← All posts ·

Europe is building an official identity layer — eIDAS 2, in plain words

Our previous post looked at payment rules and the question they keep converging on: who is getting paid? This one is about the other half of the story — the machinery Europe is building to answer questions like that in general. It is called eIDAS 2, it is already law, and it deserves to be understood in plain words, because most of what is written about it is aimed at identity specialists.

What eIDAS 2 actually is

eIDAS 2 is Regulation (EU) 2024/1183, in force since 20 May 2024. It amends the 2014 framework that already governs electronic signatures and trust services across the EU, and adds one big new obligation: every member state must offer its citizens and its businesses a digital identity wallet — an app in which a person or a company holds official, machine-verifiable statements about themselves and chooses, case by case, what to share.

This is not a white paper. Five implementing regulations — the detailed technical rules on security, data formats, interoperability protocols, notifications and conformity assessment of wallets — were adopted on 28 November 2024, which started the clocks that matter.

The dates that matter

  • Late 2026. Every member state must make at least one approved wallet available, free of charge, to people and to legal entities.
  • Late 2027. The sectors that are already required to identify their customers strongly — banks, telecoms, very large online platforms among them — must accept the wallet as a way to do it.

In other words: within roughly a year, an official, machine-verifiable way for a European company to prove things about itself stops being a pilot project and becomes standard infrastructure with acceptance obligations behind it.

The piece machine commerce should watch

Inside the framework, the piece that matters most for machine commerce is the electronic attestation of attributes: a digitally signed, machine-checkable statement that some recognised authority vouches for a specific fact — a person's age, a professional qualification, a company's registration, the power to represent it. Legal entities can hold and present these too; a "business wallet" built on the same rails is the declared direction of travel.

Around it sits an accountability structure worth noticing: the parties who ask for attributes — the relying parties — must themselves register, declare what they will ask for and why, and appear on national, machine-readable lists. Verification happens against published trusted lists, not by calling anyone in the moment.

Why this rhymes with what we build

Look at the shape of that design: a signed statement from a registered issuer, checked locally against published lists. No form to fill, no database to phone, no personal data changing hands beyond what the statement itself asserts.

That is the same architectural shape as ZadQ's seller verification: a registered issuer signs an attestation binding an endpoint to a verified, accountable operator, and anyone can check the signature locally, for free. It is also why our credential model is built on the same open formats the European framework uses — OpenID4VCI for issuing credentials and OpenID4VP for presenting them — and is designed for compatibility with EUDI-framework wallets.

And look at what eIDAS 2 deliberately does not do: it proves who someone is and what is true about them. It does not say who answers financially when a paid API endpoint takes an agent's money and fails to deliver. Identification and accountability are neighbouring layers, not the same layer — which is exactly why we build the second one to sit comfortably next to the first.

What this does not mean

The limits, stated as plainly as the promise:

  • ZadQ is not a qualified trust service provider, and a ZadQ attestation is not an eIDAS attestation of attributes. The rhyme is architectural; the legal regimes are different, and we do not borrow the framework's authority.
  • No wallet is needed to use ZadQ. Everything described on this site works today, with no European wallet in the flow — and every integration keeps working whatever the wallet timeline does.
  • "Designed for compatibility" describes formats, not endorsement. eIDAS, EUDI and the European institutions behind them are named descriptively; no affiliation is implied.
  • This post is not legal advice — for what eIDAS 2 obliges your organisation to do, and when, ask your advisers.

Where this goes

Put the two posts together and the direction is hard to miss. Payment rules are converging on identified counterparties; identity rules are building the official machinery to prove attributes without paperwork. What sits between them — who is accountable, with money behind the answer, for the endpoint a machine just paid — is the layer we build. Europe is pouring the foundations either way.

If you are working out where your endpoints, your marketplace or your regulated integration fit in that picture, talk to us — or start with what we publish instead of certifications and the payments-sector page.

Selling over x402? Let's find out if we fit.

We are onboarding our first partners: API sellers, publishers, marketplaces and regulated platforms.