Understanding the EUDI Wallet Model
The Wallet is a user-controlled digital tool. It enables users to:
- Receive, store, and manage verified identities and attributes;
- Present this information to third parties selectively (minimal disclosure / selective disclosure);
- Guarantee the authenticity and integrity of shared data;
- Ensure verifiable proof through cryptographic mechanisms;
- Function seamlessly within an interoperable ecosystem across Member States.
The model relies on three main actors:
| Role | Function |
| Attribute Providers / Issuers | Deliver verified identities or attributes (e.g., public administrations, professional bodies). |
| Wallet Providers / Operators | Provide and maintain the digital wallet application for the end-user. |
| Relying Parties (Verifiers) |
Receive and validate the identity and attributes presented by the user. |
EUDI Wallet and Qualified Electronic Attestations of Attributes (QEAA)
Beyond core government-issued civil identity, the operational engine of the eIDAS v2 Regulation relies on the wallet's ability to securely store and share digital credentials issued by third parties, known as Electronic Attestations of Attributes (EAA).
Technically governed by Implementing Regulation (EU) 2025/1569, this system enables authentic sources (administrations, universities, professional bodies, banks) to deliver Qualified Electronic Attestations of Attributes (QEAA). The conformity audit conducted by LSTI validates the robustness and alignment of issuer and Wallet provider infrastructures to guarantee the integrity, origin, and non-repudiation of these attributes across Europe.
Learn more about eIDAS certification for Qualified Electronic Attestations of Attributes (QEAA)
Regulatory Framework of the eIDAS v2 EUDI Wallet
The conformity assessment and security audit of the European Digital Identity Wallet (EUDI Wallet) are strictly guided by the regulatory architecture dictated by the European Commission's Implementing Regulations, supplemented by technical ETSI standards:
| Reference | Main Purpose |
Scope within the Wallet ecosystem |
| Implementing Regulation (EU) 2024/2982 | European Implementing Act | Sets the mandatory protocols and technical interfaces (APIs) for wallet interoperability. |
| Implementing Regulation (EU) 2024/2979 | European Implementing Act | Frameworks the assessment requirements for the security integrity and core functionalities of the Wallet. |
| Implementing Regulation (EU) 2025/1569 | European Implementing Act | Defines the framework applicable to electronic attestations of attributes provided by the public sector and authentic sources. |
| ETSI EN 319 401 | General Requirements | Assesses the organizational framework, logical security, and overall governance of the provider operating the back-end system. |
| ETSI EN 319 412 | Identity Profiles | Ensures the standardized structuring of attributes and identifiers within the wallet. |
| ETSI TS 119 461 | Identity Verification | Specifies security requirements relating to the initial user enrollment and onboarding procedures into the Wallet. |
| ETSI ESI Series (119 67x / 119 68x) | Technical Modules | Determines the final interoperability formats and data exchange models (currently being finalized). |
Strategic Stakes for Wallet Providers
For developers and providers of Wallets, achieving eIDAS v2 certification with LSTI addresses critical business and compliance challenges:
- Authorization for EU Market Entry: Without a positive Conformity Assessment Report (CAR) issued by an independent body, the software solution can neither be notified by a Member State nor listed on official European registries.
- ARF (Architecture Reference Framework) Compliance: Proving that the solution strictly respects the latest ARF requirements for interoperability, secure local storage, and privacy protection (selective disclosure, unlinkability, and anti-tracking mechanisms).
- Achieving the "High" Level of Assurance: Verifying that the wallet app successfully resists advanced physical and logical attacks on mobile devices (iOS/Android) and absolutely protects identification data.
Who is this Service Aimed At?
This ecosystem encompasses all organizations involved in digital identity and the issuance of verifiable credentials:
- Wallet Providers / Operators (public entities or authorized private structures);
- Digital Identity Providers (IdPs);
- Qualified Attribute Providers (administrations, professional bodies, certifying institutions);
- Digital Service Providers wishing to accept or verify identities or attributes via the EUDI Wallet (Relying Parties);
- Public Organizations driving digital transformation.
Your Questions About the EUDI Wallet (European Digital Identity Wallet)
-
What is a verifiable credential in the EUDI Wallet?
A Verifiable Credential is the secure, tamper-proof digital counterpart of a physical document or a traditional attestation. It can be a driving license, a company registry extract (Kbis), a university diploma, or a social security entitlement card. Thanks to the standardized interoperability protocols mandated by the eIDAS v2 Regulation, the EUDI Wallet allows users to centralize all of these certified documents and attributes within a single mobile application -
How does the EUDI Wallet present a verifiable credential?
During an identity check or a remote onboarding journey (KYC - Know Your Customer or KYB - Know Your Business processes), the wallet utilizes advanced cryptographic mechanisms to present the required information to a third-party verifier (Relying Party). This system allows the verifier to instantly validate, in the background, both the authenticity of the credential and the legitimacy of the issuing organization. This exchange process is decentralized, ensuring that no intermediary data is stored by a third party or shared without the user's explicit consent. -
What guarantees does the EUDI Wallet provide regarding privacy protection?
Regarding privacy protection, the European Digital Identity Wallet embeds Privacy by Design principles and selective disclosure natively. Unlike traditional physical identity checks where a user must show an entire document (revealing their full name, date of birth, and address), the EUDI Wallet allows the user to prove a single attribute (e.g., "being over 18" or "holding an active professional license") without disclosing any other personal details. Furthermore, the technical architecture strictly prohibits attribute issuers or the State from tracking the user's wallet usage history, guaranteeing that daily interactions remain completely confidential. -
Is the use of the European Digital Identity Wallet mandatory for citizens and businesses?
Using the European Digital Identity Wallet (EUDI Wallet) is entirely voluntary for European citizens. No public or private service can restrict access to a right or penalize a user who chooses not to use it. Conversely, the eIDAS v2 Regulation imposes a strict obligation of acceptance on public administrations as well as Very Large Online Platforms (VLOPs) (such as major social networks, e-commerce giants, banking institutions, and transport services). These entities are legally required to integrate the EUDI Wallet as an authentication and identity verification method if the user chooses to utilize it to access their services. -
Is the use of the European Digital Identity Wallet mandatory for citizens and businesses?
Using the European Digital Identity Wallet (EUDI Wallet) is entirely voluntary for European citizens. No public or private service can restrict access to a right or penalize a user who chooses not to use it. Conversely, the eIDAS v2 Regulation imposes a strict obligation of acceptance on public administrations as well as Very Large Online Platforms (VLOPs) (such as major social networks, e-commerce giants, banking institutions, and transport services). These entities are legally required to integrate the EUDI Wallet as an authentication and identity verification method if the user chooses to utilize it to access their services. -
What is the difference between the EUDI Wallet and current private digital identity solutions?
The EUDI Wallet stands out through its legal status and governance model. The framework is governed directly by EU Member States and is strictly backed by a civil identity officially verified by competent public authorities. The EUDI Wallet enjoys mandatory legal validity across all administrations and institutions in the European Union for performing official online procedures. In terms of data management, the regulatory framework prohibits commercial exploitation, profiling, or the resale of personal information, ensuring that the user retains exclusive control over their identity data.
Why Choose LSTI?

Recognized expertise
With more than twenty years of experience, LSTI supports more than 300 organizations in France and across Europe as a certification body and leading assessment center, operating in the fields of cybersecurity, digital trust, and information security.

Specialized Auditors
Our audit teams are composed of experienced professionals who are well-versed in ANSSI’s cybersecurity standards, information security management practices, and European digital trust frameworks. Their approach ensures rigorous, balanced assessments that are tailored to each organization’s operational context.

Independent Third Party and Dedicated Support
Accredited by ANSSI, LSTI ensures impartiality, transparency, and consistency throughout the entire process: preparation, audits, monitoring, and renewals. A dedicated point of contact ensures continuity and clarity throughout the certification process.




