This document describes the Wallet Provider onboarding process. The Trusted List of Wallet Providers is intended to convey trust in a set of legal entities and their solutions within Regulation (EU) 2024/1183. Wallet Providers are notified by Member States to the European Commission for inclusion in Trusted Lists.
This use case aligns with the Trust Infrastructure Schema, which defines the overall architecture and notification process. See Trust Infrastructure Schema - Responsibilities Matrix for details.
This document follows the WEBUILD ecosystem structure; see MVP and MVP+ Definitions in the base document.
Wherever feasible, this specification aligns with processes defined in Regulation (EU) 2024/1183 and the Architecture and Reference Framework, interpreting them for the testing purposes specific to WEBUILD.
For the common framework (terminology, MVP/MVP+, success criteria, preconditions), see Base Onboarding Framework. This document defines only Wallet Provider–specific content; it does not duplicate the base.
See Terminology and Acronyms in the base document.
-
Primary Actor [MVP]:
- Beneficiaries and Associated Partners providing a prototype of a EUDI Wallet for natural persons
- Beneficiaries and Associated Partners providing a prototype of a European Business Wallet
-
Secondary Actors [MVP]:
- Ecosystem Authority: WEBUILD WP4 Trust Infrastructure group
- Trusted List Provider: WEBUILD WP4 Trust Infrastructure group Please note: The Trust Infrastructure group is not a legal entity. However, the ecosystem authority may be required to provide certain information (e.g., legal name, company address) and to digitally sign data. For testing purposes, we therefore recommend designating at least one representative of the Trust Infrastructure group who is authorized to perform digital signing on behalf of the legal entity they represent.
-
Primary Actor [MVP+]:
- EUDI Wallet Provider for natural persons
- European Business Wallet Providers for legal persons
-
Secondary Actors [MVP+]:
- Supervisory Body entitled by a Member State of the European Union (alternative names: Registrar or Ecosystem Authority)
- Trusted List Provider (alternative name: List of trusted entity scheme operator)
-
Technical Goal [MVP]: To establish an onboarding process for wallet providers on a trusted list, enabling trusted interaction between EUDI Wallet Units and other parties involved.
-
Business Goal [MVP+]: Establish Trust Anchors for cryptographic trust validation to identify certified Providers and certified solutions of
- EUDI Wallets for natural persons CIR 2025/849
- European Business Wallets Proposal for a Regulation (EU) 2025/0358 (COD)
-
Success Criteria:
- [MVP] Pilot implementations successfully demonstrate wallet providers' onboarding; all wallet providers within WEBUILD are included on a publicly accessible trusted list maintained by the WP4 Trust Infrastructure group.
- [MVP+] See Success Criteria. Wallet Provider–specific: onboarding via notification (not registration with Registrar); trust anchors published in Trusted Lists (see Trust Infrastructure Schema - Responsibilities Matrix).
- The WEBUILD WP4 Trust Infrastructure group is assigned to act as Ecosystem Authority and Trusted List Provider for all WEBUILD participants.
- A LoTL with one Trusted List for Wallet Providers is available for onboarding; see MVP trust infrastructure: LoTL and Trusted Lists in the base document.
- WP4 Trust Infrastructure group has assigned responsibilities for the onboarding process.
- Wallet Providers are able to provide the requested data.
See RACI Matrix in the base document for RACI acronym definition and role definitions.
| RACI MATRIX - WP4 Trust Infrastructure Group | Lead/ Co-Lead | WP 4 - Testing | Responsible | [Participant] |
|---|---|---|---|---|
| Announce onboarding request to Wallet Providers | A,C | R | I | |
| Set up and manage a form to gather data from Wallet Providers | A,C | R | I | |
| Review Wallet Provider Data | A,C | R | I | |
| Decide upon listing and de-listing (Ecosystem Authority) | A,C | R | I | |
| Inform about decision | A,C | R | I | |
| Enable updates on Trusted Lists (Trusted List Provider) | A,C | R | I | |
| Host the Trusted List for Wallet Providers | A,C | R | I | |
| Engage with Wallet Providers during onboarding / troubleshooting | A,C | R | I | |
| Set up wallet conformity assessment | I | A,R | C | I |
Onboarding phase – responsibilities by actor: The following table assigns responsibility (R), accountability (A), consulted (C), or informed (I) for each administrative onboarding step. [MVP]: Ecosystem Authority and Trusted List Provider are the WP4 Trust Infrastructure group; [MVP+]: Supervisory Body and MS Trusted List Provider apply.
| Step | Wallet Provider | Ecosystem Authority / Supervisory Body | Trusted List Provider |
|---|---|---|---|
| [MVP] 1.1 Request onboarding | R (submit request and data) | A (provide form, receive) | I |
| [MVP] 1.2 Onboarding request review | C (clarify if requested) | R, A (review, decide) | I |
| [MVP] 1.3 Trusted List updated | I (notified) | R, A (approve, trigger update) | R (update TL, issue certificates) |
| [MVP+] 2.1 Request onboarding | R (conformity assessment, submit to Supervisory Body) | A (receive) | I |
| [MVP+] 2.2 Review onboarding request | C (clarify if requested) | R, A (review per CIR 2024/2981) | I |
| [MVP+] 2.3 Approve onboarding to Trusted List | I | R, A (approve, generate unique ref. id.) | I |
| [MVP+] 2.4 Confirm successful onboarding | I (receive report) | R, A (confirm) | I |
| [MVP+] 2.5 Trusted List updated | I (notified) | A | R (update TL) |
- Each Member State must have designated at least one Supervisory Body responsible for qualifying EUDI wallet providers to onboard to a Trusted List.
- Each Member State must have designated at least one Trusted List provider (Regulation EU 2024/1183 - Article 22(3)).
- The onboarding Wallet Provider can present proof of successfully passing an EUDI Wallet certification process according to CIR 2024/2981.
[MVP]
- As a baseline, there will be a LoTL with one Trusted List (TL) for all wallet providers in WEBUILD to reduce complexity. For the common LoTL/TL and trust-anchor model, see MVP trust infrastructure: LoTL and Trusted Lists in the base document.
- Trusted Lists for Wallet Providers comply with ETSI TS 119 602 v1.1.1. See ETSI Trusted Lists Implementation Profile for detailed implementation guidance, including Wallet Provider Trusted List data model, service entries, and profile-specific requirements.
- Wallet Provider Certificate Profile: See Task 3 - X.509 PKI with ETSI Alignments for certificate profile specifications. Certificates follow ETSI EN 319 412-6 (v01.00.00), section 5.
- Wallet Unit Attestation: EWC RFC 004 - Individual Wallet Attestation, OIDC4VCI 1.0, Appendix E
- Unique reference identifier for the wallet solution according to CIR 2025/849 Annex 2(a)
- Token Status List (OAuth 2.0 Token Status List)
The Wallet Provider must provide the following when requesting onboarding. [MVP]: submitted via the form provided by the Trust Infrastructure Responsible Group; [MVP+]: as required by the Supervisory Body and the regulations below. Normative: Regulation (EU) 2024/1183 (wallet providers, Trusted Lists, Article 22(3)); CIR 2024/2981 (conformity assessment, certification of EUDI Wallets); CIR 2025/849 (unique reference identifier per Annex 2(a), wallet solution data). Technical: ETSI TS 119 602 v1.1.1 (Trusted List structure, wallet solution service entries); ETSI Trusted Lists Implementation Profile (Wallet Provider Trusted List data model).
About the Wallet Provider (legal entity):
- Legal name of the wallet provider
- Trade name (including EUID where applicable)
- Legal address
- Country (Member State) in which the Wallet Provider is registered
- URI to terms and conditions
- Statement whether the Wallet Provider is a QTSP
- Statement whether the Wallet Provider is a single-person company
About each Wallet Solution:
- Statement whether the solution is an EUDI Wallet for natural persons or a European Business Wallet for legal persons
- Name of the Wallet Solution
- URI to the Wallet Solution
- URI of the Wallet Solution's status list entry (optional)
- Details on associated body, if applicable
- X.509 certificate signing request (required for issuance of the wallet solution certificate; certificate profile and issuance process: Task 3 - X.509 PKI with ETSI Alignments, ETSI EN 319 412-6 section 5; Trusted List entry includes the issued certificate per ETSI TS 119 602)
- Unique reference identifier of the wallet solution (optional; [MVP+] per CIR 2025/849 Annex 2(a))
1. Onboarding via Trust Infrastructure Responsible Group [MVP]
- 1.1 Wallet Provider requests onboarding
- 1.2 Onboarding Request Review
- 1.3 Trusted List of Wallet Providers is updated (MVP: by WP4 Trust Infrastructure group; LoTL with one TL for WEBUILD)
2. Onboarding via Supervisory Body [MVP+]
- 2.1 Wallet Provider requests onboarding
- 2.2 Supervisory Body reviews onboarding request
- 2.3 Supervisory Body approves onboarding to Trusted List
- 2.4 Supervisory Body confirms successful administrative onboarding
- 2.5 European Commission updates the EU-level Trusted List of Wallet Providers (after Member State notification; see Trust Infrastructure Schema - Overview)
2. Technical Onboarding
- Certificate issuance for wallet solutions is part of Administrative Onboarding (see 1.3, 2.5). See Task 3, ETSI EN 319 412-6, ETSI TS 119 602.
3. Post-Onboarding
- 3.1 Trusted List / Wallet Provider Monitoring
- 3.2 Trusted List Update
- 3.3 De-listing / Suspension
- 3.4 Wallet Solution Certificate / Status Revocation
The following apply to Wallet Provider onboarding (notification and Trusted List listing) at scale. Framework context: Task 2 - Trust Framework.
Wallet Providers are notified by Member States to the European Commission and do not register with a Registrar. They are listed on the Trusted List of Wallet Providers, which is compiled and published by the European Commission (MVP+); see Trust Infrastructure Schema - Responsibilities Matrix. For MVP, the Trusted List is maintained by the WP4 Trust Infrastructure group. Identification and listing use the data required by the Supervisory Body and CIR 2024/2981 / CIR 2025/849. Trusted Lists are published and linked via the List of Trusted Lists (LoTL) (ETSI TS 119 612).
Wallet solutions (EUDI Wallet for natural persons, European Business Wallet for legal persons) and their certified scope are described in the Trusted List entry. Conformity assessment and certification define the attributes and functionalities the wallet solution supports; sectorial and interoperability requirements are set by the applicable regulations and technical specifications.
Each Wallet Provider that intends to provide a European Digital Identity Wallet for natural persons or a European Business Wallet for legal persons will register itself and its wallet solution at WP 4 Trust Registry Infrastructure Working Group in WEBUILD. If the application process is successful, WP4 Trust Registry Infrastructure Working Group will update the Trusted List of Wallet Providers.
Preconditions:
- Prerequisites [MVP]
- The Wallet Provider is a beneficiary or an Associated Member of the WEBUILD Consortium
- Triggers:
- The Wallet Provider, that intends to provide a European Digital Identity Wallets (EUDI Wallets) or a European Business Wallet, applies to be listed.
- Prerequisites [MVP+]:
- Member State has designated at least one Supervisory Body responsible for qualifying Wallet Providers.
- Member States notify Wallet Providers to the European Commission (per Trust Infrastructure Schema - Member State Notification to European Commission); the European Commission compiles and publishes the EU-level Trusted List of Wallet Providers (per Trust Infrastructure Schema - Responsibilities Matrix).
- The Wallet Provider has successfully certified its wallet solution according to CIR 2024/2981.
Postconditions:
- Success:
- [MVP] WP4 Trust Infrastructure group accepts the Wallet application
- [MVP+] The Supervisory Body accepts the Wallet Provider application;
- The Wallet Provider gets a positive response to the application.
- Failure:
- [MVP] WP4 Trust Infrastructure group reject the Wallet application
- [MVP+] The Supervisory Body rejects the Wallet Provider application.
- Outputs:
- The Wallet Provider gets included in the Trusted Lists for Wallet Providers;
- Wallet Provider Certificate is issued to the Wallet Provider
- The Wallet Provider can provide their wallet solutions to users.
[MVP]
- Wallet provider requests onboarding via Open Social of the WeBuild Consortium
- The Trust Infrastructure Responsible Group provides a form and requests data from the Wallet Provider
- Wallet provider provides the following data about itself:
- legal name of wallet provider
- Trade name incl. EUID
- legal address
- Country name of Member state in which wallet Provider is registered
- URI to terms and conditions
- statement whether Wallet Provider is a QTSP
- statement whether Wallet Provider is a single-person company
- Wallet Provider provides the following data about its Wallet Solutions:
- statement whether wallet solution is an EUDI Wallet for natural persons or a European Business Wallet for legal entities
- Name of the Wallet Solution
- URI to Wallet Solution
- URI of Wallet Solution's status list entry in the Wallet Provider's status list (optional)
- details on associated body, if applicable
- X509 certificate signing request
- unique reference identifier of the wallet solution (optional)
The Trust Infrastructure Responsible Group reviews the onboarding request, verifying:
- Wallet provider is beneficiary or associated partner of WEBUILD Consortium
- Certificate Signing Request is provided in the expected format
Note: The Trust Infrastructure Responsible Group may check whether data is correct or complete, but is not required to do so.
If successful, the Trust Infrastructure Responsible Group approves the Wallet Provider to join the Trusted List for Wallet Providers. If not successful, the Trust Infrastructure Responsible Group informs about the review result and may request additional data.
[MVP]: The WP4 Trust Infrastructure group (acting as Trusted List Provider) maintains and updates the LoTL and the single Trusted List of Wallet Providers for WEBUILD; there is no EU-level or Member State–level Wallet Provider Trusted List in MVP.
- Wallet Provider receives a notification about the successful reviewing process.
- X509 certificates for Wallet Solutions are issued by the Ecosystem Authority
- Trusted List Provider (WP4) updates Trusted List of Wallet Providers.
- Wallet Provider is notified about updated Trusted List.
- Wallet Provider receives a x509 certificate for each of its wallet solutions
[MVP+]
- Wallet Provider passes for Conformity Assessment at dedicated Conformity Assessment Bodies.
- The Conformity Assessment results are provided to the Supervisory Body.
- Supervisory Body reviews compliance according to CIR 2024/2981
- Supervisory body generates a unique reference identifier for the wallet solution according to CIR 2025/849 Annex 2(a)
- Wallet provider receives a certification assessment report compliant with Article 5c of Regulation (EU) No 910/2014
[MVP+]: The European Commission compiles, maintains, and publishes the EU-level Trusted List of Wallet Providers. After the Supervisory Body approves the Wallet Provider, the Member State notifies the Commission (per Trust Infrastructure Schema - Member State Notification to European Commission); the Commission then updates the Trusted List accordingly. The Trusted List of Wallet Providers is not maintained at Member State level. See Trust Infrastructure Schema - Overview.
Wallet Providers do not have a separate technical onboarding phase. X.509 certificates for wallet solutions are issued as part of Administrative Onboarding (see sections 1.3 and 2.5). Certificate profile and issuance are described in Task 3 - X.509 PKI with ETSI Alignments and ETSI EN 319 412-6 section 5. Trusted List entries and service digital identities follow ETSI TS 119 602.
Once a Wallet Provider and its wallet solution(s) are listed on the Trusted List, the Supervisory Body and Trusted List Provider monitor compliance and keep the Trusted List accurate. Any change in the Wallet Provider’s status, certified scope, or conformity—whether initiated by the Supervisory Body, another competent authority, or the Wallet Provider—triggers an update to the Trusted List entry or de-listing, and may require revocation or update of wallet solution certificates or status information in line with applicable regulations.
Preconditions:
- Prerequisites [MVP]:
- The WP4 Trust Infrastructure group acts as Ecosystem Authority and Trusted List Provider and has defined procedures for listing, updates, and de-listing.
- Prerequisites [MVP+]:
- The Supervisory Body and Trusted List Provider have defined procedures for monitoring, Trusted List updates, de-listing, and certificate/status revocation per Regulation (EU) 2024/1183, CIR 2024/2981, CIR 2025/849, and eIDAS/ETSI Trusted List provisions.
- Triggers:
- Change in the Wallet Provider’s or wallet solution’s data (e.g. legal name, scope, conformity status);
- Supervisory Body or competent authority decision to suspend, restrict, or withdraw certification or listing;
- Wallet Provider no longer intends to provide the wallet solution or requests de-listing;
- Non-compliance with conformity or regulatory requirements.
Postconditions:
- Success:
- Trusted List entries are updated or the Wallet Provider/wallet solution is de-listed without undue delay.
- Wallet solution certificates or status list entries are revoked or updated when required.
- The Wallet Provider and other interested parties are informed of listing status changes.
- Outputs:
- Updated or removed Trusted List entries; published certificate/status revocation information where applicable.
The Supervisory Body and Trusted List Provider monitor listed Wallet Providers and their wallet solutions for continued compliance with CIR 2024/2981 and CIR 2025/849. Monitoring may include conformity surveillance, changes in legal or certification status, and notifications from competent authorities. Trusted Lists are maintained and published per ETSI TS 119 612 and ETSI TS 119 602. See Trust Infrastructure Schema and ARF – Trusted Lists.
The Wallet Provider notifies the Supervisory Body (or, under [MVP], the Trust Infrastructure Responsible Group) of any change to its data or wallet solution(s) without undue delay. The Trusted List Provider updates the Trusted List entry so that published information remains accurate. Under [MVP+], Member States notify the European Commission of changes as required; Trusted List content and format follow CIR 2025/849 and ETSI Trusted List specifications.
The Ecosystem Authority (under [MVP]) or the Supervisory Body (under [MVP+]) may decide to de-list a Wallet Provider or a wallet solution, or to set the Trusted List entry status to suspended or invalid, where required by regulation or where the provider no longer meets the conditions for listing (e.g. withdrawal of certification, non-compliance, or request by the Wallet Provider). De-listing or status change is performed by the Trusted List Provider; the Wallet Provider is informed of the decision and, where applicable, of redress or appeal. References: Regulation (EU) 2024/1183, CIR 2024/2981, CIR 2025/849, eIDAS Article 22 (Trusted Lists).
When a Wallet Provider or wallet solution is de-listed or its status is set to invalid/suspended, any X.509 certificates issued for the wallet solution (and, where used, status list entries) are revoked or updated without undue delay. Revocation status is published in line with the Trusted List and certificate policy (e.g. status list, CRL, or OCSP). Under [MVP], the Ecosystem Authority (as issuer of wallet solution certificates) revokes certificates when the Trusted List entry is removed or invalidated. Under [MVP+], the body responsible for issuing wallet solution certificates follows the same principle in line with national and Union requirements. See Task 3 - X.509 PKI with ETSI Alignments and ETSI EN 319 412 series for certificate lifecycle.
See Normative References for all references applicable to Wallet Provider onboarding processes, including Wallet Provider-specific references.