The EUDI Wallet: what European law requires, and by when
The EUDI Wallet is an app a member state provides, or has provided on its behalf, in which a person keeps official identity data and electronic attestations of attributes and shows them to whoever needs them. For a bank the point is narrow and useful: a wallet presentation gives you identity attributes that a state stands behind, which takes the guesswork out of the identification step of onboarding.
The deadlines are the part most summaries get wrong. Regulation (EU) 2024/1183 of 11 April 2024 amends Regulation (EU) No 910/2014 and entered into force on 30 April 2024, and it does not set calendar dates for the wallet. Both deadlines run from the implementing acts instead, which is why the planning date in your project differs from the one in the press.
What the wallet holds
Two kinds of content. The first is Personal Identification Data, the core set a member state vouches for, such as name, date of birth and a unique identifier. The second is electronic attestations of attributes, each a separate signed statement about the holder: a driving entitlement, a university degree, a company role, a residence address.
Both sit on the holder's own device, and the holder decides per request what goes out. That design is what lets a verifier ask a narrow question instead of copying a whole document, and it is also why there is no central store of who proved what to whom. The EU Digital Identity Wallet for banks goes through person identification data, trust lists and levels of assurance in detail.
The two deadlines, as the regulation words them
Article 5a(1) requires that each member state provide at least one European Digital Identity Wallet "within 24 months of the date of entry into force of the implementing acts" referred to in Article 5a(23) and Article 5c(6). Article 5f(2) gives obliged private relying parties longer: they shall accept the wallet "no later than 36 months from the date of entry into force" of those same implementing acts, and only on the user's voluntary request. The clock in both articles starts at the implementing acts, not at the regulation, which is the detail that decides a project plan.
The European Commission translates the first of those into a plain target on its own EU Digital Identity Wallet pages, where it says each member state must provide at least one wallet, built to the same common specifications, by 2026. Read the two together: 2026 is the Commission's working date for the member state obligation, and the legally operative wording is the 24 months in Article 5a.
Who has to accept it, and what that means for a bank
Article 5f(2) names the sectors, and banking and financial services are in the list, alongside transport, energy, social security, health, drinking water, postal services, digital infrastructure, education and telecommunications. The obligation catches private relying parties in those sectors that are required by law or by contract to use strong user authentication for online identification. Microenterprises and small enterprises are excluded.
So a German bank that already does strong authentication at login is a relying party in scope, and it will have to take a wallet presentation when a customer offers one. What it may not do is treat that as the whole of its duties. A wallet settles who the person is; the rest of customer due diligence, the purpose of the relationship, the source of funds, the sanctions and PEP screening and the ongoing monitoring, is untouched. KYC in Germany and AML in Germany cover those, and KYC vs AML separates the two terms.
The Architecture and Reference Framework
A wallet from one member state has to work with a verifier in another, and that only happens if everyone implements the same formats and protocols. The Architecture and Reference Framework is the document that fixes them. The Commission describes it as setting out the common architecture of the wallet ecosystem by specifying the standards, protocols and formats of information exchanges between issuers, wallets and service providers, and it states that version 2.0 is available on GitHub.
Publishing it in the open, versioned, has a practical effect for anyone building against it: you can read the current text, see what changed between versions, and raise an issue on a point that does not work in production. For a bank's architects that matters more than the regulation's recitals, because the framework is what the integration is actually built to.
The four large-scale pilots
Before the obligation bites, the ecosystem is being tested in four consortia that the Commission describes as bringing together public and private sector expertise from across the EU, funded by European Commission grants, and building prototypes and testing everyday use cases. They are POTENTIAL, NOBID, EWC and DC4EU.
They matter to a bank for one reason: the payment and the financial use cases are being worked out there first, so the integration patterns that arrive in the framework have usually been through a pilot. A bank that wants to see how a wallet behaves in an account opening or at a payment authorization can read what the pilots published today.
The German wallet
Germany is building its own. The project site eudi-wallet.gov.de presents it as an official project of Bund, Länder und Kommunen, says the German EUDI Wallet app will launch in early 2027, and describes it as voluntary to use and regulated throughout Europe. On data it is explicit: documents are encrypted and stored on your smartphone, and there is no central data collection.
For a bank in Germany that fixes two planning assumptions. The state wallet is the one most customers will carry, so it is the one to test against first, and because use is voluntary a bank still needs its existing identification routes for everyone who does not use a wallet. The eID and video identification methods on KYC in Germany stay in the product.
Where the wallet meets a payment
At a checkout a wallet credential answers a question the payment rails handle badly: who is this, and is an attribute about them true. A merchant that has to establish an age, a residence or a company role can get a signed answer instead of a scan. The payment itself still runs on a card, an account transfer or a stablecoin, which digital wallets in payments sets out.
The identity rules and the payment rules meet where authentication is concerned, because a wallet is capable of the strong authentication that payment law demands. The coming payment rulebook is covered on PSD3, and the regulation that created the wallet, with its trust services, signatures and seals, on eIDAS 2 and finance.
When does the EUDI Wallet come?
Member states must provide at least one wallet within 24 months of the entry into force of the implementing acts under Article 5a(23) and Article 5c(6), and the European Commission's own working date for that obligation is 2026. Obliged private relying parties have 36 months from the same point. The German app is announced for early 2027 on eudi-wallet.gov.de.
Is the EUDI Wallet compulsory for citizens?
No. The regulation puts obligations on member states to provide a wallet and on obliged relying parties to accept one, and Article 5f(2) adds that acceptance happens only upon the voluntary request of the user. The German project site states plainly that the wallet is voluntary to use. Nobody has to install it, and services have to keep working for people who do not.
Can a bank use an EUDI Wallet for KYC?
For the identification step, yes: a wallet presentation gives identity attributes a member state vouches for, at a level of assurance the scheme defines. It does not deliver the rest of customer due diligence. Purpose of the business relationship, beneficial ownership, source of funds, sanctions and PEP screening and ongoing monitoring stay the bank's own work under the AML rules on AML in Germany.
What is the difference between the EUDI Wallet and eIDAS 2?
eIDAS 2 is the law, the EUDI Wallet is the thing the law requires. Regulation (EU) 2024/1183 amended the 2014 eIDAS Regulation and established the European Digital Identity Framework, of which the wallet is one part next to the trust services for signatures, seals and attestations. eIDAS 2 and finance covers the rest of the regulation.
The EUDI Wallet and Finance Loop
Finance Loop is the meeting place for the people in German and European finance who have to make the wallet work in production: the onboarding and compliance side first, the payment and identity architects next. Finance Loop runs events in Frankfurt, Berlin, Munich and Hamburg where banks, payment institutions and the identity software firms sit in the same room, and the wallet belongs to its Risk & Compliance and Payments & Digital Money tracks.
Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, tokenization, stablecoins, and DeFi. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.