eIDAS 2 and finance: the regulation behind the wallet
A bank already lives with eIDAS without calling it that: every qualified electronic signature on a loan agreement and every timestamp in an archive rests on it. eIDAS 2 keeps all of that and adds instruments a bank will meet in the next contract cycle, the identity wallet being only the most visible one.
Regulation (EU) 2024/1183 was published in the Official Journal on April 30, 2024 and entered into force on May 20, 2024, amending the 2014 regulation and not replacing it. What follows is what it changed, which new trust services it created, and which parts are still open in implementing acts.
What 2024/1183 amends in the 2014 eIDAS
The 2014 regulation worked for trust services and largely failed for electronic identification. By the time of the reform only 14 member states had notified an eID scheme at all, the gap the reform set out to close for financial services, private online services had trouble connecting to the ones that existed, and the regulation covered identity but not verifiable attributes such as a qualification or a certificate. A citizen with a working national eID could therefore not use it across the border or with a private provider.
eIDAS 2 attacks that from two sides. It obliges every member state to make a wallet available, which removes the patchwork of notified schemes, and it extends acceptance obligations into the private sector, which removes the second half of the problem. The trust service part of the 2014 regulation stays in force with additions, so a bank's existing signature and seal processes keep their legal basis.
Qualified signatures, seals and timestamps a bank already uses
Three instruments carry most of a bank's current eIDAS use. A qualified electronic signature is the signature of a natural person with the legal effect of a handwritten one across the EU, which is what lets a loan agreement or an account opening be concluded remotely. A qualified electronic seal is the equivalent for a legal person, used on statements, confirmations and bulk correspondence the bank issues as an institution. A qualified electronic timestamp binds data to a time with a presumption of accuracy, which is what makes an archive defensible years later.
The practical point for a bank is where the qualified level is required and where an advanced signature is enough, because the qualified level costs more per signature and needs identity verification of the signer. That split is a legal question per document type, and eIDAS 2 does not change it. What it does change is how the signer gets identified, because the wallet can carry out that step.
Qualified electronic attestation of attributes, the new instrument
This is the addition with the most direct effect on a bank's processes. An electronic attestation of attributes is a verifiable claim about a characteristic of a person, independently of their full identity: a professional qualification, a company role, an address, a proof of being above an age. The qualified version is issued by a qualified trust service provider and carries a stronger presumption of reliability.
Cross-border recognition is what makes it usable. A qualified attestation issued in one member state has to be recognized as qualified in every other, which is the clause that lets a bank accept a Spanish or Polish attestation without a bilateral assessment. The EUDI Wallet in finance page covers how these attestations reach a bank through a wallet and what a bank has to do to read them.
The other new trust services: archiving, ledgers, remote signing
The regulation adds trust service categories that get less attention than the wallet and matter to a bank's own infrastructure. Qualified electronic archiving gives an archive service a defined legal standing for preserving data with its integrity and legibility over long retention periods, which is the exact problem a bank has with records it must keep for a decade.
Qualified electronic ledgers are the one worth noting on a site about tokenization: a trust service for recording data in a sequence with its integrity, chronological order and authenticity assured. That makes an electronic ledger a named trust service under EU law, and a qualified provider can operate one, which is a different legal route from the DLT regimes in financial market law. The tokenized securities page covers the securities-law side. Qualified management of a remote electronic signature creation device covers the case where the signing key sits in a provider's hardware and not on the signer's card, which is how most remote signing actually works.
Website authentication certificates and the browser dispute
A qualified certificate for website authentication, a QWAC, binds a domain to the verified legal identity of the organization behind it, which is a claim a plain TLS certificate does not make. The regulation now states that browsers have to recognize qualified certificates for website authentication and display the identity data they carry in a user-friendly form.
That clause was the most disputed part of the reform. Browser vendors argued that mandated recognition of certificates from authorities they do not themselves vet would weaken their ability to distrust a compromised authority, while the Commission's aim was to give users a verifiable statement about who runs a site. For a bank the interest is practical and not political: a QWAC is a way to make a banking domain's operator verifiable to a customer, and whether a browser surfaces that in a way customers notice is the open question. Phishing defense is the use case, and the cybersecurity in finance in Germany page covers the wider control set.
Supervision in Germany and the audit cycle
Trust services in Germany are supervised by the Bundesnetzagentur, which maintains the national trusted list of qualified providers and the services they are qualified for. A qualified provider has to be audited by an independent conformity assessment body, with the regulation setting a cycle of every 24 months, and the supervisory body acts on the result.
For a bank the supervisory structure matters at one point: verification. A bank that relies on a signature, a seal or an attestation checks the provider against the trusted list, and the list is the authoritative answer, not the provider's own statement. A bank that is itself a qualified trust service provider, which some are for internal signing, carries the audit obligation directly.
The implementing acts and what is still open
The regulation left the technical substance to implementing acts, with the first set due within six months of entry into force, covering technical specifications, certification standards and the reference framework the wallets have to meet. Member states had twelve months for wallet issuance preparation and for designating their supervisory arrangements.
What remains genuinely unsettled is where the regulation meets other law. How a wallet presentation is assessed against the strong customer authentication requirements in payments law is not answered by eIDAS 2 alone. Nor is the liability allocation when a wallet provider, a trust service provider and a bank are all involved in one failed transaction. A bank planning on either should treat the design as provisional, and the PSD3 page covers the payments side of the same question.
Does eIDAS 2 replace the 2014 regulation?
No. 2024/1183 is an amending regulation, so the instrument in force is still Regulation (EU) No 910/2014 as amended. A bank's existing qualified signature, seal and timestamp processes keep their legal basis and their legal effects, and no re-papering of them is needed on account of the reform. What the amendment adds is the wallet, the new trust service categories and the acceptance obligations.
Which obligations does eIDAS 2 put on a bank?
Two, and they are different in kind. The first is acceptance: a bank in the sectors subject to strong customer authentication requirements has to be able to accept a wallet when a user asks, which is an integration and compliance project with a deadline. The second is relying party conduct: a bank that reads a wallet has to register, declare the attributes and purposes it will request, and keep to them. Very large online platforms carry the acceptance duty too, under the same data minimization constraint, which is worth knowing for a bank that distributes through one.
eIDAS 2 and Finance Loop
Finance Loop brings the legal and the engineering side of eIDAS 2 into the same room, in its Risk & Compliance track for the acceptance and liability questions and in Digital Infrastructure & Sovereignty for the trust infrastructure underneath. Finance Loop runs these sessions in Frankfurt, where the banks that have to accept the wallet and the providers that issue the trust services both sit.
Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, tokenization, stablecoins, and DeFi. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.