Skip to main content

The European Business Wallet explained

The European Business Wallet is a proposed EU-wide digital wallet for organisations. It gives a company one verified identity it can use with any public body in the Union, a way to prove who may act on its behalf, and a way to exchange certificates and licences with partners and government.

This page explains what it is, where the proposal came from, what it would require, how it compares with the personal EUDI Wallet, and what you can usefully do before the text is final.

What a European Business Wallet is

A European Business Wallet is a digital wallet held by an organisation rather than by a person. It carries verified facts about the company: its registration, its tax identifiers, its certifications, and the mandates it has granted to the people and systems that act for it.

The value is not storage. The value is that whoever receives those facts can verify them without phoning a register, requesting a scanned extract, or trusting a PDF. A check that takes days of back and forth today becomes one exchange between two systems.

Because it belongs to an organisation rather than a person, two practical consequences follow. A business wallet has to run unattended, because an organisation has no single phone and its processes are automated. And it has to know who inside the organisation may do what, because several people and several systems act through the same wallet.

Credenco's Business Wallet is our implementation of this concept, in production today. See the product

What a company does with one, at a glance

Three jobs, roughly in the order in which organisations get value out of them. Each one is covered in more detail further down.

Prove its own identity

Rather than sending a register extract and waiting for somebody to read it, the company presents a verified credential that the counterparty checks in a second. The same credential works in every member state, which is the hard part today.

Show mandates and representation powers

Authority to act is itself a credential: this named person may sign contracts up to this value, that system may file on our behalf. The counterparty verifies the mandate instead of accepting a signature block and hoping.

Exchange certificates and licences

Certifications, permits, insurance attestations, supplier declarations and tax statements become things you present and verify rather than attach to an email. Partners and government agencies can check them without contacting the issuer.

What the proposal actually requires

The obligation in the proposal falls on the public sector, not on business. In other words, the proposal does not ask companies to do anything. It makes sure the other side of the counter is ready.

Public sector bodies across the Union would have to accept a European Business Wallet for the core things a company does with them:

  • Identifying the organisation
  • Authenticating it in the body's own online services
  • Submitting documents and applications
  • Receiving official notifications
  • Signing and sealing what it submits
  • Acting through someone who holds a mandate from the company

An action taken through a wallet would carry the same legal effect as its paper equivalent, resting on the qualified trust services eIDAS already governs. The proposal also provides for a European Digital Directory and for mandates in verifiable form, so delegated authority becomes something a counterparty checks rather than assumes.

Companies are free to adopt it, or not

For businesses, holding a wallet stays voluntary. Nothing in the proposal forces a company to get one. What changes is that the public side of the market has to be ready to accept one, and that is what makes holding one worth the effort.

It also does not sweep away what member states already run. The Council's negotiating position is explicit that national systems may continue alongside the wallet as long as they interoperate with it, and it leaves room for exemptions on grounds of public order, public security and defence.

Timeline, and what is still open

Where the file has been, and what still has to happen before any of it binds anyone.

  1. 2025-11-19

    The European Commission publishes the proposal, COM(2025) 838 final, as part of a wider digital simplification package.

  2. 2026-04

    The rapporteur in the European Parliament's ITRE committee, Eero Heinäluoma, publishes his draft report, which opens the amendment stage.

  3. 2026-06-09

    The Council of the European Union adopts its negotiating position, backing the model while leaving member states room to keep complementary national systems.

  4. 2026-09-10

    The ITRE committee adopts its report and votes to open interinstitutional negotiations with the Council.

  5. Next

    Parliament, Council and Commission negotiate a final text in trilogue. EU leaders have asked the co-legislators to agree before the end of 2026.

  6. After adoption

    Under the Commission's proposal, public sector bodies get 24 months from entry into force to accept wallets, and up to 36 months to keep an existing delivery channel in place of the wallet's own. The Council's text instead ties the deadline to the technical implementing acts, two years after the last of them applies.

What is still open

Both co-legislators now have a position, but they are not the same one. The shape of the instrument is settled and the details are not, so anyone calling the requirements final is ahead of the evidence.

Three arguments are worth watching. The first is scope: the rapporteur's draft report proposed exempting the smallest municipalities, those with 10,000 inhabitants or fewer, from the obligation to accept a wallet, which would change how universal the acceptance really is.

The second is sovereignty. The proposal already requires wallet providers to be established in the Union and free of third country control. The rapporteur's draft wanted the same for registered delivery and cloud providers, and wanted wallet data processed and stored only inside the Union. The third is the relationship with existing national schemes, where the Council wants parallel operation, which is pragmatic and also the likeliest source of fragmentation.

How the European Business Wallet compares with the EUDI Wallet

The two wallets get confused in procurement documents, and they really are different. Both rest on European regulation, but they identify different parties and do different jobs.

AspectEUDI WalletEuropean Business Wallet
Who it identifiesA natural personAn organisation: a company, a sole trader or a public body
Where it runsOn the holder's phoneOn a server, so it keeps working when nobody is watching
Who acts through itThe holder, approving each requestEmployees and systems acting under a mandate, each within its own limits
What backs it legallyeIDAS 2.0, in force since 2024The proposed Regulation, still in negotiation
Typical useProving identity, age or a diplomaProving company facts, signing and sealing documents, exchanging attestations at volume
Available whenMember states are rolling wallets out nowThe acceptance obligation starts after the regulation is adopted

The personal wallet and the business wallet are complements, not alternatives. A single transaction often uses both: an employee proves who they are from their personal wallet, while the organisation proves the mandate that lets that employee act for it.

Until the regulation is adopted, no product can be a European Business Wallet in the legal sense, because the requirements and the provider authorisation do not exist yet. Wallets built on the same standards are in production today, so the useful question is not which label a product carries, but whether it does the three things you need: hold credentials about the company, express who may act for it, and present both verifiably.

Proving the identity of the company

Before anything else can happen, the other side has to know which company it is dealing with. In a European Business Wallet that job belongs to one deliberately small credential: EBWOID, European Business Wallet Owner Identification Data.

EBWOID does not describe the company in full. It carries at minimum the official legal name as the register holds it and a cross-border unique identifier. Like any attestation, it also says who issued it and whether it is still valid. It comes from an authentic source, typically a business register, so it is not a claim the company makes about itself.

That cross-border identifier is normally the EUID, which company law already assigns through the interconnection of business registers. Your existing numbers do not disappear because of it. The national registration number, the VAT number and the LEI stay exactly what they are, and the wallet gives them a form that travels, so a counterparty abroad can verify them instead of re-keying them.

EBWOID identifies the organisation and nothing more. Where a transaction has to be tied to a person, the relying party asks for that person's PID alongside it. That separation is deliberate: it keeps the company verifiable without dragging personal data into every business transaction. What EBWOID contains

Mandates and representation powers

Knowing which company you are dealing with is the easy half. The hard half is knowing whether the person or the system in front of you may actually commit that company, and up to what.

Today that is proven with a register extract, a signature block and a measure of goodwill. The extract lists the statutory directors and is often weeks out of date by the time it arrives. It says nothing about the procurement manager who signs the order, because everything below board level lives in internal policy a counterparty cannot see.

A wallet turns representation into something verifiable. Statutory power arrives from the register as a credential in its own right. Delegated power is issued by the company itself: this named person may sign contracts up to this value, that system may submit filings on our behalf, valid until this date. The counterparty then gets an answer rather than an impression.

Two consequences are worth planning for. Revocation becomes real, because withdrawing a mandate is an act the wallet performs rather than an email somebody has to remember to send. And the company has to be able to state its own mandates in the first place, which is usually the slowest part of any adoption.

Dealing with government

This is where the proposal bites, because the public side is the side that would be obliged to accept a wallet. Three kinds of interaction change the most.

Public tenders

A tender is a document exercise before it is a commercial one. The bidder proves it is registered, solvent, insured, certified for the work and represented by somebody entitled to sign, then proves all of it again for the next tender in the next country. Presented from a wallet, those facts are credentials the contracting authority verifies in the exchange itself, so eligibility stops being a filing exercise that quietly favours whoever can afford the paperwork.

Permits and licences

Permits work the other way round: the authority issues, and the company later has to show what it was issued. A permit held as a credential can be shown to an inspector, a client or an authority abroad without a certified copy. It also carries its own status, so a suspended licence shows up as suspended instead of as a valid looking PDF.

Submissions and official notifications

The third is the channel itself. A wallet gives the company an address that public bodies can use to reach it with legal effect, and that the company can use to submit documents back. That is what the acceptance obligation buys: identification, authentication, submission and notification, without a national portal account for each member state.

Doing business with other companies

Nothing in the proposal obliges another company to accept your wallet. Companies will do it anyway, for the same reason they accept a bank transfer rather than a cheque: it is cheaper than the alternative. Three patterns are already running in production.

Supplier onboarding

Onboarding is where most organisations feel the cost first. A new supplier sends registration documents, certifications, insurance and bank details, somebody checks them by hand, and the pack is stale within the year. When the supplier presents them as credentials, the buyer verifies them in one exchange and can re-check them later without asking again.

E-invoicing

Invoicing is the case where identity is the whole problem. Invoice fraud works because the receiving side cannot cheaply confirm that the sender is who the invoice says it is, and that the payment details belong to them. Invoices exchanged between parties that have already proven who they are remove that class of fraud, and the correction work behind it.

The company passport

The company passport is the general case behind the other two. Rather than assembling a fresh due diligence pack for every counterparty, the company keeps one verified set of facts about itself and presents whatever a relationship needs. It is the same data KYB checks ask for, issued once and reusable.

What this already looks like in practice

These are live Credenco cases running on the same building blocks the European Business Wallet is made of, so none waits on the proposal.

Who can provide a business wallet

Under the proposal a provider notifies the national supervisory body, which checks it against the requirements and keeps supervising it afterwards. Member states designate the same supervisory bodies they already use under eIDAS, so the structure will look familiar to anyone who knows qualified trust services.

None of that is in force yet, so for now the phrase business wallet provider describes a product category rather than a legal status. When choosing one, ask not whether the vendor uses the term, but how concretely its product moves towards those requirements.

FIDES, the European digital trust community, keeps an Ecosystem Explorer that catalogues wallets for organisations and the use cases running on them. Our Business Wallet is listed there alongside roughly two dozen other products from vendors across Europe. Read it as a map of who is building what rather than as a conformance list.

Our Business Wallet won Best Business Wallet 2026 at the FIDES Community Awards, taking both the most community votes and the highest score from the expert jury. View our awards

What it costs to adopt

Nobody can quote a European Business Wallet price yet, because the regulation does not set one. The personal EUDI Wallet has to be free for a natural person acting non-professionally, but the business wallet text is silent on price, so cost depends on the provider and the deployment.

The costs that actually decide a business case are internal anyway. Getting the company's own facts straight, deciding and recording who may act for it, and integrating one process from end to end are the real work. Licence fees are usually the smaller number, and the one easiest to compare.

On the other side of the ledger, the Commission estimates that European Business Wallets could unlock 150 billion euro a year in savings for businesses, on top of up to 5 billion euro in administrative cost savings by 2029 from the wider digital package they belong to. Treat those as a direction of travel for the single market, not a forecast for one company, and build your case on processes you can measure.

How to get started now

You do not have to wait for the regulation to be final, and waiting is the expensive option. The work that takes time is your own data and the decisions around it.

Find the facts you keep proving

Registration extracts, certifications, insurance, signing authority: whatever counterparties ask you for again and again is what belongs in a wallet first.

Write down who may act for you

Mandate management is the part organisations underestimate. Knowing which employee or system may do what, within which limits, is a prerequisite rather than a wallet feature.

Run one real exchange end to end

Pick one counterparty and one credential and put it into production. A single working exchange teaches you more than a year of reading specifications.

Frequently asked questions

Is the European Business Wallet mandatory for companies?

No. The proposal obliges public sector bodies to accept a wallet, but holding one stays voluntary for businesses and sole traders. The incentive is practical rather than legal: once public administrations across the EU have to accept it, a wallet becomes the fastest way to deal with them.

How is it different from the personal EUDI Wallet?

The personal EUDI Wallet identifies a natural person and runs on that person's phone. A European Business Wallet identifies a legal entity, runs on a server so it can work unattended, and is used by employees and systems acting under a mandate. Both rest on the same credential technology and are designed to work with each other.

When will it be available?

The proposal was published on 19 November 2025 and is now in negotiation between the European Parliament and the Council. Under the Commission's proposal, public sector bodies would get 24 months from entry into force to accept wallets. The Council wants that clock to start only once the technical implementing acts apply. Wallets built on the same standards, including our Business Wallet, are in production today, so nothing stops a company from starting now.

What is EBWOID?

EBWOID, European Business Wallet Owner Identification Data, is the credential that says which organisation a wallet belongs to. It comes from an authentic source such as a business register and carries at minimum the official legal name and a cross-border unique identifier, plus, like any attestation, who issued it and whether it is still valid. It identifies the organisation only, so a transaction that also has to name a person asks for that person's PID alongside it.

What will a European Business Wallet cost?

The proposal does not set a price. The personal EUDI Wallet has to be free of charge for natural persons acting non-professionally, but the business wallet text is silent on cost, so it will depend on the provider and on how the wallet is deployed. In practice the larger cost is internal: getting your own company data straight and deciding who may act for you.

What makes a company a business wallet provider?

Under the Commission's proposal a provider notifies a national supervisory body, the same structure eIDAS uses for qualified trust services. The Council's position turns that into an authorisation, which the body has 60 days to review. Until the regulation is in force, business wallet provider describes a product category rather than a legal status.

Technical deep dive

This page stops where the implementation starts. If you need the interfaces, the credential formats and the integration steps, our documentation covers them. Read the Business Wallet documentation

Sources

  1. COM(2025) 838 final, Proposal for a Regulation on the establishment of European Business Wallets
  2. European Commission, European Business Wallets policy page
  3. European Parliament, procedure file 2025/0358(COD)
  4. European Parliament, Legislative Train Schedule, European business wallets
  5. Council of the European Union, negotiating position of 9 June 2026
  6. European Commission, announcement of the digital package, 19 November 2025
  7. European Parliament, ITRE draft report PE785.244, rapporteur Eero Heinäluoma
  8. European Parliament, ITRE report A10-0240/2026
  9. Council of the European Union, text of the negotiating position, document 10346/26
  10. European Council, conclusions of 19 March 2026

This page is informational and does not constitute legal advice. The proposal is still being negotiated, so for authoritative guidance consult the European Commission, the Council and the European Parliament directly.

Talk to us about the European Business Wallet