Estimated Reading Time: 6 minutes
In July 2014, the European Union laid the foundation for its digital fortress with the adoption of the eIDAS regulation. It was a pioneering move aimed at standardising electronic identification, seeking to create a secure digital single market. However, the current technological landscape is unrecognisable compared to that of a decade ago. The explosion of remote work, the mass adoption of the cloud, and the sophistication of modern cyber threats have exposed the weaknesses of that original framework.
Thus arrives eIDAS 2. Approved in 2024, it is not a simple patch or a minor update; it is a fundamental architectural shift. For Chief Technology Officers (CIOs), Chief Security Officers (CISOs), and business leaders, eIDAS 2 represents the critical transition from fragmented identity silos to an interoperable, secure, and, for the first time, truly user-centric ecosystem.
The implications for Identity and Access Management (IAM) are profound. As we approach the deadline for Member States to offer these wallets by the end of 2026, organisations must prepare for a paradigm shift in how they verify, onboard, and engage with their users.
Is your infrastructure ready for the biggest change in digital identity in the last decade?
Why now? The necessary evolution since eIDAS 2014
The original eIDAS achieved important milestones, such as establishing legal recognition of electronic signatures across borders. However, it suffered from significant adoption and reach issues. It relied heavily on national identification schemes that were often technically incompatible with each other.
Under the previous regime, a user could have a digital identity in Spain that was technically valid in Germany, but practically unusable due to a lack of real integration into everyday services. According to data from the European Commission, before this review, only around 60% of EU citizens had access to a reliable, cross-border electronic identification system.
The Paradigm Shift: From State to User
eIDAS 2 addresses these gaps by shifting the centre of gravity of identity. The focus moves dramatically from the issuer of identity (the state or large corporation) to the holder of identity (the user).
This decentralised approach aligns with modern privacy expectations and the technical principles of Sovereign Identity (SSI).
The goal: To ensure that citizens and businesses can operate seamlessly in any Member State, while maintaining control over their data. It’s no longer about a company “having” your data, but about you “granting” access to it on your terms.
EUDI Wallet: The Crown Jewel of Digital Identity
At the heart of the eIDAS 2 regulation is the European Digital Identity Wallet (EUDI Wallet). This is the technological vehicle that will drive mass adoption. By the end of 2026, all Member States are required to provide this digital wallet application to their citizens free of charge.
Much More Than a Mobile ID
The EUDI Wallet is designed to be a comprehensive repository of your digital self. The wallet will house:
- Legal identity: National ID card or digital passport.
- Attributes and credentials: Driver’s license, electronic prescriptions (ePrescriptions).
- Educational certifications: Verifiable university degrees.
- Financial information: Bank credentials or payment methods.
This transforms the mobile device into a universal tool for interacting with the physical and digital world.
The Role of Gatekeepers: A Mandatory Unified Marketplace
A crucial point is that eIDAS 2 expands the scope of entities required to accept the wallet. Large platforms designated as “gatekeepers” (major tech companies like Google, Apple, Amazon, and major banks) will be legally obligated to accept the EUDI Wallet for strong user authentication.

Technical Architecture: How eIDAS 2 Works Under the Hood
To ensure the EUDI Wallet functions seamlessly across 27 countries with disparate infrastructures, the EU has developed the Architecture Reference Framework (ARF). This technical blueprint ensures that a wallet issued in France “speaks the same language” as a service in Poland.
Radical Transparency: Open Source and GitHub
In an unprecedented move toward open source transparency, the European Commission maintains the ARF versions and roadmap publicly on GitHub. This allows the global technical community, including cybersecurity experts from Devoteam, to examine the code, suggest improvements, and ensure the framework is robust before mass deployment.
Key Standards: OIDC and Verifiable Credentials
At the protocol level, we are seeing a convergence toward modern standards such as OIDC4VP (OpenID Connect for Verifiable Presentations) and W3C Verifiable Credentials. For IT teams, this means that future integrations will be based on open web standards, making it easier to connect with microservices architectures.
Privacy by Design: The User Takes Control
- eIDAS 2 mandates Privacy by Design and by Default, fundamentally altering the philosophy of data collection:
- Zero-Knowledge Proofs (ZKP): The regulation popularises selective disclosure. A user can prove they are over 18 without revealing their exact date of birth. This benefits the company by minimising compliance risks (GDPR).
- Unobservability: To prevent mass profiling, infrastructure providers are prohibited from tracking user activity, and support for pseudonyms is required.
The Seismic Impact on Identity and Access Management (IAM)
For technology leaders, the intersection of eIDAS 2 and IAM is where the real action is. The regulations reinforce key concepts:
- Redefining the role of the Identity Provider (IdP): Companies will transition from being custodians of identities to being verifiers. The EUDI Wallet acts as a federated “super-IdP.”
- The end of passwords: The regulations are pushing towards passwordless authentication, relying on secure device biometrics (Face ID, fingerprint).
- Companies as issuers: Universities, insurers, and B2B companies will become issuers of verifiable credentials, integrating their IAM systems to “mint” certifications directly into users’ wallets.
Strategic business opportunities (Beyond compliance)
Viewing eIDAS 2 solely as an obligation is a mistake. It offers a compelling business case:
- Instant KYC: The EUDI Wallet enables near-instant and legally binding Know Your Customer (KYC) verification, eliminating friction in banking and telecommunications onboarding.
- QWACs against phishing: The regulation revitalises Qualified Web Authentication Certificates (QWACs), allowing companies to prove their true identity to users and combat phishing.
Critical Challenges on the Roadmap to 2027
Despite the optimism, the path ahead has obstacles that CIOs must map today:
- Technical debt: Adapting legacy IAM systems to support the new ARF protocols will require a strategic audit and, often, a modernisation to API-based platforms.
- Cybersecurity: By centralising identity attributes, the EUDI Wallet is a high-value target. Enterprise applications that rely on it must be fortified against advanced social engineering.
Conclusion: Leading the Transition to Digital Trust
eIDAS 2 is the blueprint for the next decade of the European digital economy. By requiring the EUDI Wallet, decentralizing attributes, and enforcing strong authentication, the EU is building a coherent and secure ecosystem.
For the IAM sector, this creates a landscape brimming with opportunities. Organizations that view eIDAS 2 as a strategic enabler for improving customer experience and reducing fraud will lead the market in trust and operational efficiency.
Next steps with Devoteam
Navigating the ARF technical specifications and adapting your IAM strategy to comply with eIDAS 2 requires in-depth expertise in both regulations and cutting-edge technology.
Whether you need to assess your current digital identity maturity, implement a Zero Trust architecture, or prepare your legacy infrastructure to connect with the EUDI Wallet, Devoteam is your strategic partner in this transformation.

Would you like to schedule a consultation with our Cybersecurity and IAM experts to define your roadmap to eIDAS 2?
Continue Reading
All Insights-
Expert ViewFrom Documents to Data: A Practical Guide to Automating Enterprise Workflows with OCR and AI
-
Expert ViewFrugality, De-Scaling and Experimentation: The Revolutionary Simplicity of LeSS
-
Expert ViewThe Bank’s Cost Maze: How AI Scenario Modeling Links True Costs to Business Value
-
Expert ViewA New Era for Digital Identity: Securing the Agentic Workforce
