Europe’s mandatory digital identity wallet has a certification deadline of end of 2026, and the document that will define what it means to pass that bar is now open for public review. The EU Agency for Cybersecurity launched a consultation on Draft Candidate EU Digital Identity Wallet Certification Scheme v0.4.614, giving developers, wallet providers, and member state authorities until April 30, 2026 to submit formal feedback.
The scheme matters to anyone building or deploying mobile wallet software in the EU. Under Regulation EU 2024/1183, every member state must provide at least one certified EUDI Wallet by the end of 2026, and the certification scheme is the instrument that defines whether a given wallet meets the required security and privacy standards. ENISA describes the scheme’s purpose as ensuring “security and protection of privacy of users and their personal data.”
ENISA published the draft on April 2, 2026, and held an informational webinar on April 8 to walk stakeholders through the document and answer questions. The European Cybersecurity Certification Conference, scheduled for April 15 in Cyprus, will include the wallet certification as a primary agenda item. The final scheme is to be published as an Implementing Act by end of 2026.
The certification framework was developed by an Ad Hoc Working Group of 26 appointed members and 15 reserve experts, which first convened in January 2025. In February 2026, ENISA signed a two-year Contribution Agreement worth 1.6 million euros to support member states in building out national certification schemes and aligning them with the European standard now under consultation.
For mobile wallet developers, the stakes in this process are concrete. The EUDI Wallet is conceived as a smartphone-resident credential store, letting citizens carry legally recognized identity documents, diplomas, payment credentials, and health records in a single app, and share them selectively with service providers. The security architecture under evaluation includes FIDO authentication standards, the same passkey-aligned specifications that have already shaped mobile authentication across banking and payments.
Ahead of the ENISA scheme, a Nordic-Baltic certification framework was adopted in late 2025, giving that regional bloc a head start on alignment with the broader EU standard. With the April 30 feedback window open, the consultation represents the clearest opportunity for industry to shape what mobile digital identity security looks like across 27 member states for the foreseeable future.
Sources: ENISA, ENISA Certification Portal, Digital Watch Observatory
–
By the Mobile ID World Editorial Team