Wallet provider

Learn what a wallet provider does under eIDAS 2.0: building, certifying and operating an EUDI Wallet, with recognition under the Dutch Wdo.

The wallet provider is the party that builds and operates an EUDI Wallet solution: the app, its secure cryptography (WSCA/WSCD) and the lifecycle of what the ARF calls a Wallet Unit - a Wallet Instance combined with its WSCA/WSCD - covering issuance, updates and revocation. A member state can be its own wallet provider, mandate one, or recognise private providers under its national scheme; in the Netherlands the Wdo (Wet digitale overheid) is the intended route, though as things stand in 2026 it governs the admission of login means and still needs amending for wallet providers under eIDAS 2. Wallet providers must be notified to the European Commission and published in a dedicated register of notified wallet providers - distinct from the EU Trusted List, which lists qualified trust service providers - and wallets must be offered free of charge to natural persons. Member states must make at least one certified wallet available at assurance level high within the timeframe set by the eIDAS2 Regulation.

The role is deliberately separated from the others in the ARF: the wallet provider must not collect data about the user's attributes or transactions beyond what is necessary to operate the service, nor combine such data for other purposes - a legal and design requirement rather than an inherent property - since PID providers, attestation providers and relying parties each operate in their own regulated lane. Wallet solutions must pass certification by a Conformity Assessment Body before they may be provided to users at all, and only certified wallets may carry the EU Digital Identity Wallet trust mark.

Frequently asked questions

Back to glossary