July 2026. eIDAS 2.0 and the European Digital Identity (EUDI) wallet change how citizens and businesses share identity and attributes. For organisations with customer portals, HR systems or qualified signatures, preparation is not distant — pilot countries and sector requirements are growing.
What changes for businesses?
- ability to accept wallet identity alongside existing eID where relevant;
- qualified trust services and QES for contracts and compliance;
- privacy by design for attributes you request (data minimisation);
- ISMS/ISO 27001: extend identity controls and logging.
Practical preparation
- Inventory where strong identity is already required (HR, finance, customer).
- Follow NCSC and EU guidance on wallet pilots — no premature vendor lock-in.
- Link to GDPR and identity controls in SoA.
More in eIDAS knowledge cluster. Wallet does not replace ISO 27001 — but adds identity governance and evidence requirements.
Enterprise customers in finance and government ask roadmap questions: when will you support wallet login, how do you log attributes, where do you store minimal data?
Roadmap without premature commitment
Follow EU and national pilot programmes — do not contractually commit to wallet login before interoperability and liability are clear. Do prepare identity architecture review and logging requirements.
QES and qualified trust services affect finance and legal — involve both in vendor selection alongside IT security.
Link wallet plans to GDPR data minimisation: which attributes you truly need, retention, who may view.
Next steps in your ISMS
Turn this article into one concrete action in your risk register or improvement plan: owner, deadline, expected evidence. Discuss progress in the next management review — auditors and chain partners want decisions, not policy intent alone. Link where possible to existing ISO 27001, NIS2 or GDPR documentation so you do not maintain parallel folders.
Questions on scope, certification or chain requirements? Use our readiness overview and knowledge base for deeper guidance. This article does not replace legal or audit advice for your situation.
Share relevant findings briefly with line management and procurement — compliance becomes workable when the whole organisation recognises the same priorities. Repeat the chosen action quarterly in team meetings and update evidence locations in your SoA or control plan so surveillance samples are easy to answer.
