Table of contents

Business Wallet: Europe’s Missing Trust Layer (and how Namirial is ready)

For years, Europe’s conversation about digital identity has revolved almost entirely around individuals. The European Digital Identity Wallet has rightly been celebrated as a landmark achievement: a mechanism allowing citizens to identify themselves securely, share verified attributes, and access services across borders without friction. It is a bold step forward. But as the European digital framework matures, a broader realization is quietly gaining ground: if individuals need wallets to interact digitally, businesses need them even more.

This is the premise behind the European Business Wallet initiative: not a parallel project to the citizen wallet, but a critical and complementary layer in Europe’s evolving digital infrastructure. And it arrives at exactly the right moment.

Why now?

Despite decades of digitalization efforts, most business interactions across the EU still rely on processes that would feel familiar to someone working in a Brussels notary office in 1995.

  • Registry extracts circulate as PDFs.
  • KYC and KYB checks are repeated from scratch every time a company crosses a border or enters a new ecosystem.
  • The authority of a representative to act on behalf of a company, something fundamental to every business transaction, is verified through manual checks, national registries, or paper-based documentation that has no legal force outside its country of origin.

The European Commission itself has acknowledged the scale of the problem: businesses, particularly SMEs (which represent 99% of all EU companies), still spend an enormous share of their time on administrative procedures rather than on innovation and growth. This is not merely a question of inefficiency. It is a structural gap. Europe has digitalized many of its procedures, but it has not yet digitalized the trust layer that underpins them.

The result is a paradox: we have electronic signatures, digital portals, online company registrations, yet we still cannot reliably verify, in real time and with legal effect, that a given company exists, holds a particular license, or that the person signing a contract on its behalf actually has the authority to do so.

The EU Inc. driver

The European Union’s digital agenda, through initiatives such as the Digital Compass, the European Digital Identity Wallet (EUDI Wallet), and the proposed 28th regime for companies (EU Inc.), pursues a common objective: increasing Europe’s competitiveness by simplifying cross-border interactions.

Just as the EUDI Wallet aims to make identity management seamless for citizens, the 28th regime seeks to reduce complexity for businesses by enabling more efficient B2B and B2G processes across the Single Market.

To achieve these objectives, however, companies require trusted digital mechanisms to identify themselves, share verified information, prove representation rights, and exchange legally valid documents across jurisdictions and ecosystems. This is precisely where the European Business Wallet comes in.

Business Wallet: what is it and what does it actually do?

If citizen wallets solve identity, Business Wallets must solve something harder: identity plus representation. This is where most of the real friction lies, and it is also where most of the legal risk accumulates. Without a reliable representation layer, you can verify that a company exists, but you cannot trust the transaction.

The Business Wallet promises to address this by creating a verifiable, portable mechanism for delegated authority. Under the Commission’s proposal, the European Business Wallet is conceived as the operational infrastructure through which legal entities can identify themselves, prove representation rights, exchange verified business credentials and conduct trusted digital transactions across Europe. It means that when a CFO signs a contract, or a logistics manager submits a customs declaration, the counterparty can verify instantly and with legal certainty that this person genuinely has the authority to do so.

The practical value of this model is already visible in initiatives being carried out within the WE BUILD Consortium, where organizations are already experimenting across multiple business domains. Companies are testing how a wallet can support Know Your Customer (KYC), Know Your Supplier (KYS) and Know Your Employee (KYE) processes, establish cross-border business relationships, register foreign branches, obtain VAT registrations, access public services, and exchange electronic invoices. In these scenarios, legal entities receive and use credentials such as the European Business Wallet Object Identifier (EBWOID), company registry attestations, VAT identifiers, business licenses and other verifiable business data that can be presented and validated across borders without repeating the same onboarding and verification procedures for every interaction. A representative may, for example, establish a foreign subsidiary, submit a VAT declaration, access a public administration portal, or authorize an intermediary to act on behalf of the company. In all these cases, the relying party must be able to verify not only the identity of the organization, but also the chain of authority linking the acting person to that organization.

The proposed Regulation published in November also goes beyond identity and credentials. It foresees interoperability with other qualified trust services, such as the Qualified Electronic Registered Delivery Services (QERDS), to support trusted business communications, as well as integration with electronic invoicing. This latter dimension is particularly relevant considering the VAT in the Digital Age (ViDA) initiative, which will progressively increase the importance of interoperable and trusted digital exchanges between businesses and tax administrations across the EU by 2030. This direction is reflected in the WE BUILD SC5 use case (eInvoicing), for which Namirial serves as co-lead. Within this context, pilot participants are testing direct eInvoicing scenarios, exploring how invoice exchange, wallet-held attestations, and QERDS-based delivery mechanisms can operate together within a trusted European ecosystem.

From policy to reality: the Portugal signal

The transition from concept to live infrastructure is already underway. Portugal has become the first EU country to launch a functioning Digital Business Wallet, integrated into the national gov.pt platform. The solution centralizes official company data, including tax status, registration details and compliance information, and enables real-time validation with legal effect.

This is significant not just as a milestone, but as proof of concept. It demonstrates that the Business Wallet can move from regulatory aspiration to operational reality, replacing multiple disconnected portals with a single access point, replacing static documents with real-time verifiable data, and embedding trust directly into the interaction rather than treating it as something to be verified separately.

The broader architecture: pieces of the same puzzle

Taken together, recent European developments are not isolated initiatives, they are the outlines of a coherent, digital-by-default architecture for the Single Market.

The EUDI Wallet provides portable identity for individuals. EU Inc., together with the forthcoming corporate legal framework of the 28th regime, creates a digital-first foundation for company formation and operation across the Single Market. The Business Wallet provides the operational trust layer that makes it possible to run a company across borders with the same ease as creating one: storing the EU company certificate, executing the EU Digital Power of Attorney, and delegating authority to representatives with legal certainty. These elements reinforce one another, and the Business Wallet is the connective tissue that binds them together.

The Commission has estimated that widespread adoption could unlock up to €150 billion in annual savings, through the cumulative effect of eliminating duplicated compliance procedures, accelerating B2B onboarding, enabling automated regulatory checks, and making trusted data exchange seamless across value chains.

The road ahead: European rollout

The legislative process has moved faster than many anticipated.

The European Commission published the proposal for a Regulation on European Business Wallets on 19 November 2025 (COM(2025) 838). More recently, the Council of the European Union adopted its general approach on 9 June 2026, reflecting the Member States’ view of how the Regulation should be structured. The European Parliament’s ITRE Committee is working through more than 200 amendments and is expected to finalize its position around October 2026. At that point, trilogue negotiations will begin, with all three institutions aiming to reach agreement before the end of 2026.

The main differences between the Council’s text and the Commission’s proposal concern several key articles. On representation (Article 3), Member States replaced the term “mandate”, which has a specific legal meaning under eIDAS, with “authorization”, giving it a broader definition that allows use-case-specific approaches without being tied to the eIDAS mandate framework. Legal equivalence (Article 4) was narrowed: it now applies only to qualified services and to the core functionalities of the European Business Wallet.

Regarding onboarding (Article 6), the Council raised the level of assurance required. While the Commission allowed identification at either Substantial or High assurance level, Member States now require the High level and specify that identification must be carried out by a legal representative.

Article 7 introduces a mandatory risk assessment for European Business Wallet providers and tasks the Commission with drafting an implementing act defining concrete acceptability criteria, making the requirement that the wallet must pose no threat to the European Union operationally enforceable.

Article 10 requires providers to verify their users’ essential data every 72 hours against authentic sources, ensuring the integrity of the lookup register that other parties rely on to route communications.

On supervision (Article 11), the Council moved from a notification system to a prior authorization model: every provider, including existing QTSPs, must undergo an actual assessment by the National Supervisory Body before being allowed to operate. Importantly, the silence of the Supervisory Body does not constitute automatic approval. Member States also retain the right to designate their own Supervisory Body (Article 13).

Article 16, concerning mandatory acceptance by Public Sector Bodies (PSBs), has been revised in two important respects. First, the obligation for a Public Sector Body to accept European Business Wallet interactions will be triggered by implementing acts rather than by the Regulation itself, reflecting lessons learned from the implementation of eIDAS. Second, the original Articles 16.2 and 16.3, which required Public Sector Bodies to provide a QERDS channel within three years, have been removed. Public Sector Bodies will have to accept the channel, but they will not be required to offer it.

Regarding interoperability, instead of mandating a single QERDS solution, the Council requires the Commission to designate open protocols and standards, leaving room for multiple compliant implementations.

As for the timeline, the overall picture has remained stable: the schedule outlined six months ago is still on track. Once the European Parliament votes in October, trilogue negotiations will begin immediately. All parties involved, the Council, Parliament and Commission, share the objective of concluding negotiations before Christmas 2026. After that, the Commission will lead the process of developing the implementing acts through an expert group involving Member States, with the first package of implementing acts expected between the first and second quarters of 2027.

Articles that are not disputed by the main institutions are likely to remain unchanged throughout the trilogue negotiations, while discussions will focus on those provisions where the three texts genuinely diverge.

The Parliament’s position, currently being consolidated within the ITRE Committee, will add a third set of requirements to the legislative framework. Its final content will only become known after the October vote, but it will undoubtedly become one of the central elements of the trilogue negotiations alongside the positions of the Council and the Commission.

Namirial Wallet Platform: a comprehensive solution for digital identity

When the Business Wallet framework began to take shape, it did not require us to change direction; it simply validated the path we had already chosen.

The Namirial Wallet Platform was designed from the ground up as a comprehensive solution covering both natural persons and legal entities. This dual scope is not a capability added in response to the Business Wallet initiative; it reflects our conviction that identity in a business context has always been more complex than individual identity, requiring the management of organizational hierarchies, mandates, certificate lifecycles, and multi-party interactions.

In practical terms, the platform enables the complete lifecycle management of verifiable credentials for legal entities, from issuance and storage to sharing and revocation. It supports delegated authority through cryptographically verifiable mandates, allowing organizations to manage representation chains across roles, geographies and regulatory contexts. It integrates natively with existing identity infrastructures, including national identity providers, company registries and Qualified Trust Service Providers, meaning it can be deployed within existing compliance frameworks rather than replacing them.

For organizations already operating in regulated environments, the platform provides a governed path to full Business Wallet readiness: one that respects existing legal frameworks, integrates with current onboarding and KYB procedures, and scales from SMEs entering cross-border operations for the first time to large enterprises managing identity infrastructures across multiple jurisdictions.

The European Business Wallet is not simply a digitalization project. It represents a fundamental shift in how trust operates within the economy: from something that must be recreated at every interaction to something that travels with the company, in a portable, verifiable and legally robust way across the entire Single Market.

This is not a distant vision. With the Council’s general approach now adopted and trilogue negotiations about to begin, the regulatory framework is entering its final legislative phase. The Namirial Wallet Platform is already positioned to support organizations as this new infrastructure takes shape, helping them move from fragmented, document-heavy processes to a model where trust is embedded in every interaction, from the first onboarding to the thousandth cross-border transaction.

Other articles