronic offices, administrative procedure portals and management systems that currently accept Cl@ve or digital certificates will also have to accept the EUDI Wallet.
  • Third: all systems that will accept the wallet must have completed their registration as a relying party in the corresponding national system. This registration is not instantaneous: it requires a legal analysis of the data to be requested, technical configuration of the protocols, integration with existing systems and verification time.

December 2026 is not the date when organisations will “have to start adapting”. It is the date when the system must already be operational. Preparation takes place before that date, not after it.

The implementing acts establishing the specific technical framework

To understand what must be ready, it is necessary to know the implementing acts that have gradually defined the ecosystem’s technical specifications. These are not policy documents: they are binding technical standards determining how each part of the system must operate.

In November 2024, the European Commission adopted the first five Implementing Regulations covering the wallet’s basic functionalities:

  • 2024/2977: technical specifications for the reference architecture.
  • 2024/2978: protocols and interfaces for presenting attributes.
  • 2024/2979: specifications for the wallet identifier.
  • 2024/2981: registration of wallet-relying parties.
  • 2024/2982: verification and validation mechanisms.

In May 2025, Implementing Regulation (EU) 2025/848 on the registration of relying parties was adopted, establishing the system that determines which organisations may request and receive data from a user’s wallet.

The second wave of eIDAS 2.0 technical acts was published in 2025, including those regulating qualified electronic archiving (2025/2532), qualified validation (2025/1942), certificates (2025/1943) and QTSPs (2025/2530), completing the trust services framework required for the EUDI ecosystem to operate.

The practical message from this accumulation of technical standards is clear: companies seeking to be ready by December 2026 must already have analysed these documents, or have an adviser who has done so on their behalf, and begun the technical integration.

The December 2027 deadline: obligation for the regulated private sector

Twelve months after the public administration deadline, Article 5b of the Regulation establishes the obligation for the regulated private sector. The exact deadline is thirty-six months from the entry into force of the implementing acts adopted in November 2024, placing it on 24 December 2027.

Article 5b of the Regulation establishes that private relying parties providing services in the following sectors must accept the use of European Digital Identity Wallets:

  • Transport – air, rail, maritime and road transport operators.
  • Energy – electricity and gas distributors and suppliers.
  • Banking – credit institutions, payment institutions and electronic money institutions.
  • Financial services – investment firms, fund managers and insurance companies.
  • Social security – organisations managing social benefits.
  • Healthcare – healthcare service providers.
  • Drinking water – water supply service providers.
  • Postal services – postal service providers.
  • Digital infrastructure – internet service, cloud computing and data centre providers.
  • Telecommunications – operators of public electronic communications networks.
  • Education – recognised educational institutions.

The obligation is triggered when Union law, national law or a contractual obligation requires strong authentication for online identification. This means that financial institutions governed by PSD2, which already require strong customer authentication, cannot choose not to accept the EUDI Wallet when a customer wishes to use it for that purpose.

In addition, large online platforms designated under the Digital Services Act (the so-called “very large online platforms”) must accept the EUDI Wallet for voluntary user authentication.

What “accepting the EUDI Wallet” means in practice

The obligation to “accept” the wallet does not mean replacing every existing identification system. It means that when a user wants to use the wallet to identify or authenticate themselves, the company must be able to process it. In practice, this requires four things:

First, registration as a relying party

To request and receive attributes from a user’s wallet, the organisation must register as a wallet-relying party in the national registry of the Member State where it is established. Implementing Regulation (EU) 2025/848 defines the process: the organisation must declare which data it will request, for which purposes and on what legal basis. Without this registration, the user’s wallet will not trust the data request.

Second, the relying party access certificate

For the user’s wallet to verify that the organisation requesting the data is who it claims to be, the organisation needs a wallet-relying party access certificate issued by an authorised provider. Without this certificate, there is no mutual authentication and the process cannot work.

Third, technical integration

The organisation’s authentication, onboarding or identity verification systems must be capable of processing the presentation of attributes in accordance with the protocols defined in the implementing acts. This does not necessarily require an integration from scratch: in many cases, it involves adding a module or adapting an existing component. However, it requires development and testing time.

Fourth, the data minimisation policy

The Regulation is explicit: the organisation may not request more data than is strictly necessary for the specific service. Designing this data minimisation policy, including the exact attribute requested for each use case, how it is managed and how long it is retained, involves legal and technical work that cannot be improvised.

The risk nobody is talking about: the window of influence

There is something that regulatory deadlines do not adequately capture and that is crucial when implementing a standard such as the EUDI Wallet: the window of influence closes long before the mandatory deadline arrives.

The technical interoperability standards, including protocols, credential formats and verification mechanisms, are currently being defined by European technical working groups. Organisations participating in those groups, or working with participants, have the opportunity to influence how those technical decisions are implemented. Those joining the process after the standards have been finalised can only adapt.

Julián Inza, President of EADTrust, has actively participated in the technical and regulatory discussions surrounding the EUDI ecosystem since its earliest stages, including the conference on the implementation and transformation of digital identity management organised by Comillas Pontifical University, which specifically addressed implementation challenges for the private sector. This participation is not only about keeping us informed: it ensures that our customers can access that perspective when they need it.

At EADTrust, we have built the Directory of Relying and Attesting Parties, available at usercentric.id: the entry point for organisations seeking to understand their position within the EUDI ecosystem and begin the integration process before the deadline makes it mandatory.

The impact estimated by the European Commission

The figures associated with the EUDI Wallet by the European Commission are significant. The Regulation’s impact assessment estimates that once the wallet has been deployed at scale:

  • For the financial sector: estimated savings of €1.02 billion per year by eliminating friction from customer identification and KYC processes.
  • For the digital economy as a whole: between 52% and 85% of EU citizens will use the EUDI Wallet by 2030.
  • For eliminating dependence on third parties: the wallet reduces dependence on authentication systems operated by large private platforms, such as “Sign in with Google” or “Continue with Facebook”, which currently account for 85% of logins on the European web.
  • For the Spanish tourism sector: identity verification in hotels, vehicle hire and mobility services directly affects the experience of European tourists in Spain, where the wallet simplifies processes that currently require physical documents to be presented.

Two dates, two speeds, one preparation process

The difference between December 2026 and December 2027 is not just twelve months. It is a difference in scope and urgency.

  • December 2026 primarily affects public administrations and national digital identity infrastructures. However, companies working with public administrations, including digital service providers, administrative procedure platforms and public service operators, need their systems to be compatible with the wallet by the same date so that users can use it in the context of those services.
  • December 2027 directly affects the regulated private sector. However, preparing in twelve months is insufficient in many cases. Technical integration, registration as a relying party, legal analysis of the data being requested and training the teams that will manage the new identity model require between twelve and twenty-four months of prior work in medium-sized and large organisations.

Companies that begin preparing in 2026 will reach December 2027 with their systems ready. Those that begin in 2027 will reach the deadline in emergency mode, with the costs, risks and time pressure that this entails.

EUDI Wallet timeline 2024-2030: the dates that matter

DateMilestoneWho is affected
20 May 2024eIDAS 2.0 enters into force.Regulatory framework activated
28 November 2024First five implementing acts adopted.Start of the deadline calculation
6 May 2025Implementing Regulation 2025/848 on the registration of relying parties.Organisations seeking to join the ecosystem
December 2025EUDI Wallet Launchpad in Brussels. Presentation of the IDUE Wallet.Spain among the five leading pilot countries
24 December 2026Wallet operational in every Member State. Public administrations required to accept it.Public administrations and citizens
24 December 2027Regulated private sector required to accept it.Banking, telecommunications, energy, healthcare, insurance, transport and education
2028-2030Deployment of sector-specific QEAAs. DPP integration.Sectors with specific verifiable credentials
2030Target: 52-85% of EU citizens with an active wallet.Transformed digital single market

Frequently asked questions about EUDI Wallet deadlines

What happens if my company fails to meet the December 2027 deadline?

The Regulation does not directly establish a uniform European penalty regime for failure to comply with the obligation to accept the wallet, as this must be developed by the Member States. However, operating in regulated sectors without complying with this obligation may result in exposure to the competent sectoral regulator (Bank of Spain, CNMC or CNMV), which may consider non-compliance to be a breach of electronic identification obligations. In addition, if a customer wants to use the wallet and the company refuses to accept it, there is a risk of complaints and reputational damage.

Is the preparation for December 2026 the same as for December 2027?

No. December 2026 primarily affects public administrations and requires their electronic offices to accept the wallet. For private companies, the relevant deadline is December 2027, but the technical and legal preparation required to be ready by that date must begin at least eighteen months in advance. 

How long does the registration process as a relying party take?

The registration process includes declaring which data will be requested, for what purposes and on what legal basis; the assessment of that declaration by the competent authority; obtaining the access certificate; and technical integration with the wallet protocols. The total time depends on the sector and the complexity of the organisation, but it usually takes between three and twelve months from the start of the process.

Are SMEs required to comply?

Microenterprises and small enterprises are expressly excluded from the obligation under Article 5b. The obligation applies to medium-sized and large companies operating in the regulated sectors listed. They may choose to accept the wallet voluntarily if it provides them with operational value.

Can EADTrust help my company prepare?

Yes. As a QTSP involved in the EUDI ecosystem since its earliest stages, with a presence in European pilot projects and the Directory of Relying and Attesting Parties at usercentric.id, EADTrust can support your organisation with the impact assessment, integration strategy design, registration process as a relying party and obtaining the necessary access certificates.

Does your organisation already know what it needs to do before December 2026?

The clock is already ticking. The implementing acts have been published, the deadlines have been set and the first pilots are already operational. The difference between organisations that will reach December 2026 and December 2027 with their systems ready and those that will arrive in emergency mode lies in what they do (or do not do) over the next twelve months.

At EADTrust, we can help you understand exactly how these requirements affect you, what you need to do and in what order. From the initial impact assessment and registration as a relying party to obtaining access certificates and completing the technical integration with your systems.

Fecha de publicación:

Última actualización:

31 de August de 2026

31 de August de 2026