The EU Digital Identity Wallet (EUDI Wallet) is a regulated European digital identity ecosystem, not a single credential format or protocol. Its requirements span EU law, implementing regulations, the Architecture and Reference Framework (ARF), international standards, national trust infrastructure, certification, and wallet, issuer, and relying-party implementations.
This page is an annotated route into the primary sources. It distinguishes binding law from architecture guidance, stable standards from drafts, and reference software from production-ready implementations.
Start here
- European Digital Identity Regulation overview — the Commission’s policy-level introduction and implementation timeline.
- EUDI Wallet Toolbox — the Commission’s hub for the common toolbox, ARF, reference implementation, and standards work.
- Architecture and Reference Framework — the maintained technical baseline for roles, architecture, trust, protocols, requirements, rulebooks, and technical specifications.
- ARF releases — versioned source releases and downloadable snapshots for reproducible analysis.
- Reference implementation documentation — components, feature coverage, and implementation guidance.
- Functional conformance — the EUDI conformance assessment framework and test resources.
- EUDI Wallet GitHub organization — official specifications, applications, libraries, and test tooling.
Use a versioned ARF release
when requirements must be cited or implemented reproducibly. The unversioned
latest documentation is useful for orientation but can change as the framework
evolves.
Legal foundation
The legal authority comes from EU legislation. The ARF and technical standards explain how participants can implement that framework; they do not replace the law.
- Regulation (EU) 2024/1183 — the amending regulation that established the European Digital Identity Framework.
- Consolidated Regulation (EU) No 910/2014 — eIDAS as amended, including the EUDI Wallet provisions in their legislative context.
- EUDI Regulation and implementing regulations — the Commission-maintained index of adopted implementing regulations.
- European Digital Identity Cooperation Group — the Member State and Commission coordination body supporting implementation and the common Union toolbox.
- EUR-Lex — the authoritative place to verify consolidated texts, legal status, dates, corrigenda, and language versions.
Implementing regulations cover distinct operational subjects such as wallet integrity and core functionality, person identification data and electronic attestations of attributes, protocols and interfaces, certification, and notification to the Commission. Consult the maintained Commission index before treating any list as complete.
Architecture, requirements, and rulebooks
The ARF is the best technical entry point because it connects ecosystem roles and legal requirements to concrete protocols, formats, and trust mechanisms.
- ARF main document — functionalities, ecosystem roles, architecture, data exchange, trust model, certification, and accessibility.
- ARF annexes — definitions, normative high-level requirements, rulebooks, and design guidance.
- High-level requirements by topic — a practical requirements index for implementers and reviewers.
- PID Rulebook — requirements for Person Identification Data.
- mDL Rulebook — the mobile driving licence profile.
- Technical specifications — EUDI-specific normative specifications, including trust marks, wallet unit attestations, relying-party registration, data portability, and wallet-to-wallet interactions.
- ARF discussion topics — open design work and unresolved topics; useful context, but not equivalent to adopted requirements.
- ARF changelog — changes between framework releases.
The terms PID, QEAA, PuB-EAA, and EAA identify legally and operationally distinct kinds of data or attestation. They should not be flattened into one generic credential type when evaluating issuer authority, assurance, or acceptance policy.
Protocols and credential formats
The ecosystem composes specifications maintained by several standards bodies. Check the profile and version required by the applicable ARF release rather than assuming that support for a base standard establishes EUDI interoperability.
Issuance and presentation
- OpenID for Verifiable Credential Issuance 1.0 — Final specification for credential issuance APIs and flows.
- OpenID for Verifiable Presentations 1.0 — Final specification for requesting and delivering presentations.
- OpenID4VC High Assurance Interoperability Profile 1.0 — the interoperability profile that constrains OpenID4VC protocols for high-assurance deployments; verify its publication status and the profile version selected by the ARF.
- OAuth 2.0 and OAuth 2.0 Authorization Server Metadata — underlying authorization and discovery building blocks.
Selective-disclosure credentials
- RFC 9901: Selective Disclosure for JWTs — Standards Track SD-JWT mechanism for selectively disclosing JWT claims.
- SD-JWT-based Verifiable Credentials — the IETF credential format built on SD-JWT; this link tracks an Internet-Draft and must be cited with a specific version and maturity.
SD-JWT is a disclosure mechanism, while SD-JWT VC defines a credential format and processing model. Neither label alone establishes an EUDI profile, issuer authorization, holder binding, status, or fitness for a relying party’s purpose.
Mobile documents
- ISO/IEC 18013-5 — mobile driving licence application and presentation interfaces.
- ISO/IEC 18013-7 — add-on functions for online presentation of an mDL.
- ISO/IEC 23220 series — the broader ISO mobile eID framework and associated interfaces.
ISO standards are often paywalled. Their catalogue pages identify the canonical edition and status; implementation still requires access to the normative text and the exact EUDI profile that constrains it.
Trust, registration, and certification
Protocol interoperability is only one layer. EUDI decisions also depend on the role and registration of participants, trusted-list and certificate processing, wallet and device assurance, credential status, and policy for the requested attributes.
- ARF trust model — trust relationships, participant access, registration, and trust infrastructure in the EUDI ecosystem.
- ARF certification and risk management — the framework’s account of wallet certification and risk-management obligations.
- EU Trusted List Browser — Commission service for inspecting national trusted lists and qualified trust service providers.
- List of Trusted Lists — the EU trust-list pivot used to locate Member State trusted lists.
- ETSI TS 119 612 — specifications for trusted lists.
- RFC 5280 — the Internet X.509 public-key certificate and CRL profile underlying many certificate-path decisions.
- ENISA EUDI Wallet certification support — Commission context for the wallet cybersecurity certification work.
A successful signature or certificate-path check does not by itself establish that an issuer is authorized to issue a particular PID or attestation, that a relying party is entitled to request it, or that a wallet and presentation meet the required EUDI profile.
Implementations and developer resources
The Commission reference implementation is useful for interoperability work and for understanding intended component boundaries. Its own documentation describes it as evolving reference software, not a production certification or a substitute for security engineering.
- Reference implementation map — scope, roadmap, repositories, and disclaimers.
- Reference implementation documentation — feature map and component-level guidance.
- EUDI Wallet Dev Hub — developer-oriented guidance and tools for wallets, issuers, and relying parties.
- Official GitHub repositories — the full repository catalogue.
- Reference implementation roadmap — planned and delivered capabilities.
- Functional conformance framework — conformance documentation and test resources.
Pilots and field testing
- Commission pilot overview — the reference prototype, large-scale pilots, sectors, and use cases.
- POTENTIAL — public services, banking, telecommunications, mDL, signatures, and health use cases.
- NOBID — payment authorization and Nordic-Baltic interoperability work.
- DC4EU — education and social-security credentials and infrastructure.
Pilot evidence can reveal interoperability and usability problems, but pilot participation or compatibility is not the same as legal compliance, certified wallet status, or production assurance.
Reading EUDI artifacts with Proofet Atlas
Proofet Atlas 0.1.0 can describe artifacts encountered in the EUDI ecosystem without treating EUDI as a credential family. For example, an artifact may have an intrinsic family such as ISO mdoc or SD-JWT VC, a specific PID or attestation profile, an issuance or presentation protocol context, and separately evaluated assurance results.
Detection of an EUDI-related identifier is only classification evidence. A conformance or trust conclusion requires the applicable legal and ARF version, the full profile, cryptographic and status evidence, participant authorization, holder and transaction binding, and an explicit relying-party policy.
Maintenance note
This ecosystem changes across legislative, framework, standards, and software release cycles. Links and source status were checked on 25 August 2026. For normative work, record the exact legal consolidation date, ARF release, standard edition or draft revision, implementation version, and date consulted.