Getting Starting EUDI Preparation Nobody Warned You About

Blog Owner

Omer Shafiq

CEO at Hovi
Big Thumb

Businesses preparing for EUDI Wallets tend to plan for an integration. Endpoints, protocols, a credential format or two.

Then they meet the paperwork.

Verifying anything from an EUDI Wallet means becoming a wallet-relying party; and that is only possible by registering with a national registrar.This enables you to prove things about your company to that registrar's satisfaction, and collecting certificates before a wallet will speak to you. The rules for this sit in Commission Implementing Regulation (EU) 2025/848, adopted on 6 May 2025 and applying from 24 December 2026.

If you are new to the framework itself, start with our beginner's guide to EU Digital Identity Wallets and come back to this.

Here is the part that catches people out. The regulation harmonises what you register and what comes out the other end. It leaves how you prove it, how long it takes, and in one important case whether you get it at all, to your Member State.

What is the same everywhere

Start with the good news, because it is real.

The information set is fixed. Annex I lists what every register must hold: your legal name, an identifier such as a VAT number or European Unique Identifier, your physical address, contact details, a description of your services, and for each intended use, the data you will request and why.

The entitlement vocabulary is fixed. You register under defined values such as Service_Provider, QEAA_Provider or PID_Provider. There are ten, and they mean the same thing in every Member State.

The register interfaces are fixed. Each register must expose a REST API returning signed JSON, published as OpenAPI 3, queryable by anyone without prior authentication.

Access certificates are fixed. Their policies must be syntactically and semantically harmonised across the Union and meet the normalised certificate policy requirements in ETSI EN 319 411-1 v1.4.1. Revocation status must be published within 24 hours. Registrars keep your records for ten years.

So the shape of the thing does not vary. Build once against these and the output travels.

What your Member State decides

Now the part that does vary, and it is more than administrative trim.

The registration policy itself. Each Member State lays down and publishes its own, and may reuse existing sectoral or national policies rather than writing a new one. That policy sets your actual experience of registering.

What documents you must supply. The policy specifies the supporting documentation for your identity, your business registration and your entitlements. Two companies in two countries doing the identical thing can face different evidence burdens.

How long it takes. The regulation says registrars must process applications without undue delay and respond within the timeframe defined in the applicable registration policy. It sets no number of its own. Your service level comes from your national policy, not from Brussels.

Which sources get checked. Registrars verify against authentic sources and official electronic records in their own Member State, and only those they can access under national law. Where a country has good machine-readable registries, this is quick. Where it does not, it is not.

How you prove a representative can sign. Power of attorney is handled according to the laws and procedures of the Member State where the register sits.

Your route of appeal. The redress mechanism if you are rejected comes from national law.

How many registers exist. Member States must run at least one and designate at least one registrar. Some may run several. Registrars are also required to check that you are not already registered in another national register, so the design pushes against duplicate registrations.

Extra sub-entitlements. For non-qualified attestation issuers, Member States may add sub-entitlements specifying which attestations you are allowed to issue. That is a national layer on top of the common vocabulary.

The one that will surprise you

Compare two articles of the same regulation.

Article 7 says Member States shall authorise at least one certificate authority to issue access certificates. Mandatory, everywhere.

Article 8 says Member States may authorise at least one certificate authority to issue registration certificates. Optional.

The recitals confirm it. Providers of registration certificates are described as existing "where available", and Member States "may require" their issuance.

This matters because the registration certificate is the artefact that carries your intended use to the user, along with a general access policy telling them you may only request what you registered. It is also what lets a wallet warn a user when a relying party asks for more than it declared.

Where a Member State has not authorised a provider, that mechanism does not operate the same way. Two identical services, registered in two countries, can present differently to the same customer.

The obligation not to over-request holds either way. It comes from Article 5b of the amended eIDAS Regulation, and asking for more than you registered is grounds for suspending or cancelling your registration. What varies is whether a certificate is standing there enforcing it in front of the user.

What to do about it

Decide first whether you register directly or work through an intermediary. This is the decision that sets how much national variance you absorb yourself. Register directly and every market means another policy and another registrar. An intermediary files on your behalf and carries those differences for you. It is a registered relying party in its own right, and it may not store the data passing through. Hovi can act as your intermediary, and we covered the trade-offs either way in EUDI intermediaries: what they are and why they matter.

Read your national registration policy first, not the regulation. The regulation tells you what is collected. The policy tells you what you have to produce and how long it will take. When your Member State publishes one, that is your real specification.

Do not budget a single lead time across markets. There is no EU-wide clock. If your plan assumes every registration lands in the same window, it is assuming something the regulation does not say.

Check whether registration certificates exist where you register. It changes what your customer sees at the moment of sharing, and it is worth knowing before you design that screen.

How Hovi helps

Hovi works as an intermediary across the EU, and already operates inside current active EUDI ecosystems..  

In the France Identité EUDI ecosystem and the German EUDI Wallet Deutschland ecosystem, we can help you integrate and verify against these and other EUDI wallets. You can build user onboarding and KYC identity verification flows using Person Identification Data and age verification credentials, and issue Electronic Attestation of Attributes credentials into wallet units across the full credential lifecycle.

See our live presentation from Paris at the France Identité event EUDIW Unfold #3, running verification demos with the France Identité digital wallet, built on the Hovi platform. Watch the full demo.

We have tested against ETSI TS 119 472-1 at the ETSI EAA Plugtests, covering SD-JWT VC and ISO/IEC 18013-5 across several government and private wallet providers.

Hovi gives you the orchestration layer to integrate with EUDI schemes and build your use cases at scale and connect with all 27 member state EUDI Wallets Book a demo with us today.