Private companies that are legally required to identify customers with strong authentication – banks, payment and crypto firms, telecoms, energy and utilities, insurers, healthcare providers, transport and very large online platforms – must accept the EU Digital Identity Wallet when a user offers it, in addition to their existing methods.
Who is affected
Regulated service providers in finance, telecom, energy, health, transport and large platforms, of any size.
Sizes: micro, small, medium, large · Sectors: Finance / insurance, Energy, Health, Transport / logistics, Media / marketing, Software / SaaS · Applies if: We process personal data; We deal with crypto-assets; We run a platform / marketplace
What to do
Add wallet-based login and KYC to your onboarding and strong-authentication flows using the EU reference standards, and register as a relying party in your Member State's register. Test with your national wallet pilots during 2027.
Penalty
Supervisory measures under national eIDAS enforcement
24 months after the implementing regulations of 2024-11-28 (Art. 5a Reg. 2024/1183); the Commission communicates it as 'end of 2026'
No direct obligation on private businesses yet; companies dealing with public authorities and those doing KYC/onboarding should prepare to accept wallet-based identification.