This document is an excerpt from the EUR-Lex website
Document 32026R1731
Commission Implementing Regulation (EU) 2026/1731 of 15 July 2026 amending Implementing Regulations (EU) 2024/2977, (EU) 2024/2979, (EU) 2024/2980 and (EU) 2024/2982 as regards applicable standards and specifications
Commission Implementing Regulation (EU) 2026/1731 of 15 July 2026 amending Implementing Regulations (EU) 2024/2977, (EU) 2024/2979, (EU) 2024/2980 and (EU) 2024/2982 as regards applicable standards and specifications
Commission Implementing Regulation (EU) 2026/1731 of 15 July 2026 amending Implementing Regulations (EU) 2024/2977, (EU) 2024/2979, (EU) 2024/2980 and (EU) 2024/2982 as regards applicable standards and specifications
C/2026/4827
OJ L, 2026/1731, 22.7.2026, ELI: http://data.europa.eu/eli/reg_impl/2026/1731/oj (BG, ES, CS, DA, DE, ET, EL, EN, FR, GA, HR, IT, LV, LT, HU, MT, NL, PL, PT, RO, SK, SL, FI, SV)
In force
|
Official Journal |
EN L series |
|
2026/1731 |
22.7.2026 |
COMMISSION IMPLEMENTING REGULATION (EU) 2026/1731
of 15 July 2026
amending Implementing Regulations (EU) 2024/2977, (EU) 2024/2979, (EU) 2024/2980 and (EU) 2024/2982 as regards applicable standards and specifications
THE EUROPEAN COMMISSION,
Having regard to the Treaty on the Functioning of the European Union,
Having regard to Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC (1), and in particular Article 5a(23) thereof,
Whereas:
|
(1) |
To ensure the highest level of harmonisation among Member States for the development of European Digital Identity Wallets, the technical specifications for the wallets rely on the work carried out on the basis of Commission Recommendation (EU) 2021/946 (2) and in particular the architecture and reference framework. As the architecture and reference framework has evolved significantly since Commission Implementing Regulations (EU) 2024/2977 (3), (EU) 2024/2979 (4), (EU) 2024/2980 (5), and (EU) 2024/2982 (6), those Implementing Regulations should now be amended to align them with new standards, specifications and procedures. In accordance with the objectives of Regulation (EU) No 910/2014, a number of standards have been selected to meet these specific requirements. These standards should reflect established practices and be widely recognised within the relevant sectors. For example, as the W3C VCDM format is used as the reference format for attestations in particular in the educational sector, the European Digital Identity Wallets should also support this format when the new profiles on the W3C VCDM format are available. Where necessary, these standards should be adapted or complemented in order to ensure the security and trustworthiness of European Digital Identity Wallets, while facilitating cross-border interoperability and the effective functioning of the internal market. |
|
(2) |
For any use of the wallet that requires the presentation of the wallet user’s portrait, the wallet solutions must support the functionality of selective disclosure and disclosure must be under the full control of the user. To protect the ability to decide upon disclosure, and the portrait against unintended or unauthorised request for disclosure the architectural design of the European Digital Identity Wallets should provide for warning mechanisms and logging all transactions related to the use of the portrait. To ensure that the wallet user is aware of sharing biometric data, the warnings should indicate that the request involves the sharing of biometric data and specifically require the user to confirm disclosure. Where a relying party processes the portrait for the purpose of uniquely identifying a natural person or for confirming that person’s claimed identity, Article 6 and 9 of Regulation (EU) 2016/679 of the European Parliament and of the Council (7) apply as well as all other requirements of that Regulation, including that the processing of the portrait by relying parties should be limited to what is necessary for intended use. The intended use should be communicated to the wallet user, together with the request for disclosure, in clear and intelligible language. To duly consider the sensitivity of biometric data, the wallet user should explicitly and specifically confirm the disclosure of the portrait. Silence or pre-ticked boxes should not be considered as confirmation by the wallet user. The explicit confirmation of the wallet user should be a technical safeguard and not in itself provide a legal ground for processing. As set out in paragraph 4 of Article 9 of Regulation (EU) 2016/679 Member States may maintain or introduce further conditions, including limitations, with regard to the processing of genetic data, biometric data or data concerning health. |
|
(3) |
To give Member States sufficient time to adapt their national procedures, the wallet user’s portrait may be part of the mandatory person identification data for the natural person only as of 11 August 2028. Where these images are sourced from existing identity documents, such as identity cards or passports, the relevant requirements laid down in Council Regulations (EU) 2025/1208 (8) or (EC) No 2252/2004 (9) respectively apply. |
|
(4) |
Regulation (EU) No 910/2014 requires that wallets are capable of displaying an EU Digital Identity Wallet Trust Mark, as a verifiable, simple, and recognisable indication that a wallet has been provided in accordance with the Regulation. The use of such a Trust Mark will support the effective functioning of the internal market, guarantee fair competition and protect consumer interests. To enable the use of such a Trust Mark, the visual and technical characteristics of the Trust Mark should be established. |
|
(5) |
As set out in Article 12b of Regulation (EU) No 910/2014, gatekeepers are to allow providers of European Digital Identity Wallets and issuers of notified electronic identification means effective interoperability with, and, for the purposes of interoperability, access to, the same operating system, hardware or software features. Such effective interoperability and access are to be provided free of charge and irrespective of whether those hardware or software features form part of the operating system, are available to, or are used by, that gatekeeper when providing such services. As all wallet solutions should support a common set of protocols and interfaces in order to ensure usability, security and interoperability across Member States, gatekeepers should enable the operating system, hardware or software features necessary to implement the protocols and interfaces set out in Annex XII to this Regulation. In this context, in online cross-device flows, for both the physical proximity check and data transfer between the two devices, a local communication channel as enabled by the Client To Authenticator Protocol (CTAP) specification version 2.3 (10) should be preferred by gatekeepers to using CTAP Hybrid tunnel services. |
|
(6) |
To give Member States, providers of wallet-relying party registration certificates and wallet providers sufficient time to enable wallet units to authenticate and validate wallet-relying party registration certificates, this requirement should only apply as of 11 August 2028. |
|
(7) |
Regulation (EU) 2016/679 and, where relevant, Directive 2002/58/EC of the European Parliament and of the Council (11) apply to all personal data processing activities under this Regulation. |
|
(8) |
The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation (EU) 2018/1725 of the European Parliament and of the Council (12) and delivered its opinion on 17 April 2026 (13). |
|
(9) |
The measures provided for in this Regulation are in accordance with the opinion of the committee established by Article 48 of Regulation (EU) No 910/2014, |
HAS ADOPTED THIS REGULATION:
Article 1
Amendments to Implementing Regulation (EU) 2024/2977
Implementing Regulation (EU) 2024/2977 is amended as follows:
|
(1) |
The following Article 3a is inserted: ‘Article 3a Protection of the portrait 1. In addition to information requirements pursuant to Regulation (EU) 2016/679, wallet providers shall ensure that the wallet solutions they provide issue warnings to wallet users where wallet-relying parties request the disclosure of the portrait, indicating that the request involves the sharing of biometric data and requires confirmation for the selective disclosure of the portrait. 2. For the implementation of selectively disclosing the portrait to a wallet-relying party, the wallet providers shall ensure the wallet solutions require the wallet user to explicitly and specifically confirm the presentation of the portrait. 3. The portrait shall not be retained by wallet-relying parties unless its processing is necessary for the purposes of identification and authentication in compliance with Union data protection law or where this is provided for by Union or national law, in compliance with Union data protection law. The portrait shall not be transferred to third countries or international organisations unless permitted by Union data protection law.’ |
|
(2) |
in Article 4, paragraph 1 is replaced by the following: ‘1. Electronic attestations of attributes issued to wallet units shall comply with at least one of the standards set out in Annex II of Implementing Regulation (EU) 2024/2979.’ |
|
(3) |
in Article 5, paragraph 4, point (b) is replaced by the following:
|
|
(4) |
The Annex is replaced by the text set out in Annex I to this Regulation. |
Article 2
Amendments to Implementing Regulation (EU) 2024/2979
Implementing Regulation (EU) 2024/2979 is amended as follows:
|
(1) |
in Article 3, paragraph 2 is deleted; |
|
(2) |
in Article 5, paragraph 1, point (a) is replaced by the following:
|
|
(3) |
the following Article 5a is inserted: ‘Article 5a Cryptographic mechanisms Wallet providers shall, for the purposes of paragraph 2 of Article 4, use only the cryptographic mechanisms referred to in Annex Ia.’ |
|
(4) |
Article 6 is amended as follows:
|
|
(5) |
in Article 9, paragraph 2, point (b) is replaced by the following:
|
|
(6) |
in Article 10, paragraph 1 is replaced by the following: ‘1. Wallet providers shall ensure that electronic attestations of attributes issued in accordance with the technical specifications applicable for common embedded disclosure policies set out in Annex III can be processed by the wallet units that they provide.’ |
|
(7) |
Article 12 is amended as follows:
|
|
(8) |
in Article 14, paragraph 1 is deleted; |
|
(9) |
the following Article 14a is inserted: ‘Article 14a EU Digital Identity Wallet Trust Mark 1. Wallet providers shall ensure that wallet units display the EU Digital Identity Wallet Trust Mark. The EU Digital Identity Wallet Trust Mark shall be in the form set out in Annexes VI and VII. 2. Wallet providers shall ensure that wallet units enable wallet users to access information allowing them to verify the certification status of the wallet solution. For that purpose, wallet providers shall ensure that, following the registration of a wallet solution, the corresponding wallet units include the URLs provided by the European Commission for such verification. Wallet providers shall ensure that their wallet units have access to EU Digital Identity Wallet Trust Mark data that comply with the technical specifications set out in Annex VIII. 3. The reference colours for the EU Digital Identity Wallet Trust Mark shall be Pantone No 661 and 116, or blue (100 % cyan + 67 % magenta + 0 % yellow + 40 % black) and yellow (0 % cyan + 20 % magenta + 100 % yellow + 0 % black), when a four colour process is used; when RGB colours are used the reference colours shall be blue (0 red + 51 green + 153 blue) and yellow (255 red + 204 green + 0 blue). 4. Only where the use of colour is not practicable, the EU Digital Identity Wallet Trust Mark may be used in black and white as set out in Annex VII. 5. Where the EU Digital Identity Wallet Trust Mark is used on a dark background, it may be used in negative format using the same background colour. Where the EU Digital Identity Wallet Trust Mark is used in colour on a coloured background that makes it difficult to see it, a delimiting outer line around the EU Digital Identity Wallet Trust Mark may be used to improve contrast with the background colours. 6. The EU Digital Identity Wallet Trust Mark shall have a minimum size of 64 × 85 pixels at 150 dpi. 7. Wallet providers shall ensure that the EU Digital Identity Wallet Trust Mark is used in a manner enabling the clear indication of the wallet unit that the EU Digital Identity Wallet Trust Mark pertains to. The EU Digital Identity Wallet Trust Mark may be associated with graphic or textual elements clearly indicating the wallet unit it is used for, provided that they do not change its recognisability as an EU Digital Identity Wallet Trust Mark, nor alter the association with the list of certified European Digital Identity Wallets referred to in Article 5d of Regulation (EU) No 910/2014. 8. Where wallet providers have revoked a wallet unit attestation, they shall ensure that the EU Digital Identity Wallet Trust Mark is no longer displayed by the corresponding wallet unit.’ |
|
(10) |
Annexes Ia and Ib are added as set out in Annex II and Annex III to this Regulation. |
|
(11) |
Annex II is replaced by Annex IV to this Regulation. |
|
(12) |
Annex III is replaced by Annex V to this Regulation. |
|
(13) |
Annex IV is amended in accordance with Annex VI to this Regulation. |
|
(14) |
Annex V is deleted. |
|
(15) |
The text set out in Annex VII to this Regulation is inserted as Annex VI. |
|
(16) |
The text set out in Annex VIII to this Regulation is inserted as Annex VII. |
|
(17) |
The text set out in Annex IX to this Regulation is inserted as Annex VIII. |
Article 3
Amendments to Implementing Regulation (EU) 2024/2980
Implementing Regulation (EU) 2024/2980 is amended as follows:
|
1. |
in Article 5, paragraph 2 is replaced by the following: ‘2. Where applicable, the Commission shall establish, maintain and publish a list compiling the information notified by Member States on wallet providers, providers of person identification data, providers of wallet-relying party access certificates and providers of wallet-relying party registration certificates, as referred to in Annex II, sections 2, 3, 4 and 5.’ |
|
2. |
Annex II to Implementing Regulation (EU) 2024/2980 is amended as set out in Annex X to this Regulation. |
Article 4
Amendments to Implementing Regulation (EU) 2024/2982
Implementing Regulation (EU) 2024/2982 is amended as follows:
|
(1) |
in Article 1, paragraph 2 is replaced by the following: ‘(2) the presentation of attributes of person identification data and electronic attestations of attributes to wallet-relying parties;’ |
|
(2) |
Article 3 is amended as follows:
|
|
(3) |
in Article 4, paragraph 1 is replaced by the following: ‘1. Wallet providers shall ensure that wallet solutions support the protocols and interfaces set out in Annex I for the issuance of person identification data and electronic attestations of attributes to wallet units.’ |
|
(4) |
Article 5 is amended as follows:
|
|
(5) |
Article 8 is replaced by the following: ‘Article 8 Entry into force This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union. Article 3(4) shall apply from 11 August 2028. This Regulation shall be binding in its entirety and directly applicable in all Member States.’ |
|
(6) |
The Annex is deleted. |
|
(7) |
The text set out in Annex XI to this Regulation is added as Annex I. |
|
(8) |
The text set out in Annex XII to this Regulation is added as Annex II. |
Article 5
Entry into force
This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
This Regulation shall be binding in its entirety and directly applicable in all Member States.
Done at Brussels, 15 July 2026.
For the Commission
The President
Ursula VON DER LEYEN
(1) OJ L 257, 28.8.2014, p.73, ELI: http://data.europa.eu/eli/reg/2014/910/oj.
(2) Commission Recommendation (EU) 2021/946 of 3 June 2021 on a common Union Toolbox for a coordinated approach towards a European Digital Identity Framework (OJ L 210, 14.6.2021, p. 51, ELI: http://data.europa.eu/eli/reco/2021/946/oj).
(3) Commission Implementing Regulation (EU) 2024/2977 of 28 November 2024 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards person identification data and electronic attestations of attributes issued to European Digital Identity Wallets (OJ L, 2024/2977, 4.12.2024, ELI: http://data.europa.eu/eli/reg_impl/2024/2977/oj).
(4) Commission Implementing Regulation (EU) 2024/2979 of 28 November 2024 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards the integrity and core functionalities of European Digital Identity Wallets (OJ L, 2024/2979, 4.12.2024, ELI: http://data.europa.eu/eli/reg_impl/2024/2979/oj).
(5) Commission Implementing Regulation (EU) 2024/2980 of 28 November 2024 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards notifications to the Commission concerning the European Digital Identity Wallet ecosystem (OJ L, 2024/2980, 4.12.2024, ELI: http://data.europa.eu/eli/reg_impl/2024/2980/oj).
(6) Commission Implementing Regulation (EU) 2024/2982 of 28 November 2024 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards protocols and interfaces to be supported by the European Digital Identity Framework (OJ L, 2024/2982, 4.12.2024, ELI: http://data.europa.eu/eli/reg_impl/2024/2982/oj).
(7) Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1, ELI: http://data.europa.eu/eli/reg/2016/679/oj).
(8) Council Regulation (EU) 2025/1208 of 12 June 2025 on strengthening the security of identity cards of Union citizens and of residence documents issued to Union citizens and their family members exercising their right of free movement (OJ L, 2025/1208, 20.6.2025, ELI: http://data.europa.eu/eli/reg/2025/1208/oj).
(9) Council Regulation (EC) No 2252/2004 of 13 December 2004 on standards for security features and biometrics in passports and travel documents issued by Member States (OJ L 385, 29.12.2004, p. 1, ELI: http://data.europa.eu/eli/reg/2004/2252/oj).
(10) Fido Alliance proposed standard, Client to Authenticator Protocol (CTAP), February 26, 2026.
(11) Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications) (OJ L 201, 31.7.2002, p. 37, ELI: http://data.europa.eu/eli/dir/2002/58/oj).
(12) Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39, ELI: http://data.europa.eu/eli/reg/2018/1725/oj).
(13) EDPS Formal comments on the draft Implementing Regulation as regards applicable standards and specifications and correcting Implementing Regulation (EU) 2024/2980 | European Data Protection Supervisor.
ANNEX I
ANNEX
Technical specifications for person identification data referred to in Article 3(3)
1.
Section 1: Set of natural person identification dataTable 1
Mandatory person identification data for the natural person for selective disclosure
|
Data identifier |
Definition |
|
family_name |
Current last name(s) or surname(s) of the user to whom the person identification data relates. |
|
given_name |
Current first name(s), including middle name(s) where applicable, of the user to whom the person identification data relates. |
|
birth_date |
Day, month, and year on which the user to whom the person identification data relates was born. |
|
birth_place |
The country as an alpha-2 country code as specified in ISO 3166-1, or the state, province, district, or local area or the municipality, city, town, or village where the user to whom the person identification data relates was born. |
|
nationality |
One or more alpha-2 country codes as specified in ISO 3166-1, representing the nationality of the user to whom the person identification data relates. |
|
portrait |
Except where the user explicitly opts out, where applicable, the facial image of the user to whom the person identification data relates, compliant with the quality requirements for a full frontal image type as set out in ISO/IEC 39794-5 or, for backward compatibility, ISO/IEC 19794-5, clauses 8.2, 8.3 and 8.4, provided as encoded image data without the headers or blocks as specified in clause 5 of ISO/IEC 19794-5, except for the image data itself (a JPEG) shall apply from 11 August 2028. |
|
— |
Member States may provide that the user has the option to decline the insertion of the portrait to the person identification data. |
|
— |
Member States shall ensure that the selective disclosure applies to each data identifier, including the portrait. |
|
— |
Where the birth date of the natural person is not known, Member States shall choose appropriate values that comply with the specifications set out in sections 4.1 or 4.2 (as appropriate) to this Annex. |
|
— |
Where the nationality of the natural person is unknown, Member States shall use the value 'QU'. |
|
— |
Where the natural person does not hold a nationality, Member States shall use the value 'QS'. |
|
— |
Where the user opts out of the inclusion of the portrait, Member States shall set the value empty. Table 2 Optional person identification data for the natural person for selective disclosure
|
||||||||||||||||||||||||||||
2.
Section 2: Set of legal person identification dataTable 3
Mandatory person identification data for the legal person
|
Data identifier |
|
current legal name |
|
a unique identifier constructed by the sending Member State in accordance with the technical specifications for the purposes of cross-border identification and which is as persistent as possible in time |
|
— |
Where a data identifier is not known for the person or cannot otherwise be issued as part of the person identification dataset, Member States shall instead use an attribute value appropriate to the situation. Table 4 Optional person identification data for the legal person
|
3.
Section 3: Set of metadata about person identification dataTable 5
Metadata about the person identification data
|
Data identifier |
Definition |
Presence |
|
issuing_authority |
Name of the administrative authority that issued the person identification data, or the ISO 3166 alpha-2 country code of the respective Member State if there is no separate authority entitled to issue person identification data. |
mandatory |
|
issuing_country |
alpha-2 country code, as specified in ISO 3166-1, of the country or territory of the provider of the person identification data. |
mandatory |
|
expiry_date |
Date (and if possible time) when the administrative validity period of the person identification data will expire. |
optional |
|
document_number |
A number for the person identification data, assigned by the provider of person identification data. |
optional |
|
issuing_jurisdiction |
Country subdivision code of the jurisdiction that issued the person identification data, as specified in ISO 3166-2:2020, Clause 8. The first part of the code shall be the same as the value for the issuing country. |
optional |
|
issuance_date |
Date, and if possible time, when the administrative validity period of the person identification data started. |
optional |
4.
Section 4: Encoding of natural person identification data attributes|
— |
Natural person identification data shall be issued in accordance with the standards set out in Annex II to Implementing Regulation (EU) 2024/2979, clauses 5 (SD-JWT VC format) and 6 (ISO/IEC-mdoc format) as applicable to electronic attestations of attributes. Clauses 5.2.2, 5.2.4, 5.2.5, EAA-6.1-03, 6.2.2, 6.2.3,6.2.4 and 6.2.5 shall not apply. |
|
— |
The encoding of natural person identification data shall comply with the technical specifications in sections 4.1 and 4.2 of this Annex.
|
5.
Section 5: Trust infrastructure detailsThe list of providers of person identification data made available by the Commission in accordance with Implementing Regulation (EU) 2024/2980 shall enable the authentication of person identification data.
(6) Commission Implementing Regulation (EU) 2025/1569 of 29 July 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards qualified electronic attestations of attributes and electronic attestations of attributes provided by or on behalf of a public sector body responsible for an authentic source (OJ L, 2025/1569, 30.7.2025, ELI: http://data.europa.eu/eli/reg_impl/2025/1569/oj).
(7) J. Schaad, ‘CBOR Object Signing and Encryption (COSE): Header Parameters for Carrying and Referencing X.509 Certificates’ (https://datatracker.ietf.org/doc/rfc9360/).
(8) C. Vigano and H. Birkholz, ‘Concise Data Definition Language (CDDL): A Notational Convention to Express Concise Binary Object Representation (CBOR) and JSON Data Structures’, RFC 8610, June 2019.
(9) M. Jones, A. Nadalin and J. Richter, ‘Concise Binary Object Representation (CBOR) Tags for Date’, RFC 8943, November 2020.
(10) G. Klyne and C. Newman, ‘Date and Time on the Internet: Timestamps’, RFC 3339, July 2002.
(11) C. Bormann and P. Hoffman, ‘Concise Binary Object Representation (CBOR)’, RFC 8949, December 2020.
(12) J. Jones, et al., ‘JSON Web Token (JWT)’, RFC 7519, May 2015.
(13) M. Jones, et al., ‘Proof-of-Possession Key Semantics for JSON Web Tokens (JWTs)’, RFC 7800, April 2016.
(14) M. Jones, et al., ‘JSON Web Signature (JWS)’, RFC 7515, May 2015.
ANNEX II
ANNEX Ia
Cryptographic mechanisms referred to in Article 5a
European Cybersecurity Certification Group, Sub-group on Cryptography: “Agreed Cryptographic Mechanisms” published by the European Union Agency for Cybersecurity (“ENISA”) (1).
(1) https://certification.enisa.europa.eu/publications/eucc-guidelines-cryptography_en.
ANNEX III
ANNEX Ib
Technical specifications for wallet unit attestations referred to in Article 6(2a)
1.
A wallet unit attestation shall comprise one or more wallet instance attestations and one or more key attestations.
2.
The wallet instance attestation and the key attestations shall meet the following requirements:|
(a) |
Format requirements
|
|
(b) |
Transport requirements
|
|
(c) |
Content requirements
|
|
(d) |
Life cycle requirements
|
|
(e) |
Revocation requirements
|
|
(f) |
Requirements regarding signature algorithms
|
(1) RFC 7519: JSON Web Token (JWT), May 2015.
(2) OpenID for Verifiable Credential Issuance v1.0, https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html.
(3) ETSI, ‘Electronic Signatures and Infrastructures (ESI); JAdES digital signatures; Part 3: JAdES levels and baseline profiles’, ETSI TS 119 472-3, V1.1.1, March 2026.
(4) This claim is defined in this CIR as it is not part of the OID4VCI specification.
ANNEX IV
ANNEX II
List of standards referred to in Article 8
The technical specifications set out in clauses 2 to 6 of ETSI TS 119 472-1 V1.2.1 (2026-02) apply. They shall be read with the following adaptations:
|
(1) |
|
|
(2) |
|
|
(3) |
|
|
(4) |
|
|
(5) |
|
|
(6) |
|
ANNEX V
ANNEX III
Technical specifications referred to in Article 10
|
— |
Technical specifications: |
|
— |
Clause 4.2.5 of ETSI TS 119 472-3 V1.1.1 (2026-03). |
ANNEX VI
Annex IV of Implementing Regulation (EU) 2024/2979 is amended as follows:
|
1. |
point 1, is replaced by the following:
|
|
2. |
point 3, is replaced by the following:
|
ANNEX VII
ANNEX VI
EU Digital Identity Wallet Trust Mark in colour
ANNEX VIII
ANNEX VII
EU Digital Identity Wallet Trust Mark in black and white
ANNEX IX
ANNEX VIII
EU Digital Identity Wallet Trust Mark data
|
Data |
Description |
Encoding |
Status |
|
TrustMarkResourceURL |
URL of the EU Digital Identity Wallet Trust Mark graphics and user info resources in the wallet user interface. |
URL |
mandatory |
|
ListOfCertifiedWalletsURL |
URL of the public list of certified wallet solutions in EU as set out in Commission Implementing Regulation (EU) 2025/849 (1). |
URL |
mandatory |
|
ListOfCertifiedWalletsQRCode |
QR Code containing the information of ListOfCertifiedWalletsURL |
ISO-8859-1 Byte mode QR code |
optional |
|
WalletSolutionInfoPageURL |
URL to the information page of the certified wallet solution in the list of certified wallet solution page from the ListOfCertifiedWalletsURL URL appended with a '?' and the WalletSolutionID identifier of the wallet solution. |
URL |
mandatory |
|
WalletSolutionInfoPageQRCode |
QR Code containing the information of WalletSolutionInfoPageURL |
ISO-8859-1 Byte mode QR code |
optional |
|
WalletVerifierToolURL* |
URL pointing to the wallet verification tool /.well-known/openid-credential-issuer endpoint used for retrieval of the attestation provider metadata. |
URL |
optional |
|
(1) Commission Implementing Regulation (EU) 2025/849 of 6 May 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards the submission of information to the Commission and to the Cooperation Group for the list of certified European Digital Identity Wallets (OJ L, 2025/849, 7.5.2025, ELI: http://data.europa.eu/eli/reg_impl/2025/849/oj). |
|||
ANNEX X
Annex II to Implementing Regulation (EU) 2024/2980 is amended as follows:
|
1. |
Annex II, Section 1, point 1(i), is replaced by the following:
|
|
2. |
Annex II, Section 2, point 1(h), is replaced by the following:
|
|
3. |
Annex II, Section 3, point 1(h), is replaced by the following:
|
|
4. |
Annex II, Section 4, point 1(g), is replaced by the following:
|
|
5. |
Annex II, Section 5 is added as follows:
|
ANNEX XI
ANNEX I
Protocols and interfaces referred to in Article 4
The technical specification ETSI TS 119 472-3 V1.1.1 (2026-03) shall apply with the following adaptations:
|
1. |
|
|
2. |
|
|
3. |
4.2.4.2 ARF pre-defined PID/EAA reuse policy
|
|
4. |
Annex A shall not apply. |
ANNEX XII
ANNEX II
Technical specifications referred to in Article 5
The technical specification in Annex C to ISO/IEC 18013-7:2025 shall apply.
The technical specifications in clauses 4.1, 4.2, 5, and 6 of ETSI TS 119 472-2 V1.2.1 (2026-03), shall apply with the following adaptations, including the insertion of a new clause 4.3:
|
(1) |
|
|
(2) |
|
|
(3) |
|
|
(4) |
|
|
(5) |
|
|
(6) |
|
|
(7) |
|
|
(8) |
|
|
(9) |
|
|
(10) |
|
|
(11) |
|
|
(12) |
|
|
(13) |
|
|
(14) |
|
|
(15) |
|
|
(16) |
|
|
(17) |
|
|
(18) |
|
|
(19) |
|
|
(20) |
|
ELI: http://data.europa.eu/eli/reg_impl/2026/1731/oj
ISSN 1977-0677 (electronic edition)