Wallet certification
How an EUDI Wallet is certified under Article 5c eIDAS: designated bodies, European and national schemes, five years validity, biennial vulnerability checks.
The certification regime for EUDI Wallets, set out in Article 5c of eIDAS. It covers both the wallet and the electronic identification scheme under which it is provided, against the wallet requirements of Article 5a - the functional requirements, the logical separation of personal data, and where applicable the standards and specifications adopted by implementing act. The certificates are issued by conformity assessment bodies designated by Member States.
The regime is deliberately split. Parts that are relevant for cybersecurity are certified under the European cybersecurity certification schemes of the Cybersecurity Act; the rest, and the cybersecurity parts for which no European scheme exists yet, go through national certification schemes that a Member State has to notify to the Commission and to the European Digital Identity Cooperation Group, which may issue opinions and recommendations - the procedure for that notification is set out in Implementing Regulation (EU) 2025/849. Compliance with the personal data requirements can additionally be certified under the GDPR.
Two numbers are worth remembering. A certification is valid for at most five years, and only on condition that a vulnerability assessment is carried out every two years; where a vulnerability is found and not remedied in time, the certification is cancelled. Certified wallets are then published in a list, and a serious security breach can lead a Member State to suspend the wallet altogether. In other words, certification here is a running obligation, not a stamp you collect once.