Independent. MyID is not affiliated with the Department of Social Protection, MyGovID, or the Government of Ireland.

New EUDI Wallet rules: what Irish organisations should do now

Published 2026-08-27Updated 2026-08-27By MyID Editorial

EU rules adopted in July 2026 update wallet standards, relying-party checks and biometric disclosure controls. Irish organisations should tighten their evidence and procurement questions now without pretending that every production detail is settled.

Business briefing · source check 27 August 2026

This web edition is independent and does not contain sponsored placement. It is general information, not legal, compliance or security advice.

The status change: these rules are final

Commission Implementing Regulation (EU) 2026/1731 was adopted on 15 July 2026, published on 22 July and is in force. It amends four earlier EUDI Wallet implementing regulations to align them with newer standards, specifications and procedures. This is final EU law, not a proposal, consultation, pilot or vendor announcement.

What changed for relying parties and wallet users

The amended rules require wallets to validate wallet-relying-party registration certificates and compare requested attestations and attributes with the relying party's registered intended use. The Regulation also introduces safeguards when a portrait is requested: the wallet must warn that biometric data is involved and require explicit, specific confirmation. User confirmation is a technical safeguard; it does not create a legal basis for processing.

Registration is becoming machine-readable

Commission Implementing Regulation (EU) 2026/1730 also amends the relying-party registration rules. It requires intended uses to be expressed in registration certificates, introduces a harmonised general access policy, requires a privacy-policy URL for the intended use and provides for automated certificate issuance after registration. For an Irish buyer, the practical question is not simply whether a supplier can read a credential; it is whether the organisation's entity, intended use and requested attributes can be represented and governed through the eventual Irish registration route.

Important dates are not all the same

The Regulation is in force, but some technical duties have later application dates. Requirements concerning wallet validation of relying-party registration certificates and the possibility of including a portrait in mandatory person-identification data are framed around 11 August 2028. Buyers should record the date and scope of each requirement instead of turning one future date into a claim that the entire framework is optional until then.

The Irish buyer decision

Add an evidence schedule to any wallet or verification procurement now. Ask the supplier to name the exact implementation role, OpenID4VP or OpenID4VCI version, HAIP profile, credential format, transport, trust configuration and test date. Ask separately how the service validates relying-party authority, detects over-requesting, warns the user and records consent. A roadmap answer should be labelled roadmap, not production support.

Conformance is useful, but it is not the whole certification story

OpenID Foundation conformance tests can show that an issuer, wallet or verifier behaves correctly for the tested OpenID and HAIP role. That is valuable interoperability evidence. It is not the same as EUDI Wallet cybersecurity or statutory certification, and it does not by itself prove security, privacy, accessibility, Irish availability or fitness for a buyer's configured use case.

Remote onboarding now has a concrete legal reference

Commission Implementing Regulation (EU) 2026/798 is final and in force. It sets reference standards and specifications for combining an electronic-identification means at assurance level substantial with additional remote-onboarding procedures so the overall process meets assurance level high. Its Annex refers to ETSI TS 119 461 V2.1.1 with adaptations. Irish teams evaluating onboarding should therefore ask how the exact workflow maps to the referenced clauses, rather than accepting a general claim of high assurance.

Sector lens: business and payments remain pilot evidence

The European Commission now describes six Large Scale Pilot projects overall, with two active and four concluded. WE BUILD focuses on business and payment uses across B2B, B2G and B2C interactions. APTITUDE covers travel and vehicle-related credentials. These programmes are useful implementation evidence, but they are still pilots and do not prove that a production service, credential issuer or relying-party registration route is available in Ireland.

What Irish organisations can do this quarter

Keep one register separating final law, standards, certification evidence, pilot results and supplier claims. Map the minimum attributes required for each use case. Document non-wallet fallback and accessibility. Test over-requesting, invalid or expired relying-party credentials, user cancellation, biometric disclosure warnings and recovery. Re-check the Irish registration and governance route before launch because MyID has not found a final public Irish production process for relying parties.

Primary sources

Continue the research

MyID for Business · Briefing archive · Subscribe