For many years, Swedish digital identification has been almost synonymous with BankID. WitheIDAS 2.0the game plan is redrawn at EU level. The regulation establishes a common European framework for digital identity and aEU Digital Identity Wallet (EUDI Wallet)which each Member State must offer. For Swedish companies that build login, e-signing, age control or onboarding, this is one of the most concrete rule changes in several years.
What is eIDAS 2.0?
eIDAS 2.0 is the colloquial name forRegulation (EU) 2024/1183 of the European Parliament and of the Council of 11 April 2024, which amends the original eIDAS Regulation (EU) No 910/2014 and establishes a framework for European digital identity. It was published in the Official Journal of the EU on 30 April 2024 and entered into force 20 days after publication, in May 2024.
The original eIDAS regulation from 2014 regulated electronic identification and trusted services (e-signatures, e-stamps, time-stamping, etc.) across borders. It worked, but in practice it was mostly used between authorities. eIDAS 2.0 takes three big steps forward:
A personal wallet for everyone.Every citizen and resident must have the right to a digital identity wallet that they themselves control.
The private sector is withdrawn.Not only authorities, but also banks, platforms and other services are subject to requirements to accept the wallet.
The user controls their data.The principle of data minimization and selective disclosure is built in: you share only the necessary attribute, such as being over 18, without revealing your date of birth or social security number.
What is the EUDI Wallet in practical terms?
EUDI Wallet is a mobile app where you collect verifiable information about yourself: your identity, but also so-called electronic attestations of attributes (electronic attestation of attributes) such as a driver's license, diploma, professional qualification or proof of age. When a service needs to know something about you, you present that exact attribute, cryptographically verified and with your consent.
Technically, the wallet rests on a comprehensive framework ofimplementing acts(implementing acts) and a common architecture and reference framework (ARF) that specifies data formats, security requirements and interoperability. The first implementing acts were published in December 2024, and more technical standards have been added continuously in 2025 and 2026 as the framework matures.
The timeline you need to keep track of
It is possible to navigate eIDAS 2.0 with a few points of reference in the calendar:
April–May 2024:Regulation (EU) 2024/1183 is adopted and enters into force.
December 2024:First set of implementing acts with technical specifications is published.
End of 2026:No later than approximately 24 months after the central implementing acts enter into forceeach Member State offer at least one EUDI Walletto its citizens and residents. A country can provide the wallet itself, have a designated party build it, or recognize a private solution.
End of 2027:Approximately 36 months after the implementing acts, the requirement formandatory acceptancein parts of the private sector. Relying parties that require strong authentication by law or contract, such as banks, payment service providers and certain sectors such as energy, health, education and telecom, as well as very large online platforms, shall accept the wallet at the user's request.
2030:The EU's goal within the framework of the Digital Decade is for 80 percent of the population to use a digital identity solution.
A realistic reservation: the rollout is uneven between the countries. Several Member States and independent experts have signaled in 2025 and 2026 that fully functioning wallets in all 27 countries at the turn of the year 2026 is uncertain. However, the legal deadline is fixed, and the demands on the companies are coming.
What is happening in Sweden?
Sweden has historically registered BankID and Freja+ as Swedish e-identifications according to eIDAS. None of these currently reach the highest level of trust on which the EUDI framework is based. Therefore, the state is now coming up with its own solution.
Sweden IDis the state e-identification which, according to the plan, will be launched on 1 December 2026. It is being developed by the Police Authority in collaboration with the Digital Administration Authority (Digg), under the Ministry of Finance, and is linked to the new national ID card, which means that those who want the state e-identification apply for a Sweden ID and a national ID card at the same time. Digg is responsible for the electronic identification part of the eIDAS regulations. Sweden-ID is intended to reach the highest level of trust and thereby meet the EUDI requirements, as a complement to the market-leading solutions.
What does it mean for your business?
If your business handles login, identification, e-signature or onboarding, eIDAS 2.0 affects you on several levels.
1. You may need to accept the wallet
Does your service require strong authentication by law or contract? Then you may be subject to the requirement to accept the EUDI Wallet by the end of 2027 at the latest. This applies to particularly regulated sectors such as finance, health, energy, education and telecom, as well as very large platforms. Micro and small businesses that already use strong authentication have some exceptions, but no one should assume that they are not affected without doing the analysis.
2. You must register as a relying party
Whoever wants to use the wallet to request information about users must be registered as a relying party in the Member State where the company is established. In the registration, you specify, among other things, legal identity, which attributes you intend to request and for what purpose. A central principle is that you may only request what is truly necessary, and to support pseudonyms where identification is not required by law.
3. Your flows need to be mapped
The practical work starts with an inventory: where in your flows is strong authentication required, what personal data is collected at each step, and which of them are actually necessary? This is where eIDAS 2.0 and the data protection rules meet. Data minimization is no longer just a GDPR principle on paper, but something technology actively supports through selective disclosure.
4. Login becomes more diverse
For Swedish users, this probably means that the login page will eventually contain more options: today's market solutions, the government Sweden ID and foreign wallets from other EU countries. Services that build authentication smartly, abstractly and vendor-independent do not have to rebuild every time a new option is added.
How to prepare now
Map authentication flows.Document where strong authentication is required and which attributes you request.
Build vendor independence.Add an abstraction layer between your application and the identity providers so that new wallets can be connected without rewriting the code.
Prepare relying party registration.Make sure you have the legal entity, purpose statement and technical contact information ready.
Connect with GDPR.Use the transition to purge unnecessary data collection and document legal basis.
Monitor the implementing acts.The technical details continue to be specified. Build so you can follow along as standards stabilize.
Summary
eIDAS 2.0 is not just an updated regulation, it is a shift in how identity works digitally in Europe. For Swedish companies, it is not about if you are affected, but about when and how. Those who start mapping their flows and build supplier-independent logins already now are in the strongest position when the wallet and the requirements become reality in 2026 and 2027.
At ZORC, we build login, identification and onboarding that keeps up with changing regulations, with architecture that takes height for both today's e-identifications and tomorrow's EUDI Wallet. Do you want to know what such a project would mean for you? Describe your need inthe quote calculatoror get in touch viacontactthen we'll look at it together.