eIDAS 2.0 and the Identity-Assurance Gate Most Platforms Aren't Ready For
By January 2027, regulated businesses across the EU must accept Digital ID wallets for KYC, at Level of Assurance High. Most identity-verification stacks haven't been tested against the fraud that requirement assumes they've solved.
eIDAS 2.0 is the European Union's revised digital identity regulation, requiring every member state to offer citizens a European Digital Identity Wallet by the end of 2026, and requiring regulated businesses to accept those wallets for KYC by January 1, 2027. Identity verification under the wallet must be performed at Level of Assurance High, the strictest tier, typically requiring document verification combined with biometric checks. That last requirement is where most platforms' current stacks haven't actually been tested.
The compliance checklist
- Confirm your Level of Assurance requirement. LoA High applies to most regulated onboarding under eIDAS 2.0 and requires biometric verification, not just document checks, before wallet-credential issuance or acceptance.
- Register as a relying party with your national eIDAS 2.0 authority. This is a prerequisite for accepting EUDI Wallet credentials and varies by member state.
- Confirm technical compatibility with ISO/IEC 18013-5 (the mobile driving license standard underlying wallet credentials) and W3C Verifiable Credentials.
- Redesign onboarding workflows to accept wallet-issued credentials alongside, or instead of, your existing document-plus-selfie flow.
- Test your liveness and biometric-matching stack against synthetic and deepfake presentation attacks, not just against real applicants, since LoA High assumes the biometric check itself can't be spoofed.
- Document your identity-verification methodology for the audit and assurance requirements regulators increasingly expect platforms to demonstrate, not just claim.
- Plan for the January 1, 2027 acceptance deadline, and treat wallet rollout timing by member state as a moving target rather than a fixed date, since national rollout schedules vary.
Why step 5 is the one most stacks fail
Steps 1 through 4 and 6 through 7 are largely process and integration work. Step 5 is different: it requires proof that your biometric verification actually resists the attack it's meant to stop, and the evidence available says most stacks haven't been tested against that specific threat. Frontier vision-language models, evaluated against realistic synthetic identities, accept them as genuine at rates from 94 to 100 percent. A platform whose underlying detection fails that test in evaluation will fail the same test in production, the difference being that in production the failure surfaces as a fraudulent account rather than a benchmark score.
This isn't hypothetical for eIDAS specifically. The regulation exists in part because of documented cases like the ABN Amro incident, in which one fraudster opened 46 separate bank accounts using stolen identity documents combined with deepfake video, passing conventional remote verification 46 times before the pattern was caught. LoA High is a regulatory response to exactly that failure mode.
What "tested against synthetic and deepfake presentation attacks" actually requires
Testing a live system against real fraud after the fact only proves it can catch fraud it's already seen. Demonstrating LoA High assurance credibly requires testing against synthetic identities built to exploit the fraud your specific stack currently misses, at a scale and demographic breadth no real incident log can supply, without introducing real citizens' biometric data into the process in a way that recreates the exposure the regulation is meant to prevent.
FAQ
When does eIDAS 2.0 require businesses to accept EU Digital ID wallets?
Regulated businesses must accept Digital ID wallets for KYC by January 1, 2027. Member states are required to make wallets available to citizens by the end of 2026, though national rollout timing varies.
What is Level of Assurance High under eIDAS 2.0?
LoA High is the strictest identity-assurance tier under eIDAS, typically requiring document verification combined with biometric checks (such as liveness detection and face matching) before a credential is issued or accepted, rather than document checks alone.
Do I need to register with a national authority to accept EUDI Wallet credentials?
Yes. Businesses that want to accept EUDI Wallet credentials generally need to register with their national eIDAS 2.0 authority as a relying party, a prerequisite that varies by member state and should be initiated well ahead of the January 2027 deadline.
Read the white paper or book a call to see how the compliance evidence is structured.
Sources: eIDAS 2.0 requirements and LoA High detail via fingerprint.com, Entrust, and GBG; relying-party and technical-standard detail via walt.id and Gataca; ABN Amro case via Biometric Update.
Measuring this on your own model
The first step is a sample built to your specification, which you score on your own detectors and benchmarks. No cost and no commitment.