Regulation (EU) 2024/1183, better known as eIDAS 2, entered into force on 20 May 2024, and its next milestone lands at the end of this year. Every Member State has to provide at least one European Digital Identity Wallet within 24 months of the entry into force of the implementing acts the Commission adopted in late November 2024. That deadline falls in December 2026.
Slovakia has a starting point in the eDoklady app run by the Ministry of the Interior — an ID card and driving licence on the phone, plus sign-in to the slovensko.sk portal. The eIDAS 2 wallet is a wider concept: alongside identity it carries verified attributes issued by third parties, and the user discloses only the data a given service actually needs.
Who has to do what, and by when
- Public administration. Where access to an online service of a public sector body requires electronic identification, the wallet has to be accepted as one of the options.
- Regulated private sectors. Transport, energy, banking, financial services, social security, health, drinking water, postal services, digital infrastructure, education and telecommunications — wherever law or contract requires strong user authentication, the wallet has to be accepted within 36 months of the implementing acts entering into force, meaning by the end of 2027. Micro and small enterprises are exempt.
- Anyone relying on the wallet. A relying party has to register in the Member State where it is established and state the intended use together with the list of data it will request from users.
Where this hits existing IT
Relying party registration is essentially a data minimisation exercise. You declare what you will ask for — and you may only ask for what you declared. That assumes you know which attributes each service genuinely needs. In most organisations that map does not exist; sign-up forms have accumulated fields over the years that nobody ever removed.
The second point is that the wallet cannot be the only route. Users adopt it voluntarily, and service cannot be refused to someone who does not have it. Authentication flows are therefore added rather than replaced — two branches to test, two to monitor, two to support.
The third point is the service desk. Wallet-based verification comes with its own class of incidents: device replacement, revoked attestations, failed attribute disclosure. Without prepared procedures in the knowledge base, those tickets land on second line and stay there.
What is worth doing now
- A list of the services that use electronic identification today, including those that sign users in through a national eID portal.
- A decision per service on whether wallet acceptance will be an obligation or an option, and on what date.
- For regulated sectors, budgeting the 2027 work in next year's plan. Registration, integration and testing are not last-quarter tasks.
- Reflecting access management changes in security documentation — under Decree 227/2025, authentication is one of the audited measures.
Public debate sells the wallet as an ID card on a phone. For IT it is closer to a new identity channel with its own registration, its own rules about data and its own support load — on a timeline set by the regulation rather than by a project plan.