The eIDAS 2.0 framework in Venvera helps your organisation manage its obligations under Regulation (EU) 2024/1183, which amended the original eIDAS Regulation and entered into force on 20 May 2024. It covers the European Digital Identity Wallet and modernised trust services, and it is built for the compliance owner who has to prove readiness to a national supervisor.

Regulatory Context

Who is in scope?

Scope follows the role your organisation performs, not just its sector. You are in scope if you are a trust service provider, a wallet provider, a relying party that requests identity data, a Very Large Online Platform that requires login, or a browser vendor. The common private-sector trigger is Article 5f: non-micro and non-small companies that must use strong user authentication for online identification, because of EU law, national law or contract, must accept the wallet. Micro and small enterprises are exempt from that acceptance duty, but not from trust-service or wallet-provider duties.

The key deadline

Covered relying parties must be able to accept the wallet by 24 December 2027 (36 months from the relevant implementing acts, which entered into force on 24 December 2024). Member states are expected to make national wallets available by the end of 2026. Trust service providers undergo conformity reassessment at least every 24 months.

Using the eIDAS 2.0 module

The module gives you a scoped control set (applicability and the SME test, relying-party registration and identification, wallet-acceptance readiness, data minimisation, trust-service usage, security and incidents, and a conditional trust-service-provider block), a gap assessment, and a controls workspace where you record evidence.

ℹ️
Scope out the trust-service-provider controls (EIDAS-20 to EIDAS-23) as Not applicable on the Controls page if your organisation is only a relying party. The gap assessment marks those questions "TSP only" so they do not distort your score.

Evidence you already hold

Many eIDAS controls overlap DORA, NIS2 and ISO 27001: strong authentication, incident reporting, certificate lifecycle, supplier obligations and security of the identity stack. Because Venvera maps controls across frameworks, evidencing one satisfies its eIDAS equivalent, and Evidence Autopilot chases only the eIDAS-specific gaps. The wallet-acceptance, registration and data-minimisation duties are eIDAS-specific and are never auto-satisfied by unrelated evidence.

⚠️
eIDAS 2.0 does not replace eIDAS 1. Existing qualified signatures and seals continue to work; the wallet and relying-party duties sit on top. Venvera tracks the new obligations, not your signature technology itself.