eIDAS – Top 3 Problems

Europe is twelve months away from a legal deadline for a wallet no one has asked for. Governments are required to issue digital IDs, banks are not required and will likely hold off given the success of Norway’s Bank ID model (commercial terms there). Under Regulation (EU) 2024/1183, commonly called eIDAS 2.0, every Member State must offer at least one certified European Digital Identity (EUDI) Wallet to all citizens and residents by December 2026. The Commission’s stated ambition is that 80% of European citizens use a digital identity solution by 2030.

The wallet is a container. It holds Person Identification Data (PID), the citizen’s legally recognized core identity issued under national authority. It holds Qualified Electronic Attestations of Attributes (QEAAs), which are verified claims such as a driving license, a professional qualification or a bank account identifier. It also supports Qualified Electronic Signatures (QES), which carry the legal weight of a handwritten signature in all 27 Member States. For payments, the relevant consequence is that a certified wallet credential satisfies Strong Customer Authentication, so a bank cannot arbitrarily reject a wallet based authentication event in a payment flow.

I have written about this framework several times, most recently in Understanding eIDAS Impact on Banking and Payments and, more bluntly, in Why eIDAS Will Fail in Banking. My view has not softened. The architecture is impressive. The design has three flaws that no amount of engineering will fix, and the 2026 deadline is now forcing Member States into decisions that contradict Europe’s own architecture reference. This analysis draws on my research and on the Commission’s European Digital Identity Architecture and Reference Framework (the ARF).

Problem 1: The deadline is forcing implementations that break Europe’s own rules

The regulation is unambiguous about security. Article 5a requires PID to meet Level of Assurance “High”. Article 26 and Annex II require that the signatory keeps sole control of signature creation data. The eIDAS architectural reference (ARF) operationalizes this through the Wallet Secure Cryptographic Device (WSCD), a cryptographic boundary responsible for key generation, credential storage and isolated execution of sensitive operations. The ARF also states plainly that “standard software execution environments” do not provide the level of trust certain computations require, and that the wallet shall meet Article 8 assurance level high as defined in CIR 2015/1502.

Now the practical problem. The secure elements inside iPhones, Pixels and Galaxy devices are controlled by platforms and/or their manufacturers, not by the citizen or the Member State, and they generally lack the Common Criteria certifications (EAL5+, AVA_VAN.5) that eIDAS specific Protection Profiles demand. So the citizen cannot have sole control of a key stored in a chip that the handset vendor governs. Development teams facing a statutory deadline therefore have two choices: accept storage in software or in a Light Trusted Execution Environment (TEE) on hardware that already exists in consumers’ pockets, or move the keys to remote cloud based cryptographic services (a Remote Secure Element, effectively a server side HSM operated by a Qualified Trust Service Provider).

Most are quietly taking the first option, and that is a mistake. Software and TEE storage fail LoA High. TEEs remain vulnerable to microarchitectural side channel attacks and to bugs in the TEE kernel, as the European Data Protection Supervisor has documented. Application processors have no fault injection shielding, and under voltage manipulation an unprotected processor can be induced to bypass cryptographic checks. Threat modeling work by Ranise and colleagues (DBSec 2025) reached the same conclusion: software only storage cannot maintain a secure state under active threat conditions.

The timing could not be worse. AI has accelerated the window between vulnerability disclosure and working exploit has collapsed from weeks to hours as AI agents discover pre authentication flaws and chain them into remote code execution in a single session. That changes the shape of the risk, not just its size. Extracting a key from a certified secure element requires physical possession of one handset and a laboratory. Extracting a key from a software store requires one exploit deployed simultaneously against millions of devices. Software storage converts an isolated physical risk into a systemic, networked one.

The result is an implementation that is legally non compliant in three directions at once: eIDAS LoA High, GDPR Articles 25 and 32 (which require security appropriate to the state of the art), and the ARF’s own WSCD attestation rules, since a software only wallet cannot produce hardware backed Wallet Trust Evidence for a relying party to verify. This is what I mean when I say Europe is abandoning device bound identity credentials in practice while maintaining them in law.

Problem 2: There is no commercial model, and merchants pay for everything in payments

Read the ARF looking for economics and you find nothing. There are no fees, no interchange equivalent, no funding mechanism, no revenue framework of any kind. Terms for PID provision are left “for each Member State to determine”. Terms for QEAA issuance are left “for each QTSP to determine”. Relying parties must register with their Member State, build and maintain a mutual authentication interface, and are “responsible for carrying out the procedure for authenticating the attestations” they receive. They do all of that at their own cost, with no defined way to recover it and no revenue line attached.

This is not a detail. It is the whole game. As I argued in Part 1, Identity Models, Government and Governance Structures, “The only commercial model where PERMISSIONED identity has been ‘monetized’ is payments.” Card networks became the identity infrastructure of eCommerce precisely because they built a commercial construct around risk, not because their cryptography was superior. Every participant knows what they pay, what they earn and what they are indemnified against. eIDAS creates an identity utility with no equivalent flow of funds. When something costs money to operate and generates no revenue, it gets the minimum viable investment, and the minimum viable investment is exactly how you end up with wallets that store keys in software.

There is a second order effect that should worry anyone running a processor or a bank. Europe wants eIDAS to become the pillar that lets account to account schemes compete with cards by removing risk through consumer authentication. But if authentication becomes a free public good with no commercial model attached, the value that today funds acquirers, processors, issuers, gateways and fraud specialists does not transfer anywhere. It evaporates. Europe is not reallocating the economics of trust, it is deleting them, and then wondering why the private sector is not investing.

Problem 3: Governance was never designed, so liability has nowhere to land

My position has been consistent for years: trust requires governance in the form of either commercial constructs or government mandates. eIDAS attempts the mandate route across 27 jurisdictions with different legal traditions and different supervisors, and then leaves the hard part undefined.

Banking is where this breaks first. Banks do not verify identity so much as absorb liability, and European supervisors do not permit that liability to be delegated. A verifiable credential proves what it says. It does not prove source of funds, beneficial ownership, risk profile or sanctions status. As I put it in Why eIDAS Will Fail in Banking, “Accepting the credential as a substitute would mean outsourcing risk without outsourcing liability, which is simply not permitted.” And if a large number of banks come to depend on a small number of credential issuers who are not supervised like banks, “When something goes wrong, the credential issuer shrugs. The wallet provider points to the spec. The banks pay the price.” You cannot build a delegated trust system on top of non-delegable liability.

The ARF compounds this by being an engineering document. It specifies protocols, interfaces, building blocks and certification bodies. It does not specify who is accountable to whom when a credential is wrong, who compensates a relying party for a loss, or who arbitrates a dispute across borders. That is not a technical omission, it is the missing institution. Don’t get distracted by the tech. Winning approaches to identity will not derive from technology but rather from control, governance, law, and economics.

What Europe should have copied: BankID

The most successful identity scheme in Europe is already European. I covered it in detail in BankID Norway, Evolution and Success. BankID reaches roughly 97% of Norwegian adults and carries authentication for banking, tax, healthcare and government services. Its success “was not the result of innovation but rather deliberate, multi-decade collaboration between the private financial sector and government authorities.” It has a governed wallet, an operator with a balance sheet, a defined liability model and a commercial construct that pays for all of it. It also has the technology right: BankID is migrating to FIDO passkeys with keys held in the Secure Enclave or equivalent, “a transition from software-defined and probabilistic identity toward hardware-bound, deterministic identity proof.”

That is the ordering that works. Governance first, commercial model second, technology third. eIDAS inverted it. Banks are best placed to deliver a universal ID, and Europe has the only market in the world where banks have already proven it at national scale, yet the eIDAS design gives banks the obligations of a relying party and none of the economics of an issuer.

What this means for payment executives

Three things are worth watching over the next twelve months.

First, watch which Member States ship wallets at “Substantial assurance” (in software storage) rather than High, and quietly say so in the small print. Substantial is adequate for most authentication and inadequate for the highest risk transactions, which are precisely the ones payments cares about. A wallet at Substantial does not solve your onboarding problem, and it does not carry the legal weight the marketing implies.

Second, watch whether Remote Secure Elements (ie cloud based) become the default. They are the only architecture that meets LoA High on today’s handsets, and they hand the strategic position to whoever operates the Qualified Trust Service Provider. Banks are the obvious candidates. If banks do not take that role, the wallet becomes a government or platform utility and the bank is reduced to a regulated balance sheet with no differentiation at the customer interface.

Third, watch for a commercial model to appear, because nothing else will move the needle. My recommendation in the research note is straightforward: create a commercial model for device manufacturers and platforms to build and maintain a secure environment for credential storage, and pair it with open access to secure elements enforced through the Digital Markets Act. Without payment, Apple and Google have no reason to open the silicon, and without the silicon, LoA High on the handset stays theoretical.

eIDAS 2.0 has the right architecture and the wrong timeline for most of Europe. My concern is no longer the timeline. It is that a deadline driven compromise on credential storage will lock in a software based identity layer, in the exact era when automated attackers make software based storage indefensible, and that it will do so without ever answering the two questions Norway answered thirty years ago: who governs this, and who pays for it.

But hey Europe is use to failure here.. remember GSMA and TSM? how about eIDAS V1.0? Mandates with no commerical use case.. yep that will drive innovation and margin.

Please Login to Comment.