eIDAS 2.0 is the European Union’s updated framework for electronic identification, authentication and trust services, and it changes how banks, payment providers and e-money institutions bring customers on board. The regulation mandates secure, interoperable digital identity across all 27 member states, replacing a patchwork of national eID schemes with a single technical and legal baseline.
For financial institutions, that shift redefines how customers are authenticated, how documents are verified and how compliance teams document their decisions. Jumio already supports eIDs across most EU member states, giving institutions a foundation to build on as wallet adoption accelerates. This roadmap lays out what compliance, risk and technology teams need to prioritize before the December 2026 deadline arrives.
eIDAS Regulation Explained
Before 2024, EU member states operated under a patchwork of national identification laws with limited cross-border recognition. The eIDAS regulation update closes that gap by standardizing digital identity requirements, giving financial institutions one framework to design against instead of 27.
What Is eIDAS 2.0?
eIDAS stands for Electronic Identification, Authentication and Trust Services, and version 2.0 updates the original Regulation (EU) No 910/2014 that has governed digital trust services since 2014. The update moves the EU away from voluntary, fragmented national eID schemes toward a mandatory framework built around a single instrument. That instrument is the European Digital Identity Wallet (EUDI Wallet), which becomes the cornerstone of identity and trust services across the union and will be available to citizens, residents and businesses in all 27 member states.
The regulation also extends legal recognition to qualified electronic signatures, seals, timestamps and electronic attestations of attributes. Perhaps more significant for compliance teams, it converges with the EU Anti-Money Laundering Regulation taking effect in July 2027. Together, the two frameworks create a unified compliance baseline for Know Your Customer (KYC) and Anti-Money Laundering (AML) programs, meaning remote identity verification processes built for one increasingly satisfy the other.
Where eIDAS 2.0 Stands Today
The regulation was published in the Official Journal of the EU on April 30, 2024, and entered into force on May 20, 2024. Since then, several implementing acts have been finalized, setting interoperability standards and wallet certification procedures that institutions can now build against with confidence.
Large-scale EUDI Wallet pilots have been running across member states since 2023, and the European Commission has set a target of 80% of citizens actively using EUDI Wallets by 2030.For financial institutions, wallet acceptance and alignment with European Telecommunications Standards Institute (ETSI) standards are operational obligations with a fixed timeline attached.
Inside eIDAS 2.0: Key Components Financial Institutions Must Understand
eIDAS 2.0 is a layered architecture of identity instruments, and each layer carries distinct compliance obligations for financial institutions.
Reusable Digital Identity
Under the new framework, citizens verify their identity once and reuse that credential across all EU member states. That reduces friction in cross-border onboarding for banks and fintechs with pan-EU footprints, since customers no longer submit fresh documentation for every new relationship.
The model relies on selective disclosure, meaning users share only the attributes a given transaction requires, which aligns directly with General Data Protection Regulation (GDPR) data minimization principles. For KYC and AML workflows, reusable credentials streamline identity proofing while preserving the audit trail supervisors expect.
Qualified Trust Services
eIDAS 2.0 expands the list of qualified trust services to include electronic signatures, electronic seals, timestamps, registered delivery, website authentication and electronic attestations of attributes. ETSI TS 119 461 v2 now governs how financial institutions perform remote verification and onboarding, and institutions that build ETSI-certified onboarding flows simultaneously satisfy eIDAS 2.0, AML and KYC requirements in a single process.
That reduces compliance fragmentation considerably for institutions operating across borders. Institutions using video identification or biometric methods must also align with the updated general policy requirements for trust service providers under ETSI EN 319 401.
EU Digital Identity Wallets
The EUDI Wallet is a government-issued, secure mobile application that stores verifiable credentials, including national IDs, professional qualifications, health credentials and bank account information. Credentials inside the wallet are cryptographically signed, which allows instant, tamper-proof verification against EU trust lists.
Each wallet also includes a privacy dashboard giving users full transparency into their transactions and GDPR-aligned control over their data. Wallet issuance, use and revocation remain free of charge for all natural persons, though commercial providers may offer certified wallets alongside the government-issued option. Jumio’s own analysis of the EU Digital Identity Wallet landscape covers how institutions should prepare for both variants.
Interoperability Among EU Member States
Every member state wallet must conform to the Architecture and Reference Framework, which guarantees that a wallet issued in one country is accepted across all 27. That eliminates the need for parallel verification processes built jurisdiction by jurisdiction. Cross-border onboarding can be designed against a single technical and regulatory reference instead of 27 separate ones, and duplicative due diligence checks per member state disappear entirely.
Electronic Attestation of Attributes and Verifiable Credentials
Electronic Attestations of Attributes, or EAAs, are cryptographically signed certificates that enable selective attribute sharing rather than full identity disclosure. Common examples include age, IBAN, professional license and legal entity status. EAAs support attribute-based KYC checks, letting institutions verify a specific claim (such as the customer’s age) without exposing unnecessary personal details (such as their date of birth). That reduces reliance on document uploads, accelerates digital onboarding and strengthens fraud-resistant verification chains inside existing KYC and AML pipelines.
Advantages and Benefits of eIDAS 2.0
Compliance obligations aside, eIDAS 2.0 delivers measurable operational and commercial value, particularly at the identity verification layer.
For Citizens
Citizens gain a single, portable digital identity usable across public and private services throughout the EU. Repeated document uploads across member states or service providers become unnecessary. Selective disclosure keeps data exposure to a minimum for every interaction, and government-certified credentials paired with cryptographic verification lower the risk of identity theft considerably. Wallet use remains entirely voluntary, so parallel identification methods must stay available for anyone who opts out.
For Businesses
Businesses gain faster, lower-cost customer authentication through instant, wallet-based credential sharing. One harmonized framework replaces 27 fragmented national onboarding processes.
For financial institutions specifically, EUDI Wallet credentials satisfy PSD2 and PSD3 Strong Customer Authentication requirements, which reduces authentication friction without sacrificing compliance. ETSI-aligned proofing satisfies KYC, AML and supervisory expectations in a single conformant process, and wallet-based onboarding tends to reduce abandonment rates during digital onboarding. Interoperable credentials also lower the cost of cross-border customer due diligence and enhanced due diligence.
For Governments
Mandated interoperability eliminates the fragmented national ID systems that have blocked progress toward a true digital single market. Public-sector costs tied to identity management and citizen authentication drop as a result. Tamper-proof cryptographic credential chains improve fraud detection and audit capacity, while EU trust lists allow real-time validity checks of issued credentials across every member state.
eIDAS 2.0 Implementation
Meeting eIDAS 2.0 obligations means aligning identity verification, authentication workflows and compliance frameworks across several technical and regulatory layers at once. Jumio’s eIDAS primer walks through the technical detail behind each requirement below.
Regulatory Obligations and Actionable Steps for Financial Institutions
Institutions should start by mapping their current identity verification stack against ETSI TS 119 461 v2. Gaps identified now avoid costly remediation once the December 2026 deadline arrives. That means assessing video identification and biometric methods against the updated proofing standards well ahead of time.
Institutions must also register as a relying party. Banks, payment service providers and e-money institutions are required to formally register in order to accept EUDI Wallets, which involves both technical integration and legal designation under eIDAS 2.0. Onboarding journeys need to be redesigned to accept wallet-issued EAAs alongside traditional document verification, rather than replacing one with the other.
Non-wallet identification options cannot be retired. Wallet use remains voluntary, so parallel methods must stay fully operational, and institutions cannot refuse service to customers who decline to use a wallet. Institutions should also participate in national EUDI Wallet sandbox environments to test attribute verification, such as IBAN or Legal Person Identifier checks, along with Strong Customer Authentication (SCA) integration well before the deadline. Coordinating eIDAS 2.0 readiness with AMLR preparation makes sense given how closely the two frameworks converge on a harmonized remote verification standard, and aligning both compliance programs reduces duplication and legal uncertainty considerably.
Key eIDAS 2.0 Dates and Deadlines
In the first half of 2026, all 27 member states were required to make at least one certified EUDI Wallet available to citizens and businesses. On July 10, 2027, the AMLR applies directly across every member state, converging fully with eIDAS 2.0. By December 2027, banks, payment service providers and e-money institutions must accept EUDI Wallets for Strong Customer Authentication. Looking further out, the Commission’s target remains 80% active EUDI Wallet adoption among EU citizens and businesses by 2030.
Challenges in Implementation
Legacy system incompatibility ranks among the biggest hurdles. Many institutions’ KYC pipelines predate the ETSI TS 119 461 v2 proofing standards, and aligning legacy infrastructure with wallet-based credential acceptance requires significant technical uplift.
National rollout timelines are also uneven. Wallet maturity will vary by member state heading into December 2026, and institutions with multi-jurisdictional customer bases will need to manage inconsistent credential quality as a result.
Maintaining parallel verification pathways adds further complexity. Institutions must support wallet-based and traditional document verification simultaneously, since wallet use stays voluntary and customer populations will remain mixed well into 2030.
Fraud in the new credential layer is another concern worth planning for. EUDI Wallets strengthen assurance overall, but credential spoofing and AI-generated attacks remain active threats. Biometric identity solutions, especially selfie verification and liveness detection, stay essential alongside wallet acceptance, not as optional add-ons.
Cross-regulatory alignment adds one more layer of complexity. eIDAS 2.0 intersects with PSD2, PSD3, AMLR, GDPR and sector-specific supervisory requirements, so institutions need a compliance architecture that satisfies every regulatory layer at once rather than treating each in isolation.
Jumio accepts and validates eIDAS-compliant eIDs today across the EU and many more digital IDs globally. AI-powered identity verification, certified liveness detection and identity intelligence extend protection well beyond a point-in-time wallet check. As EUDI Wallets move into production, institutions using Jumio can layer wallet credential acceptance on top of existing workflows without rebuilding them, and fraud controls stay active regardless of credential format through KYC and AML compliance tools already in place.
FAQs
What is eIDAS 2.0?
eIDAS 2.0 is the EU’s updated regulation on electronic identification, authentication and trust services, formally known as Regulation (EU) 2024/1183. It replaces the original 2014 framework with a mandatory, interoperable digital identity architecture. It also introduces the EUDI Wallet, which every member state must issue by December 2026.
What is the EUDI Wallet and how does it work?
The EUDI Wallet is a government-certified mobile app for storing and presenting verified identity credentials, including national IDs, professional qualifications, IBAN details and health data. Credentials are cryptographically signed, allowing instant, tamper-proof verification against EU trust lists. Selective disclosure means users share only the minimum attributes a given interaction requires.
When must financial institutions comply with eIDAS 2.0?
EUDI Wallets must be available to all EU citizens and businesses by December 2026. Banks, payment service providers and e-money institutions must accept wallets for Strong Customer Authentication (SCA) use cases by December 2027. Institutions should begin ETSI alignment and wallet integration planning now rather than waiting for the deadline.
Does eIDAS 2.0 replace existing KYC and AML processes?
No, it provides a harmonized technical framework that aligns with KYC, AML and SCA requirements simultaneously. ETSI TS 119 461 v2-compliant onboarding satisfies eIDAS 2.0, AML, KYC and supervisory expectations at once. The AMLR, applying in July 2027, further converges with eIDAS 2.0 and reduces compliance fragmentation.
Is EUDI Wallet use mandatory for citizens?
No, wallet use is entirely voluntary for EU citizens and residents. Institutions must accept wallets wherever identity verification is required but cannot refuse service to individuals who choose not to use one. Parallel non-wallet methods, including document verification and biometric authentication, must remain operational.
How does eIDAS 2.0 interact with PSD2 Strong Customer Authentication?
EUDI Wallets provide a standardized, government-certified mechanism for satisfying PSD2 and PSD3 SCA requirements. Banks and payment providers must accept wallet-based authentication as valid SCA by December 2027. This reduces authentication friction for consumers while providing a legally recognized instrument for institutions.
What are the biggest implementation risks for financial institutions?
For financial institutions, legacy systems often remain incompatible with ETSI TS 119 461 v2 and wallet-based credential formats. Uneven national wallet rollout maturity creates inconsistent cross-border compliance coverage. New fraud vectors, including wallet credential spoofing and AI presentation attacks, require layered biometric fraud prevention on top of standard credential acceptance.
What is the difference between eIDAS 1.0 and eIDAS 2.0?
eIDAS 1.0, dating to 2014, allowed voluntary national eID notification with limited cross-border interoperability and no wallet mandate. eIDAS 2.0, in force since 2024, mandates EUDI Wallet issuance, expands qualified trust services and introduces attribute-based identity through EAAs. It also harmonizes proofing standards and converges with the AMLR for mandatory acceptance by regulated relying parties.
How does identity intelligence improve eIDAS 2.0 compliance outcomes?
Wallet credential verification confirms identity at a single moment but doesn’t detect fraud that emerges after onboarding. Identity intelligence adds continuous cross-transaction risk assessment on top of eIDAS-level assurance. Behavioral analysis and connected data signals across the Jumio Identity Graph surface threats that a one-time wallet check alone would miss.
Future-Proof Your eIDAS 2.0 Compliance With Jumio
eIDAS 2.0 raises the bar for digital identity verification across the EU, but compliance alone doesn’t stop fraud that evolves after onboarding. Jumio supports eIDAS-compliant eIDs and national identity documents across every EU member state today, and its AI-powered document verification already handles the credential formats EUDI Wallets will issue. Advanced liveness detection meeting ISO/IEC 30107-3 Level 2 compliance satisfies eIDAS high assurance requirements, while Jumio’s identity intelligence platform closes the gap between point-in-time eIDAS assurance and real-world fraud prevention through continuous, cross-transaction risk assessment.
Financial institutions gain a single platform for KYC and AML compliance, digital onboarding and fraud prevention. Jumio helps ensure you’re architecturally ready for eIDAS 2.0’s evolving wallet ecosystem now and in the future.
Don’t wait for the December 2026 deadline. Discover how Jumio’s identity verification platform supports eIDAS-compliant eIDs and prepares your institution for the full eIDAS 2.0 transition. Schedule a call today!