Solutions

Industries

Markets

Partnerships

Resources

Get in touch

The Fourthline Team

eIDAS vs. eIDAS 2.0: What’s changed and who is impacted

eIDAS vs. eIDAS 2.0: What’s changed and who is impacted

The case for digital identity verification solutions has been growing progressively stronger since the early days of the internet. But with so much of our daily lives now existing on our devices, it was only a matter of time before governments and regulators recognised the acute need for standardised and mutually recognised digital verification across Europe. 

The original eIDAS RegulationRegulation (EU) 910/2014, in force since 2014 — was at its core a framework for exactly that. It set up the legal conditions for cross-border recognition of electronic signatures, seals, and trust services across Europe. It did not, however, mandate that private institutions adopt or accept those services. Participation was largely voluntary. In essence, the infrastructure was built, but no one was required to use it. 

This has changed. eIDAS 2.0, Regulation (EU) 2024/1183, in force since May 2024, introduces a standardised digital wallet that every EU citizen or resident will be entitled to, carrying verified attributes about them (age, qualifications, nationality, and more). And for the first time, private sector institutions, such as banks, fintechs, payment service providers (PSPs), are legally required to accept those credentials both at home and throughout the EU.

In this article, we’ll explore the differences between eIDAS and eIDAS 2.0, and what this means for financial service providers. 

What eIDAS actually did, and where it fell short

eIDAS was a real achievement in its time, making genuine attempts to bring digital identity infrastructure to the EU. It established a pan-European legal framework for electronic signatures, seals, timestamps, and trust services. It also created the QTSP framework and EU Trust List, a compilation of national lists of QTSP providers who have been formally approved by member countries. 

However, eIDAS had three structural weaknesses that ultimately limited its real-world impact. Here are the main ones:

·      Fragmented identity schemes. Under eIDAS, member states were essentially operating independent national eID systems, each with varying security levels, where they existed at all. Cross-border authentication remained inconsistent and difficult to rely upon in practice.

·      Limited private sector obligation. Adoption of the framework was completely voluntary. Institutions across the EU could choose whether or not to recognise eID schemes. The result was a legal framework with limited real-world uptake in the private sector.

·      Narrow credential scope. eIDAS focused on signatures and seals, but it did not cover the broader types of verification, such as professional qualifications, age, or citizenship status that modern onboarding and compliance workflows require.

These issues were systematically addressed by eIDAS 2.0. Now, we'll look at what’s changed. 

What eIDAS 2.0 actually changes: The four shifts that matter

1. Voluntary to mandatory

Member states must make at least one EUDI Wallet available to citizens and residents by December 2026. Designated relying parties, which includes banks, PSPs, public authorities and more must accept EUDI Wallet credentials by December 2027. 

2. Signatures to attributes

As we noted above, eIDAS focused on signatures and seals. eIDAS 2.0 introduces Electronic Attestations of Attributes (EAAs) and their qualified variant (QEAAs). Institutions can now receive verified attributes professional qualifications, age verification, driving licence status, and more directly from their Wallet credentials. This fundamentally changes what onboarding flows can do and what they need to be built to handle.

3. Cross-border recognition to cross-border interoperability

eIDAS enabled cross-border recognition in theory; in practice, cross-border identification remained difficult and cumbersome. eIDAS 2.0's Architecture Reference Framework (ARF) establishes common technical standards designed to ensure that Wallets issued in one member state function across all others. This is an especially helpful change for institutions operating across multiple EU markets. 

4. Trust services, expanded

eIDAS 2.0 adds new qualified trust service categories: electronic ledgers, electronic archiving, and EAAs. QTSPs also face new obligations, including high-level identity assurance certification for issuing credentials to EUDI Wallets. The QTSP alignment deadline passed on 21 May 2026, which means that providers must now operate under the updated requirements or risk suspension from the EU Trusted List.

Who is impacted by eIDAS 2.0  

eIDAS 2.0 is unusual in that it lands simultaneously across multiple teams inside a financial institution. Here is what each group needs to know:

Team

Changes

Product

Video-Ident becomes a documented exception from July 2027; eIDAS-compliant methods become the expected default under AMLR; EBA adequacy assessments remain the institution's responsibility

Engineering

Onboarding flows must support EUDI Wallet credential ingestion; selective disclosure changes what data can be requested and how consent is managed

Legal/Risk

Protocol support for ISO 18013-5, SD-JWT and OpenID4VP; trust-list management; holder-binding verification; audit-trail design; relying party registration with national authority

Product

PSD2 SCA and eIDAS 2.0 are not automatically aligned; wallet-based authentication may not satisfy every SCA requirement without additional mapping

Procurement

QTSP selection becomes a compliance dependency; native QTSP status vs. reseller model matters more after July 2027

The AMLR connection and the July 2027 deadline

eIDAS 2.0 does not exist in isolation. It is one half of a regulatory pair and its counterpart, the Anti-Money Laundering Regulation (AMLR, (EU) 2024/1624), is what gives the compliance timeline its real urgency.

From 10 July 2027, AMLR Article 22 establishes eIDAS-compliant methods: notified eID schemes at substantial or high assurance level, qualified electronic signatures, and the EUDI Wallet, as the preferred standard for remote customer verification. Non-eIDAS methods are not prohibited, but institutions using them where an eIDAS-compliant alternative exists may need to formally justify that decision.

The sequencing matters. Member states must have EUDI Wallets available by December 2026. AMLR applies in July 2027. That is a seven-month window in which institutions must be technically and operationally ready to ingest EUDI Wallet credentials as part of compliant onboarding. Institutions that miss the first deadline will struggle to meet the second.

The regulatory design here is intentional. AMLR defines what must be achieved: reliable, risk-based, auditable remote identity verification. eIDAS, on the other hand, defines how it can be achieved: through trusted, interoperable, high-assurance digital identity infrastructure. The two regulations are designed to work together, not independently.

What Fourthline's experience across eIDAS and eIDAS 2.0 tells us

As an identity verification provider across both eIDAS versions, serving 40+ regulated financial institutions with compliant onboardings at scale, one thing is clear: eIDAS 1.0 required expertise, while eIDAS 2.0 requires infrastructure.

Of course, the institutions best positioned for 2027 are those that took eIDAS seriously to begin with. These are the institutions that built solid QTSP relationships, designed rigorous audit trails, and developed the compliance infrastructure that they can now build upon in the age of eIDAS 2.0. 

But regardless of where you stand, Fourthline is built for this transition. We already support all three AMLR-compliant remote onboarding methods: QES, operating on a pan-European basis; eID, with German eID live and further markets in active rollout.

We hold BVA authorisation as a German eID service provider, are ETSI 119 461 (level high) certified for remote identity proofing, and ISO/IEC 27001:2022 compliant. The same stack that carried clients through eIDAS 1.0 is built to carry them through eIDAS 2.0 and AMLR.

Meet your eIDAS 2.0 requirements with Fourthline

Fourthline is Europe's leading identity verification provider for regulated financial institutions, holding ISO/IEC 27001:2022 certification and official BVA authorisation as a German eID service provider. Our platform supports all three AMLR-compliant verification methods (QES, national eID, and EUDI Wallet) within a single orchestration layer, meaning clients don't need to rebuild as regulations evolve.

If you want to understand where you stand on eIDAS 2.0 and AMLR requirements, contact us today.

FAQs 

Does eIDAS 2.0 replace eIDAS 1.0 entirely? 

No, eIDAS 2.0 (Regulation EU 2024/1183) amends and significantly expands eIDAS 1.0 rather than replacing it. The existing qualified trust service framework, EU Trust List, and legal recognition of QES remain in place. However, eIDAS 2.0 adds the EUDI Wallet framework, Electronic Attestations of Attributes, new QTSP obligations, and mandatory acceptance requirements for designated relying parties. 

Our institution already accepts electronic signatures. Does that mean we're eIDAS 2.0 compliant? 

Not necessarily. Accepting electronic signatures under eIDAS 1.0 does not automatically satisfy eIDAS 2.0 obligations. The key new requirements are the mandatory acceptance of EUDI Wallet credentials by December 2027, alignment with updated QTSP standards, and for institutions subject to AMLR the use of eIDAS-compliant methods as the preferred remote identification path from July 2027.

We operate across multiple EU member states. Do we need a separate integration for each country's EUDI Wallet? 

No. The Architecture Reference Framework (ARF) establishes common technical standards across all member states, meaning a wallet issued in Germany should function in France, Spain, or the Netherlands without requiring a separate national integration. In practice, however, rollout timelines will vary by country. 

The case for digital identity verification solutions has been growing progressively stronger since the early days of the internet. But with so much of our daily lives now existing on our devices, it was only a matter of time before governments and regulators recognised the acute need for standardised and mutually recognised digital verification across Europe. 

The original eIDAS RegulationRegulation (EU) 910/2014, in force since 2014 — was at its core a framework for exactly that. It set up the legal conditions for cross-border recognition of electronic signatures, seals, and trust services across Europe. It did not, however, mandate that private institutions adopt or accept those services. Participation was largely voluntary. In essence, the infrastructure was built, but no one was required to use it. 

This has changed. eIDAS 2.0, Regulation (EU) 2024/1183, in force since May 2024, introduces a standardised digital wallet that every EU citizen or resident will be entitled to, carrying verified attributes about them (age, qualifications, nationality, and more). And for the first time, private sector institutions, such as banks, fintechs, payment service providers (PSPs), are legally required to accept those credentials both at home and throughout the EU.

In this article, we’ll explore the differences between eIDAS and eIDAS 2.0, and what this means for financial service providers. 

What eIDAS actually did, and where it fell short

eIDAS was a real achievement in its time, making genuine attempts to bring digital identity infrastructure to the EU. It established a pan-European legal framework for electronic signatures, seals, timestamps, and trust services. It also created the QTSP framework and EU Trust List, a compilation of national lists of QTSP providers who have been formally approved by member countries. 

However, eIDAS had three structural weaknesses that ultimately limited its real-world impact. Here are the main ones:

·      Fragmented identity schemes. Under eIDAS, member states were essentially operating independent national eID systems, each with varying security levels, where they existed at all. Cross-border authentication remained inconsistent and difficult to rely upon in practice.

·      Limited private sector obligation. Adoption of the framework was completely voluntary. Institutions across the EU could choose whether or not to recognise eID schemes. The result was a legal framework with limited real-world uptake in the private sector.

·      Narrow credential scope. eIDAS focused on signatures and seals, but it did not cover the broader types of verification, such as professional qualifications, age, or citizenship status that modern onboarding and compliance workflows require.

These issues were systematically addressed by eIDAS 2.0. Now, we'll look at what’s changed. 

What eIDAS 2.0 actually changes: The four shifts that matter

1. Voluntary to mandatory

Member states must make at least one EUDI Wallet available to citizens and residents by December 2026. Designated relying parties, which includes banks, PSPs, public authorities and more must accept EUDI Wallet credentials by December 2027. 

2. Signatures to attributes

As we noted above, eIDAS focused on signatures and seals. eIDAS 2.0 introduces Electronic Attestations of Attributes (EAAs) and their qualified variant (QEAAs). Institutions can now receive verified attributes professional qualifications, age verification, driving licence status, and more directly from their Wallet credentials. This fundamentally changes what onboarding flows can do and what they need to be built to handle.

3. Cross-border recognition to cross-border interoperability

eIDAS enabled cross-border recognition in theory; in practice, cross-border identification remained difficult and cumbersome. eIDAS 2.0's Architecture Reference Framework (ARF) establishes common technical standards designed to ensure that Wallets issued in one member state function across all others. This is an especially helpful change for institutions operating across multiple EU markets. 

4. Trust services, expanded

eIDAS 2.0 adds new qualified trust service categories: electronic ledgers, electronic archiving, and EAAs. QTSPs also face new obligations, including high-level identity assurance certification for issuing credentials to EUDI Wallets. The QTSP alignment deadline passed on 21 May 2026, which means that providers must now operate under the updated requirements or risk suspension from the EU Trusted List.

Who is impacted by eIDAS 2.0  

eIDAS 2.0 is unusual in that it lands simultaneously across multiple teams inside a financial institution. Here is what each group needs to know:

Team

Changes

Product

Video-Ident becomes a documented exception from July 2027; eIDAS-compliant methods become the expected default under AMLR; EBA adequacy assessments remain the institution's responsibility

Engineering

Onboarding flows must support EUDI Wallet credential ingestion; selective disclosure changes what data can be requested and how consent is managed

Legal/Risk

Protocol support for ISO 18013-5, SD-JWT and OpenID4VP; trust-list management; holder-binding verification; audit-trail design; relying party registration with national authority

Product

PSD2 SCA and eIDAS 2.0 are not automatically aligned; wallet-based authentication may not satisfy every SCA requirement without additional mapping

Procurement

QTSP selection becomes a compliance dependency; native QTSP status vs. reseller model matters more after July 2027

The AMLR connection and the July 2027 deadline

eIDAS 2.0 does not exist in isolation. It is one half of a regulatory pair and its counterpart, the Anti-Money Laundering Regulation (AMLR, (EU) 2024/1624), is what gives the compliance timeline its real urgency.

From 10 July 2027, AMLR Article 22 establishes eIDAS-compliant methods: notified eID schemes at substantial or high assurance level, qualified electronic signatures, and the EUDI Wallet, as the preferred standard for remote customer verification. Non-eIDAS methods are not prohibited, but institutions using them where an eIDAS-compliant alternative exists may need to formally justify that decision.

The sequencing matters. Member states must have EUDI Wallets available by December 2026. AMLR applies in July 2027. That is a seven-month window in which institutions must be technically and operationally ready to ingest EUDI Wallet credentials as part of compliant onboarding. Institutions that miss the first deadline will struggle to meet the second.

The regulatory design here is intentional. AMLR defines what must be achieved: reliable, risk-based, auditable remote identity verification. eIDAS, on the other hand, defines how it can be achieved: through trusted, interoperable, high-assurance digital identity infrastructure. The two regulations are designed to work together, not independently.

What Fourthline's experience across eIDAS and eIDAS 2.0 tells us

As an identity verification provider across both eIDAS versions, serving 40+ regulated financial institutions with compliant onboardings at scale, one thing is clear: eIDAS 1.0 required expertise, while eIDAS 2.0 requires infrastructure.

Of course, the institutions best positioned for 2027 are those that took eIDAS seriously to begin with. These are the institutions that built solid QTSP relationships, designed rigorous audit trails, and developed the compliance infrastructure that they can now build upon in the age of eIDAS 2.0. 

But regardless of where you stand, Fourthline is built for this transition. We already support all three AMLR-compliant remote onboarding methods: QES, operating on a pan-European basis; eID, with German eID live and further markets in active rollout.

We hold BVA authorisation as a German eID service provider, are ETSI 119 461 (level high) certified for remote identity proofing, and ISO/IEC 27001:2022 compliant. The same stack that carried clients through eIDAS 1.0 is built to carry them through eIDAS 2.0 and AMLR.

Meet your eIDAS 2.0 requirements with Fourthline

Fourthline is Europe's leading identity verification provider for regulated financial institutions, holding ISO/IEC 27001:2022 certification and official BVA authorisation as a German eID service provider. Our platform supports all three AMLR-compliant verification methods (QES, national eID, and EUDI Wallet) within a single orchestration layer, meaning clients don't need to rebuild as regulations evolve.

If you want to understand where you stand on eIDAS 2.0 and AMLR requirements, contact us today.

FAQs 

Does eIDAS 2.0 replace eIDAS 1.0 entirely? 

No, eIDAS 2.0 (Regulation EU 2024/1183) amends and significantly expands eIDAS 1.0 rather than replacing it. The existing qualified trust service framework, EU Trust List, and legal recognition of QES remain in place. However, eIDAS 2.0 adds the EUDI Wallet framework, Electronic Attestations of Attributes, new QTSP obligations, and mandatory acceptance requirements for designated relying parties. 

Our institution already accepts electronic signatures. Does that mean we're eIDAS 2.0 compliant? 

Not necessarily. Accepting electronic signatures under eIDAS 1.0 does not automatically satisfy eIDAS 2.0 obligations. The key new requirements are the mandatory acceptance of EUDI Wallet credentials by December 2027, alignment with updated QTSP standards, and for institutions subject to AMLR the use of eIDAS-compliant methods as the preferred remote identification path from July 2027.

We operate across multiple EU member states. Do we need a separate integration for each country's EUDI Wallet? 

No. The Architecture Reference Framework (ARF) establishes common technical standards across all member states, meaning a wallet issued in Germany should function in France, Spain, or the Netherlands without requiring a separate national integration. In practice, however, rollout timelines will vary by country. 

Fourthline has been certified by EY CertifyPoint to ISO/IEC27001:2022 with certification number 2021-039.

Copyright © 2026 - Fourthline B.V. - All rights reserved.

Fourthline has been certified by EY CertifyPoint to ISO/IEC27001:2022 with certification number 2021-039.

Copyright © 2026 - Fourthline B.V. - All rights reserved.