Through late 2024 and 2025 the European Commission has been adopting the implementing acts that turn eIDAS 2.0 from statute into specification: wallet core functions and integrity, certification schemes, protocols and interfaces, relying-party registration. It is unglamorous plumbing, and it is the plumbing on which the December 2026 wallet obligation stands.
Relying parties become visible
One theme deserves business attention: relying parties, the companies that will ask users for wallet attributes, must register in their member state and declare what data they intend to request and why. Over-asking becomes visible and sanctionable. The data-minimisation habit that GDPR encouraged, wallets will enforce structurally.
Qualified services are the anchor
The acts also reconfirm where trust originates: qualified trust service providers, audited, supervised and listed on the EU Trusted List. Wallet credentials trace back to verifications performed to standards like ETSI's identity-proofing baseline, and qualified signatures remain the gold standard the wallet will carry. WeVerify operates as a QTSP today: chip-level identity verification, qualified signatures legally equal to handwriting across all 27 member states, and qualified seals. Businesses integrating these flows now are, in effect, wallet-ready before the wallet arrives.
