Regulatory reference

EUDI wallet acceptance

From 24 December 2027, private businesses across eleven named sectors must accept the EU Digital Identity Wallet when a user offers it. That date is not written in the Regulation. Article 5f(2) expresses it as 36 months from the entry into force of implementing acts that came into force on 24 December 2024 — so it has to be computed, which is precisely why published sources disagree about it and about who it binds.

Where the date comes from

The European Digital Identity Framework — Regulation (EU) 2024/1183, amending the original eIDAS Regulation (EU) No 910/2014 — contains no calendar dates after 21 May 2025. Every later milestone is a relative period running from the entry into force of the implementing acts adopted under Articles 5a(23) and 5c(6).

Those implementing regulations were adopted on 28 November 2024 and entered into force on 24 December 2024. From that single anchor:

PeriodDateWhat it triggers
24 months24 December 2026Each Member State must provide at least one EU Digital Identity Wallet
24 months24 December 2026CIR (EU) 2025/848 applies — national registers of wallet-relying parties go live
36 months24 December 2027Private relying parties in scope must accept wallets

This is why you will see four different dates. "2027", "late December 2027", "December 2027" and "24 December 2027" all circulate, because each writer computed it or rounded it differently. The arithmetic above is the check.

Who is actually in scope — and the limb everyone omits

Article 5f(2) binds private relying parties that are, in the Regulation's own words:

"required by Union or national law to use strong user authentication for online identification or where strong user authentication … is required by contractual obligation, including in the areas of transport, energy, banking, financial services, social security, health, drinking water, postal services, digital infrastructure, education or telecommunications"

Read that middle clause again, because most summaries drop it. The obligation attaches where strong user authentication is required by law or by contractual obligation. A great many organisations require strong authentication because a payment scheme, an insurer, a framework agreement or a customer contract obliges them to — not because a statute does.

A law-only reading of Article 5f(2) materially understates who is caught. If you have concluded you are out of scope, check whether the conclusion rested on the absence of a statutory requirement while a contractual one exists.

The exemption is a two-part test, not a headcount

Micro and small enterprises are excluded, defined by Commission Recommendation 2003/361/EC. That definition is not "fewer than 50 staff" alone — it pairs a headcount ceiling with a financial ceiling, and both limbs matter. A company under the headcount but over the financial threshold is not a small enterprise for this purpose.

It is a common place to get the answer wrong in your own favour, and worth having someone check rather than assume.

One claim we will not repeat

Wikipedia and several vendor pages state that very large online platforms must comply by December 2027, citing Article 5f(3). The enacted text of Article 5f(3) that we retrieved contains no deadline at all. We could not resolve the conflict against a primary source, so we are not asserting either position. If you are a VLOP, this is worth a lawyer rather than a blog post — including ours.

What acceptance actually requires

"Accept the wallet" is doing a lot of work in most summaries. Three things sit underneath it.

1 · You must be registered. CIR (EU) 2025/848 establishes national registers of wallet-relying parties and applies from 24 December 2026. An unregistered organisation cannot request data from a wallet. Registration is a precondition, and it opens a full year before the acceptance obligation.

2 · You must declare what you intend to request. The registration model is built around stating which attributes you will ask for. This is a data-minimisation mechanism, and it means the integration design has to be settled before registration rather than after.

3 · Acceptance is on the user's request. Article 5f(2) applies "only upon the voluntary request of the user". You are not obliged to make the wallet the default or the only route — you are obliged to honour it when someone chooses it. That is a smaller build than "replace your identity stack", and worth knowing before anyone scopes it as the latter.

The honest complication: will the date bite?

Content in this space tends to assume smooth enforcement. The evidence does not support that assumption, and pretending otherwise would make this page less useful.

24 of 27 Member States are reported as set to miss the 24 December 2026 issuance deadline. Germany has indicated January 2027. The Netherlands has pushed to late 2027 after a pilot that reached very few users. In September 2026 the Commission reopened implementing acts on privacy safeguards — facial images and unlinkable revocation.

Note carefully what that last point is and is not. Reopening an implementing act is not amending the Regulation. The 36-month clock runs from acts that entered into force in December 2024 and is unaffected. The deadline has not moved.

But a duty to accept wallets has limited practical force in a market where wallets are barely issued. Two honest readings follow, and you should hold both:

The case for treating it as real: the obligation is in primary law with a computable date, there is no slippage mechanism in the text, and building identity acceptance takes longer than the twelve months you would have left if you waited for certainty.

The case for caution: if issuance is genuinely absent across most of the Union through 2027, political forbearance on enforcement is plausible, and heavy investment ahead of demand may sit idle.

The proportionate position for most organisations is to complete registration and scope the integration — both cheap, both on the critical path — and stage the build against actual wallet availability in the markets you serve rather than against the calendar.

Dates worth having in one place

DateWhatWho
24 Dec 2026Member States provide at least one walletMember States
24 Dec 2026Relying-party registers apply — CIR (EU) 2025/848Member States and relying parties
10 Jul 2027AML Regulation (EU) 2024/1624 applies in full; customer due diligence and remote identity verification rebuiltObliged entities — financial sector and the expanded scope
24 Dec 2027Private relying parties in scope must accept walletsNon-micro, non-small businesses in eleven sectors

The AML date is worth noting alongside, because for regulated firms the two land eighteen months apart and touch the same identity-verification infrastructure. Scoping them separately usually means building twice.

On the UK and the US: there is nothing comparable. We looked. The UK's only live date is 1 October 2026, and it is narrower than commentary suggests — digital right-to-work and right-to-rent checks remain optional, and the register requirement bites only if you choose the digital route. The 2025 call for views on trust services produced a government response committing to further evidence gathering with no legislative timetable. At US federal level there is no live reform: the SECURE Notarization Act has not been enacted, and ESIGN and UETA are unchanged. State activity is remote-notarisation expansion, which is permissive rather than deadline-bearing.

Common questions about EUDI wallet acceptance

Is the EUDI wallet deadline 2026 or 2027?

Both, for different parties. Member States must provide at least one wallet by 24 December 2026. Private businesses in scope must accept wallets by 24 December 2027. Relying-party registration also opens in December 2026. Sources that give a single date have usually merged two of these.

Why do sources disagree about the exact date?

Because it is not written in the Regulation. Article 5f(2) says "no later than 36 months from the date of entry into force of the implementing acts referred to in Article 5a(23) and Article 5c(6)". Those acts entered into force on 24 December 2024. Everyone computing that independently, and some rounding to "late 2027", is why you see four versions.

We are not legally required to use strong authentication. Are we out of scope?

Not necessarily, and this is the most commonly missed point. Article 5f(2) also catches organisations where strong user authentication is required by contractual obligation. Payment scheme rules, insurer requirements and customer contracts all commonly impose it. Check the contractual limb before concluding you are exempt.

Does the deadline move if Member States do not issue wallets?

Not automatically. The 36-month clock runs from implementing acts already in force since December 2024, and reopening other implementing acts — as the Commission did in September 2026 on privacy safeguards — does not amend the Regulation. What is genuinely uncertain is enforcement appetite in a market where wallets are scarce, not the legal date.

Do we have to make the wallet our primary login?

No. The obligation applies "only upon the voluntary request of the user" — you must honour the wallet when someone chooses it, not make it the default or the only route. That is a considerably smaller build than replacing an identity stack, and worth establishing before anyone scopes it as one.