FB pixel

ENISA invites feedback for EU Digital Identity Wallet cybersecurity certification

ENISA invites feedback for EU Digital Identity Wallet cybersecurity certification
 

The European Union Agency for Cybersecurity (ENISA) has launched a public consultation on a draft cybersecurity certification scheme for European Digital Identity (EUDI) Wallets and electronic identities.

The publication covers certification of the cybersecurity of cloud services in accordance with the EU’s Cybersecurity Act. It is designed to ensure that digital ID wallets operate securely and uniformly across EU member states.

The consultation seeks feedback on the scheme’s principles, structure and proposed elements, with responses due by April 30th, 2026. ENISA will hold a webinar on the draft document on April 8th at 3 PM CEST.

EUDI Wallets will also be the topic of the upcoming 2026 European Cybersecurity Certification Conference, scheduled for April 15th, 2026, in Cyprus.

ENISA was tasked by the European Commission to develop the certification scheme in 2024 through an Ad Hoc Working Group. In February this year, the agency signed a two-year agreement worth 1.6 million euros (US$1.8 million) to support national EUDI Wallet certification schemes in EU member states.

Last year, the organization also held the 11th Trust Services and eID Forum in Split, Croatia, which discussed the details of EUDI Wallet implementation and the challenges of cybersecurity certifications.

Digital rights group identifies 5 privacy problems in EUDI Wallet

EU countries are required to have at least one certified EUDI Wallet by the end of 2026. Not everyone, however, is satisfied with the privacy safeguards introduced in the upcoming digital IDs.

Austria-based digital rights group Epicenter.Works says it has identified five data privacy concerns in the EUDI Wallet’s technical proposals, among which the most pressing are those related to biometrics. The organization also says that many private representatives have explicitly praised the EU Commission for its efforts to weaken data protection.

The European Commission has proposed including a mandatory biometric photo in the minimum data set that every EUDI wallet must contain. This, however, could mean that every time a person uses their digital ID wallet, whether for age verification, ordering books, or signing contracts, a facial image could potentially be transmitted.

“During the trilogue negotiations on the eIDAS Regulation, a clause explicitly intended to protect users from biometric processing was expressly removed from the text. The Commission now appears poised to introduce mandatory biometrics via an implementing act – thereby completely bypassing Parliament,” says the organization, which operates under the umbrella of European Digital Rights (EDRi).

Other issues include loopholes in registration certificates that allow for excessive data requests and weakened pseudonymity rights, enabling excessive identification. The current draft also makes certificates that allow the wallet to detect impermissible data requests optional rather than mandatory.​

Finally, the group says that current technical specifications allow existing passkey solutions, such as Google Passkeys or iCloud Keychain, to be used as a substitute for true EUDI wallet integration.​

“This means we’re stuck with the same proprietary options as before, while the regulation gives the impression of having solved the problem,” it says.​

Related Posts

Article Topics

 |   |   |   |   |   |   | 

Latest Biometrics News

 

Biometrics regulations, misconceptions threaten to undermine EUDI Wallets

Is it a case of shoot first and ask questions later? Asking for a biometrics provider. Maybe it’s due caution…

 

ID4Africa vendors see Africa leapfrogging legacy digital identity systems

The annual ID4Africa AGM is a major world event in identity – a must-attend for many biometrics providers working on…

 

Gataca boosts age assurance pitch with certification to ISO standard by ACCS

Madrid-based Gataca is now certified as a provider of privacy-preserving age assurance following an independent assessment. The company successfully completed…

 

BixeLab testing activity highlights expansion of biometric assurance

As digital identity systems evolve, biometric testing labs are increasingly becoming central to trust, compliance and interoperability. BixeLab’s recent activity…

 

Apple removes Russian digital ID app Max from its stores citing sanctions

Apple has removed Russian state-backed messaging and digital ID platform Max from its official App Store, affecting more than 20…

 

G7 backs privacy-preserving age assurance as Japan proposes social media access limits

Japan is considering new restrictions on minors’ access to social media while stopping short of blanket age bans. While countries…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events