Identity Success Story – itsme Belgium

This is the fourth case study I have written on inational identity efforts. The first was India’s UIDAI, which I covered in Payments and Identity, UPI continues to lead the world. The second was Norway, in BankID Norway, Evolution and Success, last month i outlined eIDAS, Top 3 Problems. Belgium’s itsme is a fantastic collaboration of banks and mobile operators in a commercial model, it may be the cleanest available proof of my rule of thumb on identity success (see Part 1 – Identity Models, Government and Governance Structures).

Summary of today’s thesis: European digital identity is succeeding at the country level, wherever commercial entities are allowed to own the governance and the economics, and it is failing at the EU and regulatory level, where neither is defined (or mandates set). Belgium is NOT a counterexample to Europe’s identity problem. In my view, Belgium represents an example model for the answer Europe is looking for.

Short History

Belgian banks and mobile operators formed the Belgian Mobile ID consortium in 2016 and launched itsme in 2017. In April 2020 the European Commission published a case study on the scheme. At that point itsme had 1.6 million users, roughly 30% of the Belgian population, and was processing 5 million transactions per month. It connected to more than 2,000 public service applications, and around 30% of all Belgian public administration transactions ran through it.

Six years later, usage has exploded:

Measure2020 (European Commission)2025 results (itsme)
Users in Belgium1.6 million (~30% of population)8 million+ (over 80% of adults)
Actions5 million per month~50 million per month (594 million annually)
Daily volumenot stated1.6 million actions per day
Growth in actionsbaseline+25% versus 2024
Corporate profitnot statedover €7 million, +25% year over year
Platforms per citizennot stated5 (up from 4)
Sectorsinsurance, retail, banking, healthcaremore than 20
European footprintBelgium32 countries (doubled from 16 during 2025)

Let’s highlight 2 things:

The first is the profit line. itsme made over €7 million in 2025, its third consecutive year of strong results, and it grew profit 25%. A national identity utility that pays for itself is not a common object. It is, as far as I can tell, the thing that eIDAS 2.0 has no mechanism to produce.

The second is the qualified electronic signature growth: up 55% in a single year. A qualified electronic signature carries the same legal weight as a handwritten one across the EU and EEA. Belgians are now signing legally binding documents with a bank and telco consortium app, at scale, as a matter of routine. That is not a login button. That is legal infrastructure.

Commercial Model + Governance

Belgian Mobile ID was formed by an unusually powerful combination of four banks and three mobile operators.

BanksMobile operators
BelfiusOrange Belgium
BNP Paribas FortisProximus
KBC/CBCTelenet
ING Belgium

In mid 2021 the Belgian federal government’s Federal Participation and Investment Company (FPIM) acquired a 20% stake, the first time a government fund became a shareholder. Six other shareholders put in additional capital at the same time, with the stated aim of taking further steps toward a European digital identity. Commercial entities built it, took the risk, and set the price. The government bought in afterward, as a minority shareholder, on the commercial vehicle’s terms. It did not commission a wallet, mandate adoption, and wait.

As I argued in Part 1, Identity Models, Government and Governance Structures, trust requires governance in the form of either commercial constructs or government mandates. Belgium has both, in the right sequence, with the commercial construct load bearing and the mandate supporting rather than substituting. The Commission’s own case study contains the line that should be on a poster in Brussels. A Belgian Royal Decree allowed the recognition of private eID solutions, in the Commission’s words, “in order to foster innovation and control government costs.” Belgium decided the state did not need to build the app. It needed to recognize a good one.

The proofing chain is the interesting part

This is where itsme becomes considerably more interesting than an ordinary app based identity provider, and where it stops resembling “Sign in with Google” and looks much more like India’s UIDAI. Anyone with a Belgian eID card, a SIM and a mobile phone can create an itsme identity. The original model anchored the person to the government issued eID, while banks and mobile operators contributed existing customer and device relationships. The consortium described the system at launch as transferring the security of Belgium’s electronic identity card into the mobile environment. Telenet’s original launch description combined payment card security concepts with SIM security.

Banks also act as the proofing channel. BNP Paribas Fortis, for example, lets a customer create an itsme identity through the bank’s existing authenticated banking relationship. The identity is then bound to the combination of smartphone, mobile number and itsme app, unlocked by PIN or biometric.

ID&V looks like this: Government identity (Belgian eID, authoritative attributes) → bank identity proofing plus mobile and device binding → itsme credential → authentication, signing, transaction authorization → banks, government, merchants, insurers, healthcare

Note what the state contributes and what it does not. It contributes the authoritative attributes and the legal recognition. It does not contribute the customer relationship, the distribution, the app, the price list, or the liability rulebook. Those are the hard parts, and in Belgium they sit with institutions that already had them.

Before itsme, the de facto Belgian digital identity was the eCard plus a card reader. The card had PKI. It had been issued for years. It never achieved meaningful online usage because nobody wants a card reader. The chip was never the problem. The distribution and the experience were the problem, and the consortium fixed those without needing new cryptography. That is the same lesson I drew from Norway, and the same one I keep coming back to: don’t get distracted by the tech. Winning approaches to identity will not derive from technology but rather from control, governance, law, and economics.

Legal Status

This is important, because the easy dismissal of bank led schemes is that they are merely private arrangements, fine for logging into your own bank and inadequate for anything legally serious. Belgium closed that gap years ago.

itsme was recognized as a digital identity by the Belgian government in January 2018. Belgium’s notification of the mobile eID scheme (FAS plus itsme) was published in the Official Journal of the European Union on 18 December 2019, at eIDAS Level of Assurance High. itsme is an accredited Qualified Trust Service Provider for the validation of e-seals and e-signatures. It complies with PSD2, FATF and GDPR, and holds ISO 27001 certification.

The notified scheme is the Belgian government’s Federal Authentication Service (FAS), operated by BOSA, combined with the itsme app. FAS is the gateway that supervises identification and authentication for public services without interacting with the app’s internal processes, and the Belgian eIDAS node is implemented as part of FAS. The government built a bridge, not a wallet. itsme authenticates; FAS translates that assertion for government services.

The consortium also built itsme using the EU’s own CEF eID and eSignature building blocks. Belgium used Europe’s specifications to ship faster. This is not a story about a national champion ignoring Brussels. It is a story about a commercial consortium using Europe’s technical work and supplying the two things Europe did not: a distribution engine and a price.

So itsme is not merely a group of banks saying “we know this customer.” It has crossed the boundary into a recognized national electronic identity mechanism at the highest assurance tier, and it did so seven years ago. That makes Belgium a very useful counterexample to the idea that Europe needs to build digital identity from scratch with the EUDI Wallet.

The Right Model

Belgium is one instance of a repeating structure. Starpoint’s own inventory of active identity efforts applies a four question test to every scheme in the field, in order, stopping at the first failure: who asserts, who is liable when the assertion is wrong, what is the commercial construct, and who enforces.

Six schemes pass all four questions and are bank owned, in production, and charging a fee:

SchemeOperating entityStatus
BankID NorwayStø ASProduction since 2004
Sweden BankIDFinansiell ID-Teknik BID AB~8.5 million users, near universal adult adoption
Denmark MitIDFinans Danmark (with the state)Production since 2021, effectively all Danish adults
Belgium itsmeBelgian Mobile IDProduction since 2017, per transaction fee tiered by assurance
ConnectID (Australia)Australian Payments PlusAll four majors live as of Jan 2025
Interac Verified (Canada)Interac CorpLive, six major banks

Six jurisdictions, six bank owned schemes, all in production, all with a price. None of them required new legislation to work. Set that against the EUDI Wallet, which in the same inventory is recorded as having world class specifications (ISO 18013-5, SD-JWT VC, OpenID4VP, OpenID4VCI), a binding regulation with hard dates (wallets by 24 December 2026, regulated sector acceptance December 2027), and, no commercial construct, no fee schedule, no bank rulebook, and no liability allocation. No payments credentials, No bank commercially committed to a fee bearing role.

The single most damning data point is NOBID, the payments focused EU Large Scale Pilot, which named DSGV, DNB, BankID Norge, Intesa Sanpaolo, PagoPA and ABILab across six countries and thirty plus partners. It completed in June 2025. It tested whether a commercial model could emerge and it did not create one. No fee schedule, no rulebook, no liability framework. Technical feasibility demonstrated; commercial viability not.

I made this argument at length in Why eIDAS Will Fail in Banking and in Understanding eIDAS Impact on Banking and Payments, and the structural version in Europe’s Digital Sovereignty Siege. Belgium is the control group for all of it. Same continent, same regulation, same standards, wildly different outcome, and the only variable that changed was who owned the economics.

Device Binding

There is a technical twist here that deserves attention, and it connects to the Google DPC work I covered in EMVCo and DPCs. As I laid out in eIDAS, Top 3 Problems, the eIDAS ARF operationalizes Level of Assurance High through the Wallet Secure Cryptographic Device, a cryptographic boundary for key generation, credential storage and isolated execution (ie Device BOUND IDENTITY CREDENTIAL). The practical problem is that the secure elements in iPhones, Pixels and Galaxy devices are controlled by platforms and manufacturers rather than by the citizen or the member state, and they generally lack the certifications that eIDAS specific protection profiles demand. Deadline driven teams then either accept software or Light TEE storage, which fails LoA High, or move keys to a remote cloud cryptographic service, which relocates the identity to whoever operates that service.

Meanwhile itsme has been running PKI keys in the phone’s secure environment, bound to device and mobile number, unlocked by PIN or biometric, at LoA High, in production, since well before the regulation existed. India also leveaged SIMS for this purpose. The commercial bank and telco app is closer to the device bound model the regulation describes than most implementations of the regulation are. Europe wrote the architecture. Belgium shipped it, using Europe’s own building blocks, funded by relying party fees.

That is the pattern in miniature. The specification was never the bottleneck.

WERO is NOT EPI

Do not confuse itsme with Wero and EPI. Belgian banks are heavily involved in both, but they are different layers. Wero is a bank led European payments wallet and network, which I assessed in Wero 2026, Sovereignty at a Commercial Premium. itsme is the identity, authentication and signature infrastructure. Belgian banks are increasingly participating in both layers, which is exactly what you would expect from institutions that have worked out that identity and payment are separable and that both are worth owning.

itsme Expansion

itsme is no longer a Belgian story. In December 2025 it acquired iDIN, the Dutch identification service built by the Dutch banks and established in 2016. On 1 June 2026 itsme launched in the Netherlands as iDIN’s successor, with Dutch users able to identify to PostNL and to BKR, the national credit register, and roughly 300 Dutch private partner websites planned across 2026. In April 2026 Revolut integrated itsme for Belgian market registration. The scheme is now available in 32 European countries, double the 16 it covered at the start of 2025, and it intends to reach all 27 EU member states.

Look closely at the iDIN acquisition, because it is the most important thing in this post after the profit line. One bank built identity scheme bought another bank built identity scheme and migrated its users. That is consolidation, and consolidation is what infrastructure markets do when the economics work. Cross border European digital identity is being assembled right now, by acquisition, funded by relying party fees, by a commercial entity, roughly eighteen months ahead of the regulatory deadline that was supposed to deliver it.

This is what I meant in Separating Payment and Identity and in Identity Driving Payments. Identity infrastructure with a working revenue model does not sit still. It expands, because expansion of commercial incentive. itsme’s CEO Tom Van Den Bosch put it in one sentence that I could not improve on: “The challenge today is not technology, but trust and simplicity.”

I have been saying a version of that for fifteen years. It is pleasant to hear it from someone running an eight million user scheme at a profit.

What Europe should take from this

The EUDI Wallet has world class specifications, a binding regulation, hard deadlines and substantial political will. It does not have a fee schedule, a rulebook for private sector acceptance, or a liability allocation. Belgium has all three and has had them for years, at eIDAS Level of Assurance High, notified in the Official Journal, with the state as a 20% shareholder rather than the operator.

The honest conclusion is uncomfortable for Brussels. Europe does not have an identity technology problem, and it does not have a standards problem. Europe has a governance and economics problem, and four Belgian banks plus three Belgian mobile operators solved it in 2017 with a Royal Decree, a price list, and a distribution channel they already owned.

If I were advising the Commission, my recommendation would be short. Stop trying to build the wallet. Recognize the ones that work, mandate interoperability between them, let them charge, and require that the liability rules be written down. That is roughly what Belgium did, and Belgium is the only member state where over 80% of adults use a notified LoA High electronic identity five times a week across twenty sectors and sign legally binding documents with it.

The question was never who can build the credential. It is who will pay for assurance, and who carries the loss when the assurance is wrong. Belgium answered both questions in 2016, before writing any code. That is the whole difference.

Please Login to Comment.