EU Digital Identity
The EU Digital Identity Wallet, for relying parties
The EU Digital Identity Wallet is coming to all 27 member states under the eIDAS update. Here's what it is, a straight read of the timeline, and what relying parties actually need to accept it.
At a glance
- Law
- Regulation (EU) 2024/1183, amending eIDAS 910/2014
- In force
- 20 May 2024
- Wallets available
- Each member state within 24 months of the implementing acts, around end of 2026
- Acceptance
- Regulated relying parties within 36 months, around end of 2027
- For citizens
- Voluntary. Other identification methods stay available
- Formats
- SD-JWT VC and ISO 18013-5 mdoc, over OpenID4VP
What the wallet is
The EU Digital Identity Wallet is a state-backed app that holds verified credentials, from a national ID to attributes like being over 18. The point of it is selective disclosure. Instead of handing over a whole document, the user shares only the fact that is asked for, with a cryptographic proof that it is genuine and unaltered.
For a business that needs to check something about a person, that changes the shape of the problem. You ask a question, the wallet answers it, and you can trust the answer without collecting and storing the underlying identity data.
The timeline, realistically
The regulation has applied since 20 May 2024. The deadlines that follow are tied to the implementing acts, the first batch of which entered into force around 24 December 2024. Each member state has to make at least one wallet available within 24 months of those acts, which lands around the end of 2026. Regulated relying parties have to accept the wallet within 36 months, which lands around the end of 2027.
Two caveats worth stating. Those dates are derived from the 24 and 36 month clocks rather than fixed in the text, and rollout across 27 member states is likely to be uneven. And using a wallet is voluntary for citizens, so real users will not all have one on day one. That is why a fallback method still matters, and why Tessio ships with one.
What relying parties have to accept
The acceptance duty is not on everyone. Under Article 5f it falls on private relying parties, other than micro and small enterprises, that are required by law or contract to use strong user authentication for online identification. The regulation names the sectors, including banking and financial services, transport, energy, health, telecommunications and more.
If you are one of those relying parties, you will need to accept the wallet when a user chooses to present it. In practice that means running a verifier that can speak the wallet protocols and check the credential against a current trust layer.
What you need to verify a wallet
To accept a wallet credential you need a verifier that speaks OpenID4VP and understands both mandated credential formats, SD-JWT VC and ISO 18013-5 mdoc. You also need a trust layer that stays current as member states and issuers come online, so you know a credential really was issued by who it claims.
That is what Tessio is. A hosted verifier and trust layer for age and identity checks, with an open source .NET core you can self host if credentials cannot leave your environment.
Where Tessio fits
Tessio is built on the EU Digital Identity Wallet standards, so accepting a wallet is the thing it does rather than a feature bolted on. You integrate once and stay ready as wallets roll out, instead of re-integrating a document based tool later.
For age specifically, Tessio returns a signed over-18 yes or no and stores no personal data. If you are a regulated relying party planning your 2027 rollout, or you just want a wallet native age check now, that is the fit.
Frequently asked
When do businesses have to accept the EU Digital Identity Wallet?
Regulated relying parties that must use strong user authentication have to accept the wallet within 36 months of the relevant implementing acts, which lands around the end of 2027. That date is derived from the implementing-acts clock rather than fixed in the regulation, and acceptance applies when a user chooses to present the wallet.
Is the wallet mandatory for everyone?
No. Using a wallet is voluntary for citizens, and other identification methods stay available. The obligation is that each member state makes a wallet available, and that regulated relying parties accept it when a user presents it. That is why a fallback method still matters in practice.
What do I need to verify a wallet credential?
A verifier that speaks OpenID4VP and understands SD-JWT VC and ISO 18013-5 mdoc, plus a trust layer that stays current as issuers come online. Tessio provides both, hosted or self hosted on .NET.
Primary sources
This is a plain language summary, not legal advice. Check your own duties against the primary sources and your regulator.
Put it into practice
Age verification for iGaming
Betting and gaming
Age verification for age restricted retail
Nicotine, vape and alcohol
Age verification for adult platforms
Adult content
UK Online Safety Act age assurance
UK regulation
EU Digital Services Act and age assurance
EU regulation
Tessio for compliance
For compliance, legal and DPOs
Age verification API
Get ready with a wallet native check
Tessio proves someone is over 18 from their EU Digital Identity Wallet and stores no personal data. Access is invite only while we onboard design partners. Tell us what you're building.