The EUDI Wallet is often presented as Europe’s next major step in digital identity. What is emerging is a new market infrastructure for trusted digital interactions, in which citizens, public institutions, regulated entities, and service providers collaborate, each playing a distinct role.
- Its core objectives include:
- Giving users real control over their own personal data
- Making it easier for people and businesses to interact across EU borders
- Improving digital services offered by both public bodies and private companies
- Cutting down on bureaucracy and administrative red tape
By the end of 2026, all EU member states are expected to provide EUDI Wallets to their citizens, residents and organizations, and several countries have already launched pilot initiatives ahead of the rollout.
Work on the EUDI Wallet started back years ago, and it is currently being tested through large-scale pilot projects in Europe (Namirial Group is currently involved in the 2 new LSPs “Aptitude” and “We Build”, and was previously part of the now-closed projects “Potential” and “EWC”).
The EUDI Wallet will shape how identity is issued, how onboarding is performed, how compliance is managed, and how trust is embedded into digital customer journeys. It revolves around three core functions:
- Identification and Authentication: this covers a wide range of situations, from proving you are old enough to buy a ticket, to showing a driving licence at a checkpoint, to confirming your identity for an online or in-store payment.
- Exchanging User Attributes: users can request, keep and hand over their own personal data through the wallet, which effectively replaces the paper folder where such documents used to be kept, while giving users direct, secure control over who sees what.
- Electronic Signatures: users can also sign documents and transactions with qualified electronic signatures directly from the wallet.
Understanding the EUDI Wallet, therefore, means understanding the ecosystem behind it. The key question is not only what the wallet is, but who makes it work, how the various actors interact, and where organisations can position themselves. This article outlines the main actors in the EUDI Wallet ecosystem and the role each of them plays.

The user: the focal point of the ecosystem
The wallet user stands at the centre of the ecosystem: the individual who controls the wallet and decides when and how to use it. The User (Wallet Unit Holder) manages, stores, and presents:
- Person Identification Data (PID), and
- Qualified/Non-qualified electronic Attestations of Attributes (QEAA, EAA).
EAA is digitally signed and confirms specific characteristics (the attributes) about a person (or organization). Examples of EAA are a university diploma, professional license, or proof of address. Unlike Person Identification Data, an EAA does not prove who you are, but rather that a specific fact or qualification about you is true.
The logic of the EUDI Wallet is built around a strong principle: users must remain in control of their digital identity and of the data they choose to share. They decide when to identify themselves, whether to present the attributes requested, and with whom to share them. Specifically, the Users are responsible for:
- Deciding how to organise their digital identity, including which credentials go into which wallet, since a person can hold more than one
- Giving explicit consent each time specific data is shared with a relying party
- Creating their own electronic signatures and seals
The users always have control over their data: selective disclosure lets them share only the specific attributes a given service actually requires, and no attribute ever leaves the wallet without their explicit consent.
Wallet providers: those who supply the solution
A Wallet Provider is either a Member State itself, or an organisation that a Member State has mandated or formally recognised. Its job is to distribute a working wallet solution to users. In addition to EUDI Wallet Providers following this scheme, there are also private wallets issued by private companies that do not necessarily fall under the EUDI Wallet framework and may be used within closed circuits, generally referred to as private or closed wallets. Examples include corporate wallets used to manage employee authentication and logical or physical access control (e.g. login to company systems, building or badge access), as well as wallets used within a network of mutually recognised entities, such as supply-chain partners, industry consortia, or federated organisations that trust each other’s credentials.
Wallet providers are responsible for:
- making sure the user keeps sole control over their Person Identification Data (PID), their Electronic Attestations of Attributes (QEAA, PuB-EAA or EAA), and any other personal data held in their Wallet Unit
- making sure the private keys and other sensitive cryptographic material tied to that Wallet Unit stay solely under the user’s control
- undergoing the certification of the wallet solution (the certification schema is in definition phase)
For organisations looking at the market, this role opens a broad set of opportunities. Some may aim to act directly as wallet providers, where the national model allows it, since as anticipated above wallets may be issued by public authorities or by private entities recognised by Member States. Others may contribute wallet technology, integration components, or white-label services that allow wallet propositions to be launched more quickly and at scale.
Issuers
An issuer (or provider) is whatever organisation or body puts digital credentials and attributes into the EUDI Wallet in the first place. This can range from public authorities (issuing personal identification or driving licence), to private entities (such as banks or insurance companies), or to a university awarding diplomas. Before issuing anything, issuers first authenticate and verify the user and/or the data involved, then package the result as a signed, verifiable digital credential. Because the issuing entity is itself trusted, the resulting credentials come with a strong assurance level and are protected with a cryptographic electronic signature.
One of the founding principles of the EUDI Wallet is untraceability (or unlinkability): once a credential is created by the issuer, the issuer loses visibility into how and where it gets used afterwards. A university that issues a diploma credential, for instance, is not informed each time a graduate presents it.
Credentials generally fall into three main categories, depending on the issuer (also referred to as a “provider”) and the associated level of assurance:
- Personal Identification Data (PID): each member state designates a single PID provider, whose task is to supply the Person Identification Data needed to activate an EUDI Wallet and confirm the identity of a natural person (identification of a legal person falls under the separate Business Wallet track).
- Qualified electronic attestations of Attributes (QEAA), for example tax records, mobile driving licence, or a bank IBAN, issued by qualified trust service providers (QTSP). To reach that high level of assurance, QTSPs draw on so-called Authentic Sources: repositories or systems, managed by public or private entities, that hold verified attributes about people or objects and are recognised under EU or national law as primary references for that information.
- Non-qualified electronic attestations of attributes (EAA), such as membership or customer cards or employee passes. There are no specific requirements for issuing credentials of this kind, since virtually any organisation is free to issue them, so the variety in practice is open-ended.
- Public electronic attestations of attributes (Pub-EAA), such as residency confirmations, professional licences, or civil status records, issued by or on behalf of a public sector body responsible for an authentic source. These carry the same legal effect as an equivalent attestation lawfully issued in paper form, since the issuer’s status as the authoritative source of the attribute gives the attestation an inherent presumption of accuracy that ordinary EAAs lack.
In all cases, Issuers transform trusted information into digital credentials that users can store in the wallet and present to online services when needed. The main distinction between the above mentioned attestations is the applicable assurance level and legal value.
A QEAA is issued by a Qualified Trust Service Provider (QTSP), which is formally audited and certified, and must meet the technical and procedural requirements set out in Annex V of the Regulation (Art. 45c). Because of this, a QEAA benefits from a legal presumption of authenticity and integrity: under Art. 45d(2), a QEAA (as well as attestations issued by or on behalf of a public sector body responsible for an authentic source) has the same legal effect as a lawfully issued attestation in paper form. This means courts and public authorities across the EU must accept it without the relying party needing to prove anything further about its trustworthiness — the burden of proof, if challenged, shifts to the party disputing it. This reliability is reinforced by Art. 45e, which requires QTSPs to be able to verify attributes electronically against the relevant authentic source.
An EAA, by contrast, is issued by a non-qualified provider. It can still be legally valid and admissible as evidence in proceedings — Art. 45d(1) establishes that an electronic attestation of attributes shall not be denied legal effect or admissibility as evidence solely because it is in electronic form or because it does not meet the QEAA requirements — but this is only a “non-discrimination” floor, not equivalence. If its authenticity or integrity is challenged, the burden falls on the party relying on it to demonstrate that the attestation is trustworthy, accurate, and was issued through a reliable process. There is also no guaranteed cross-border mutual recognition obligation, unlike for QEAAs.
In short: QEAA (Arts. 45c, 45d(2), 45e, Annex V) shifts the burden of proof onto whoever challenges it and guarantees EU-wide recognition; EAA (Art. 45d(1)) leaves the burden of proof on the party relying on it and offers no automatic cross-border recognition guarantee, even though its content can be just as accurate in practice.
This is a crucial step, because it makes verified data portable and reusable across multiple services and contexts. Without a strong issuer ecosystem, the wallet would largely contain only Person Identification Data and a limited set of information issued directly by public authorities. That would significantly narrow its range of applications. By contrast, a mature issuer ecosystem opens the door to a much broader set of use cases, from age verification and proof of professional qualifications to entitlements and sector-specific credentials.
Relying parties
If users present (technical term for “share”) data and attestations, someone on the other side must be able to receive and verify them. Relying Parties (or verifiers) are public or private entities that intend to rely on the wallet by requesting and validating data or credentials, and using the results to deliver a service through digital interaction.
In short, an RP is any organisation that needs to extract information out of a user’s wallet to do business with them, whether that is a car rental company checking a licence, a bank running onboarding checks, or a public administration confirming eligibility for a service.
Organisations in the Art. 5f sectors — such as banking, telecoms, healthcare, energy, transport and education — will have to accept the EUDI Wallet from 24 December 2027 in any situation where the law demands strong user authentication (SCA). In practice, this means these organisations must themselves become Relying Parties. To do so, they need to complete a registration process towards the Member State of establishment and state the purpose and scope of the data requested (declaring which attributes they intend to request).
This is essential to uphold the EUDI Wallet’s founding principles of data minimisation and sovereignty for users.
Information about relying parties must be public through specific Registries, available in both human-readable and machine-readable form. The rules also provide that the user must be able to verify the relying party’s registration data, and that the wallet may warn the user if more information is being requested than what was registered or authorised.
For businesses, this is perhaps the most relevant point. In the EUDI ecosystem, it is not enough simply to accept the wallet. Companies must embrace a logic of justified, proportionate, and transparent data requests. This is the role most businesses will recognise immediately, because it connects directly to real operational moments: customer onboarding, strong customer authentication, KYC, access control, delegated authority checks, age verification, and digital service access. In these scenarios, the wallet is not simply an identity tool. It becomes an operational interface for consuming trusted information.
This role becomes even clearer when translated into sector-specific scenarios. In insurance, relying parties may use wallet-based credentials to streamline customer onboarding, eligibility checks, policy activation, or claims-related identity verification. In financial services, the wallet can support KYC and customer onboarding by allowing users to present verified identity data and relevant attributes in a reusable and privacy-preserving way. In HR and enterprise environments, it can enable employee onboarding, access to internal services, role-based permissions, and professional credential checks. In the public sector, relying parties may use the wallet to grant access to e-government services, benefits, permits, or citizen portals. And the example can continue to several more sectors and use-cases.
That is why becoming a relying party is about more than technical acceptance. It requires the ability to integrate credential requests and verification steps into business processes, customer journeys, and compliance flows, while keeping pace with ongoing technical and regulatory developments. For many organisations, this will be the first concrete entry point into the EUDI ecosystem.
Intermediary RP: the role that accelerates adoption
The Intermediary is going to cover an increasingly important role. In a few words, intermediaries form a special class of Relying Party. Article 5b (10) of the European Digital Identity Regulation states “Intermediaries acting on behalf of relying parties shall be deemed to be relying parties and shall not store data about the content of the transaction”. An Intermediary is a party that offers services to Relying Parties to, on their behalf, connect to Wallet Units and request the User attributes that these Relying Parties need. The intermediary then sends the presented attributes to the intermediated Relying Party. This implies that an intermediary performs all tasks assigned to a Relying Party in the ARF on behalf of the intermediated Relying Party, facilitating the entry into the EUDI Wallet ecosystem.
Intermediaries help reduce the friction of ecosystem participation. They can support integration, service orchestration, trust flow management, credential exchange, verification enablement, and the connection between business processes and regulatory requirements. In practice, they help organisations participate in the ecosystem without having to build every layer from scratch.
This role is especially relevant in a market that is still moving from framework definition to real deployment. Many participants will need:
- a faster route to implementation,
- avoiding high setup investments (setting up a team and an infrastructure) in favour of operating costs proportional to the amount of the effective EUDI Wallet transactions,
- a way to bridge legacy systems with wallet-based interactions
- support in coordinating multiple roles across the trust chain.
That is where the Intermediary can become a real accelerator, acting on behalf of those service providers that prefer to “buy” instead of “build”, to
- maintain their focus on the core business, and
- outsource the costs related to technology updates (to support standards, protocols and ecosystem evolution) and the compliance risk
In this area, it will be increasingly important to rely on partners that can deliver not only an EUDI-compliant solution, but also the right combination of regulatory expertise and technological capability.

Trust infrastructure actors: the hidden layer that guarantees reliability
The EUDI ecosystem also depends on actors that are less visible to end users but fundamental to secure operation. These include the Registrars and other trust infrastructure players that are a fundamental part of a trusted ecosystem able to guarantee full trust among all actors.
Their role is to make trust machine-readable and enforceable. They ensure that interactions are not based on assumptions, but on recognisable trust signals that can be validated across the ecosystem. This layer is essential for scale, because interoperability without reliable trust metadata quickly becomes fragile.
Such a delicate ecosystem also requires independent oversight. Wallet-related solutions must operate within assurance frameworks covering functionality, cybersecurity, and data protection. This external validation is what allows trust to scale across sectors and borders.
For organisations assessing the market, this means that value will not only be created at the user interface level. A significant part of the ecosystem will depend on infrastructure capabilities that make trusted interactions possible behind the scenes.

EUDI Wallet: an ecosystem of public and private actors
EUDI Wallet should not be seen as an isolated product or platform, but as a trust ecosystem to which several actors contribute: the user controls the data; Member States guarantee the institutional framework; Wallet Providers supply the solution; identity and attribute issuers create reliable evidence; relying parties consume that evidence; and trust infrastructure actors make the whole system interoperable, verifiable and scalable.
For businesses, preparing for the EUDI Wallet does not simply mean integrating a new authentication option. It means understanding which role to play in the ecosystem. Wallet Provider, issuer, verifier, intermediary, trust service provider, technology partner: each position implies different responsibilities, opportunities, and operating models.
In this evolving landscape, turning regulatory clarity into operational readiness will be a key success factor for ecosystem participants. That is exactly what the Namirial Wallet Platform is designed to support: helping organisations address the different operational roles emerging within the EUDI ecosystem through a technology foundation for trusted, interoperable, and compliant digital identity services.
Namirial value

As a leading European and global QTSP, Namirial has invested significant effort in developing the Namirial Wallet Platform, specifically designed to cover all the roles of the EUDI Wallet ecosystem.
Structured in three main components, the Namirial Wallet Platform enhances adoption and acts as an accelerator for organisations that want to join the EUDI Wallet framework.
To discover more about the Namirial Wallet, please register to our open Global Sandbox or visit the Namirial Wallet page and get more information by clicking the “contact us” button.




