WIRE 10.09.2026Commission opens formal AI Act proceedings against two model providersECB digital euro pilot names first Belgian banksAgeas, AXA, Allianz sign joint letter on cloud exit clausesBelgium's NIS2 transposition enters force 18 October
All wire
Hosaka Seven

Tech, policy and power. For the people who have to sign off on it.

Preview

The identity wallet is due on 24 December. Which phones can carry it has not been decided anywhere you can read.

Firms that already demand two-factor logins must accept it a year later, on request, and small ones not at all. The handset list will come out of national certification schemes, and the regulation says nothing about year four.

A service counter behind glass. On the customer's side a smartphone lies face down with its SIM tray pushed out, beside a sealed pouch holding a blank chip card. Behind the glass, a December calendar with one square circled, and a pegboard of empty phone-shaped outlines with nothing hanging on them.

Draft, not yet edited. Written by Joris Feenstra, and not yet through the desk: nothing here has been checked against the sources listed at the foot of the page. Do not act on it.

On 24 December every member state has to be providing at least one European Digital Identity Wallet. That date is not a launch window. It is arithmetic, and the Commission has already done the sum.

Article 5a(1) of the amended eIDAS Regulation gives member states 24 months from the entry into force of two sets of implementing acts: those on how the wallet works, under Article 5a(23), and the one on how it is certified, under Article 5c(6). Five were adopted on 28 November 2024 and published on 4 December. Each entered into force on the twentieth day after, which is 24 December 2024. Two regulations adopted in May 2025, on registering relying parties and on cross-border identity matching, then state that they apply from 24 December 2026. The clock is settled. What arrives when it runs out is less so.

The obligation on a regulated firm is narrower than the one being repeated

The version going round is that banks, and anyone else doing strong customer authentication, must accept the wallet a year after it ships. Close, and wrong in three ways that matter to whoever signs the gap analysis.

Article 5f(2) catches private firms required, by Union or national law or by contract, to use "strong user authentication for online identification". That is eIDAS's own term, defined in Article 3(51) as two independent factors from knowledge, possession and inherence. It is not the payments-law term, and it attaches to identification: logging in, proving who you are. Recital 62 says the wallet should help "support" strong customer authentication for account login and payment initiation. A recital is an aspiration. Whether a wallet presentation satisfies payments law is a question for payments law, which I have not opened.

Second, micro and small enterprises are excluded outright. Third, acceptance is owed "only upon the voluntary request of the user". Nobody has to steer customers towards it. The deadline is 36 months from the same acts, so 24 December 2027. The sectors named, from transport and banking to drinking water and education, follow the word "including". The list is an illustration, not a boundary.

The shorter fuse is registration. A firm that intends to rely on the wallet registers in the member state where it is established, declaring what it will use the wallet for and which data it will ask for, and it may not ask for anything else (Article 5b(1) and (3)). The registration rules in Implementing Regulation 2025/848 apply from 24 December 2026, and only a registered firm gets the access certificate a wallet uses to check who is asking. An intermediary acting for you counts as a relying party in its own right and may not store the content of the transaction (Article 5b(10)). That clause will interest whichever identity vendor currently sits in your login flow.

Member statesArticle 5a(1)

24 months → 24 Dec 2026

Relying-party registration2025/848

applies from 24 Dec 2026

Regulated private firmsArticle 5f(2), on request

36 months → 24 Dec 2027

Commission assessmentArticle 5f(5)

within 24 months of deployment

wallets dueacceptance due

Dec 2024Dec 2026Dec 2027Dec 2028
Two fixed dates hung off one publication date. The third clock has no start until the wallets exist.Regulation (EU) 2024/1183, Articles 5a(1), 5f(2) and 5f(5); Implementing Regulations (EU) 2024/2977 to 2024/2982 and 2025/848.

What the phone has to contain

The hardware requirement is one sentence. Article 4(1) of Implementing Regulation 2024/2979: a wallet "shall use at least one wallet secure cryptographic device", defined as a tamper-resistant device that protects the keys and does the cryptography. It does not say chip, phone or brand.

The Architecture and Reference Framework, which is guidance and not law, sets out four shapes that can take. The keys can live in a hardware security module in the provider's data centre. On a smart card issued for the purpose and tapped against the phone's NFC antenna, though the framework notes most existing identity cards cannot do it. On the SIM, the eSIM or an embedded secure element, with a Java Card applet pushed to the chip at activation, which may need the co-operation of whoever controls that chip. Or in the phone's own keystore, reached through the operating system. A provider may use any of them. The framework adds, with some care, that describing an architecture does not mean an implementation of it will pass certification.

That is where the list of supported phones gets decided. Under Implementing Regulation 2024/2981, a handset the user brings is outside the object of certification. National schemes instead write assumptions about it, under which the wallet must resist attackers with "high attack potential". A phone that meets the assumptions is supported. One that does not, is not. No text I opened names a model, an operating system version or a chip.

Recital 49 anticipates the argument over who holds the keys to the chip: handset makers and network operators "should not refuse access" to secure elements and NFC where a wallet needs them. It is a recital. For the largest platforms it points to Article 6(7) of the Digital Markets Act, which I have not reopened for this piece.

Year four, which nobody has written down

A wallet is only as supported as the phone under it, and the regulation says nothing about the day that phone stops getting security updates. A wallet whose security has been compromised can be revoked (Article 5a(9)), and the user must be told within 24 hours (2024/2979, Article 7(3)). Whether an unpatched operating system counts as compromised is left to each provider's published revocation policy.

The smartphone ecodesign regulation, 2023/1670, helps less than it looks. For models placed on the market from 20 June 2025, a manufacturer that ships operating system updates must keep offering them for at least five years after the model leaves the shelves. "If they provide" carries most of that sentence, and anything sold before June 2025 is outside it entirely. Someone holding a 2022 handset on 24 December sits in neither regime.

For that person the regulation's answer is Article 5a(15). Use is voluntary, and nobody may be restricted or disadvantaged for declining; existing ways of identifying must keep working. For a relying party that cuts both ways. From December 2027 the wallet must be accepted on request. The login that works without one cannot be retired.

Decided, and not

QuestionWhere it standsWhere it sitsWhat would settle it
When a wallet must existDecided: 24 Dec 2026Art 5a(1); 2025/848Nothing; the date is arithmetic
When regulated firms must accept itDecided: 24 Dec 2027, on request, not micro or small firmsArt 5f(2)Nothing short of amendment
How to registerOutline decided2025/848Each state's published registration policy
Whether it meets payment authentication rulesNot decided in eIDASRecital 62 onlyPayments law or supervisory guidance
Which phones qualifyNot decided2024/2981, national assumptionsCertified wallets listed under Art 5d, with their assumptions
What happens when updates stopNot addressedProvider revocation policiesThose policies, once published
When very large platforms must accept itNo date in the textArt 5f(3)Not visible in the text

I have opened no primary source for any member state's rollout and print no status for any of them. The document that will answer it is the list of certified wallets Article 5d obliges member states to feed the Commission. After that the Commission has 24 months from deployment to assess take-up, the first point at which anyone must say how many people used the thing.

The date is fixed in Brussels. The phone will be fixed somewhere else, in each member state's certification scheme, one written assumption at a time.

Primary The document itself. Claims in this piece rest only on these.

  1. Regulation (EU) 2024/1183 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework, OJ L, 30.4.2024Official Journal of the European UnionOpened and read in the parts cited, from the Publications Office's English text. Source for: Article 5a(1), the 24-month deadline tied to implementing acts under Articles 5a(23) and 5c(6); Article 5a(9) on revocation where security is compromised; Article 5a(15) on voluntary use and no disadvantage for non-users; Article 5b(1), (3), (8), (9) and (10) on registration, data limits, pseudonyms and intermediaries; Article 5c on certification; Article 5d on the list of certified wallets; Article 5f(2), including the micro and small enterprise exclusion, the 'including' list of sectors, the 36-month deadline and 'only upon the voluntary request of the user'; Article 5f(3), which carries no date; Article 5f(5) on the Commission's assessment; the definition of strong user authentication at Article 3(51); recitals 49, 56 and 62. Signed 11 April 2024; entry into force on the twentieth day after publication. The consolidated version of Regulation 910/2014 was not opened separately.
  2. Commission Implementing Regulations (EU) 2024/2977, 2024/2979, 2024/2980, 2024/2981 and 2024/2982 of 28 November 2024, OJ L, 4.12.2024Official Journal of the European UnionAll five opened for their headers, legal bases and entry-into-force articles: four adopted under Article 5a(23), one (2024/2981) under Article 5c(6); all published 4 December 2024 and in force on the twentieth day following, which is 24 December 2024 by this desk's count. 2024/2979 read in Articles 2 to 7: the definition of a wallet secure cryptographic device, Article 4(1) requiring at least one, Article 5(2) on embedded secure elements, Article 7 on revocation policies and the 24-hour notice. 2024/2981 searched rather than read in full: the recital and Article text on assumptions for hardware and platforms not provided by the wallet provider, and resistance to attackers with high attack potential. 2024/2977, 2024/2980 and 2024/2982 were not read beyond their headers and final articles.
  3. Commission Implementing Regulation (EU) 2025/848 of 6 May 2025 as regards the registration of wallet-relying parties, OJ L, 7.5.2025Official Journal of the European UnionOpened. Articles 3 to 7 and 11 read. Source for national registration policies, access certificates issued only to registered relying parties, and the statement that it applies from 24 December 2026, which is the Commission's own confirmation of the wallet date. Annexes not read.
  4. Commission Implementing Regulation (EU) 2025/846 of 6 May 2025 as regards cross-border identity matching of natural persons, OJ L, 7.5.2025Official Journal of the European UnionOpened for its final article only, which also applies from 24 December 2026. Nothing else in the piece rests on it.
  5. Commission Regulation (EU) 2023/1670 laying down ecodesign requirements for smartphones, mobile phones other than smartphones, cordless phones and slate tabletsOfficial Journal of the European Union, OJ L 214, 31.8.2023Opened and searched. Source for the operating system update requirement in Annex II (at least five years from end of placement on the market, conditional on the manufacturer providing updates at all) and for application from 20 June 2025. The body's claim that earlier models are outside it follows from that application date.
  6. European Digital Identity Wallet Architecture and Reference Framework, main branch, chapters 4 and 8European Commission and Member States, eudi-doc-architecture-and-reference-framework on GitHubOpened. Guidance, not law, and the body says so. Source for the four WSCD architectures (remote HSM, local external smart card, local internal SIM, eSIM or embedded secure element, local native via the operating system), the statement that a provider may use any of them, the caveat that an architecture does not imply certification, and the note that most existing identity cards cannot act as an external WSCD. Read from the main branch on 22 September 2026; the latest tagged release was v3.0.0. An editor should pin the citation to that release.
  7. Payments legislation on strong customer authentication (Directive (EU) 2015/2366 and its technical standards)Not opened. The body does not say what payments law requires; it says only that eIDAS leaves that question to it.
  8. Regulation (EU) 2022/1925 (Digital Markets Act), Article 6(7)Not opened for this piece. Cited only because recital 49 of Regulation 2024/1183 points to it.

Lead Pointed us at the story. Nothing here is cited as authority.

  1. Member state wallet rollout plansNot relied on. No national rollout status is printed in this piece because this desk opened no primary source for any member state.

Joris Feenstra

Hardware and previews

I cover energy, climate policy and the industrial politics behind Europe's transition, from grid bottlenecks to carbon border taxes. I get genuinely excited about a well-argued impact assessment.