There is no published price for eIDAS 2.0 compliance, but there is one official estimate, and almost nobody quotes it. The European Commission's impact assessment for the proposal that became Regulation (EU) 2024/1183 put an online service provider's first year at EUR 60,000 to EUR 70,000 per provider, initial qualification as a trust service provider at an average of EUR 545,000, and EUR 255,000 a year after that to keep the qualified status. Those are 2021 figures for a proposal rather than prices for the adopted text, and the document itself calls its totals a minimum. They are still the only numbers with the Commission's name on them.
What makes them worth reading is not their precision. It is their shape. A relying party's cost is front loaded into a single integration year. A trust service provider's cost is dominated by a recurring audit that never stops. Those are two different budget problems, and which one you have is decided entirely by the role you play, not by your size or your sector.
| Fact | Detail |
|---|---|
| Governing law | Regulation (EU) 2024/1183, amending Regulation (EU) No 910/2014 (the eIDAS Regulation). |
| Where the figures come from | SWD(2021) 124, the Commission impact assessment of 3 June 2021, Policy Option 3, the preferred option. |
| Online service provider, year one | EUR 60,000 to EUR 70,000 per provider. |
| Trust service provider, qualification | An average of EUR 545,000 initially, then EUR 255,000 a year on a recurrent basis. |
| First wallet build | About EUR 10.5 million for first time development and rollout across the first three years. |
| Cost to the person using the wallet | Nothing. Issuance, use and revocation are free of charge to all natural persons under Article 5a(13). |
| Total quantifiable cost, EU wide | EUR 3.2 billion or more. The document is explicit that this is a minimum. |
What does eIDAS 2.0 compliance cost?
It depends on which of three roles you are in, and the gap between them is larger than any other variable. A private relying party that has to accept the EU Digital Identity Wallet is buying an integration. A qualified trust service provider is buying a permanent audit relationship. A Member State or wallet provider is building a national product. Nothing about turnover, headcount or sector moves the number as much as which of those three sentences describes you.
If you are a relying party, and most organisations reading this are, the honest planning position is one integration year in the tens of thousands of euros, followed by ordinary maintenance. That is not a small number, but it is not a programme cost either, and it is much lower than the figures quoted for regimes like NIS2 or DORA, which change how you run the whole organisation rather than one authentication flow.
What did the Commission actually estimate?
SWD(2021) 124 accompanied the proposal for a European Digital Identity framework and assessed several policy options. Option 3, the one built around a wallet, was chosen as preferred. Its cost table breaks down like this.
| Who pays | Estimate | What the document says about it |
|---|---|---|
| Public authorities | EUR 849 million to EUR 910 million | Around EUR 170 million of that is expected to be a yearly recurrent cost across all Member States. |
| Online service providers | EUR 60,000 to EUR 70,000 | Expected for the first year, per provider. The equivalent row under Option 1 reads EUR 42,500 per each provider. |
| Trust service providers | EUR 2.3 billion in aggregate | Individual qualification was estimated at an average of EUR 545,000, then EUR 255,000 a year. |
| Wallet providers | About EUR 10.5 million, plus EUR 80,000 to EUR 100,000 per provider | The EUR 10.5 million covers first time development and rollout over three years. The per provider figure is certification under future Cybersecurity Act schemes. |
| Conformity assessment bodies | Up to EUR 678,000 | Described as the maximum familiarisation cost. |
| Total quantifiable | EUR 3.2 billion or more | A minimum, because the document states that some cost items cannot be quantified. |
Three cautions before anyone puts a line of that table into a board paper.
It prices a proposal, not the adopted Regulation. Between June 2021 and the text that entered into force on 20 May 2024, the framework gained obligations that the impact assessment did not cost, including the relying party registration duty in Article 5b. Treat the numbers as an anchor for the order of magnitude, not as a quote for what you now have to do.
It is an EU wide aggregate. The EUR 2.3 billion figure for trust service providers describes a whole market. The per provider figures inside it, EUR 545,000 and EUR 255,000, are the ones that map onto a single organisation.
It is explicitly a floor. The document repeats, for every option, that the total establishes the minimum cost because some items could not be quantified or could only be defined per stakeholder. An estimate that says so about itself is more trustworthy than one that does not, and it is also a warning.
Where does a relying party's money actually go?
Five lines, and only one of them is the integration everybody thinks of first.
1. Confirming whether Article 5f reaches you
The acceptance duty applies to private relying parties that are required, by Union or national law or by contractual obligation, to use strong user authentication for online identification. Microenterprises and small enterprises are carved out. This is a legal question, it is cheap to answer, and getting it wrong in either direction is expensive: our guide to who must comply with eIDAS 2.0 works through the decision tree.
2. Registering as a relying party
Article 5b requires a relying party that intends to rely on wallets to register in the Member State where it is established, declaring who it is and what data it intends to request. The Regulation requires that process to be cost effective and proportionate to risk, which is unusual and useful: the registration itself is designed not to be the expensive part.
3. Building wallet presentation into the authentication flow
This is the line the EUR 60,000 to EUR 70,000 estimate is mostly describing. It is engineering work: accepting a presentation, verifying it, and handling the cases where verification fails.
4. Cutting the attributes you ask for
Article 5b bars a relying party from requesting data other than that indicated in its registration. In practice that means auditing what each flow asks for today and removing what it does not need. This is a product change rather than a legal one, and on a mature signup flow it is frequently the longest of the five lines.
5. Keeping a fallback and supporting it
The duty bites only where a user voluntarily chooses to present a wallet. Your existing identification path does not go away, so you end up supporting two, and that is a permanent operating cost rather than a project cost.
Why is a trust service provider's number so much larger?
Because the cost is structural rather than one off. The Commission's evaluation of the original Regulation found that qualified trust service providers spent an average of EUR 800,000 to obtain and maintain qualified status, and the impact assessment separates that into roughly EUR 545,000 for initial qualification and EUR 255,000 a year to keep it.
The recurring half has a specific cause. Article 20(1) requires qualified trust service providers to be audited by a conformity assessment body at least every 24 months, and to submit the resulting conformity assessment report to their supervisory body within three working days of receiving it. That is an audit relationship with a fixed cadence, not a certification you obtain and then forget. Any budget that treats qualification as a project with an end date is wrong by about EUR 255,000 a year.
What the other results get wrong
Three errors run through the pages that currently rank for this query.
They answer a cost question with a checklist. Page one for eIDAS 2.0 compliance cost is almost entirely qualitative: integrate the credential libraries, plan early, late adoption costs more. All true, none of it a number. A published Commission estimate exists and is simply not being cited.
They imply the wallet is a cost to users. It is not. Article 5a(13) provides that the issuance, use and revocation of European Digital Identity Wallets are free of charge to all natural persons. Every euro in this article sits on the accepting side of the transaction, not the presenting side.
They treat eIDAS 2.0 as a single obligation with a single price. It is at least three roles with three different cost curves, and mixing them is how you get published figures that differ by four orders of magnitude for what looks like the same question.
What does the Commission expect you to get back?
The same document quantifies the benefit side, and for online service providers it is larger than the cost side by a wide margin. Under the preferred option it estimates yearly recurrent savings of between EUR 3.5 billion and EUR 6.7 billion for online service providers across four sectors, split between cheaper identification and onboarding procedures and reduced losses from online fraud.
| Sector | Identification and onboarding savings a year | Fraud and cybercrime savings a year |
|---|---|---|
| Financial services | EUR 0.68bn to EUR 1.36bn | EUR 0.85bn to EUR 1.4bn |
| eHealth | EUR 1.26bn to EUR 2.51bn | EUR 0.3bn to EUR 0.6bn |
| eCommerce | EUR 0.24bn to EUR 0.47bn | EUR 0.13bn to EUR 0.26bn |
| Aviation | EUR 30m to EUR 60m | EUR 3.5m to EUR 7m |
Add the columns and you land back on the EUR 3.5 billion to EUR 6.7 billion headline, which is a useful check that the aggregate and the detail come from the same arithmetic. What it is not is a forecast for your organisation. These are sectoral totals across the EU, and the savings accrue to firms whose identification and know your customer procedures are expensive today. If yours are already cheap, the benefit line is thinner and the cost line is unchanged.
Size your own eIDAS 2.0 budget
Fill this in. Any row you cannot complete is a scoping question, and scoping questions are cheap to answer now and expensive to answer in 2027.
| Question | Your answer | What it changes |
|---|---|---|
| How many of your online services are required to use strong user authentication, by law or by contract? | This is the Article 5f trigger. Zero means the acceptance duty does not reach you. | |
| Are you a microenterprise or a small enterprise? | If so, the acceptance duty does not apply. Count group and partner structure, not just your own entity. | |
| In which Member State are you established? | Article 5b registration happens there, once, rather than in every country you serve. | |
| How many attributes does each identification flow request today? | Every attribute you cannot justify is rework. This is usually the longest engineering line. | |
| Do you also issue trust services, or plan to? | That moves you from a one off integration to roughly EUR 255,000 a year of recurrent audit cost. | |
| What does your existing identification path cost to run? | It does not go away. Wallet acceptance is a second path, not a replacement. |
If you want a baseline before you commit a number, a free compliance check will tell you which of those rows you are going to struggle with. The dates that constrain the whole plan are in our guide to the eIDAS 2.0 deadline of 24 December 2027, and the framework overview sits on our eIDAS 2.0 page.
Frequently asked questions
Is there an official price for eIDAS 2.0 compliance?
No, but there is an official estimate. SWD(2021) 124 put an online service provider's first year at EUR 60,000 to EUR 70,000 per provider under the preferred option. It estimates a 2021 proposal rather than the Regulation as adopted, and it describes its own totals as a minimum.
Does the wallet cost our users anything?
No. Article 5a(13) makes issuance, use and revocation free of charge to all natural persons. There is no user fee to design around.
Is relying party registration expensive?
It is not designed to be. Article 5b requires the registration process to be cost effective and proportionate to risk, and registration happens in the Member State where you are established rather than in each Member State where you operate.
Is this a one off cost or a recurring one?
For a relying party, mostly one off, plus the permanent cost of running two identification paths instead of one. For a qualified trust service provider it is structurally recurring, because Article 20(1) requires a conformity assessment audit at least every 24 months.
Can we avoid the cost by not accepting the wallet?
Only if Article 5f does not reach you, which means no law and no contract requires you to use strong user authentication for online identification, or you are a microenterprise or small enterprise. Voluntary acceptance is also possible, and it brings the relying party obligations with it.
How does this compare with the Cyber Resilience Act?
Different shape entirely. The CRA prices per product rather than per organisation, and its recurring cost is a support period rather than an audit cycle. We work through the arithmetic in Cyber Resilience Act compliance cost.
Primary sources
Cost and benefit figures are taken from SWD(2021) 124 final, the Commission impact assessment of 3 June 2021 accompanying COM(2021) 281, specifically the Policy Option 3 cost table and the REFIT cost savings table. Obligations and article references are from Regulation (EU) 2024/1183 amending Regulation (EU) No 910/2014, and timing context from the European Commission's European Digital Identity Regulation pages. Estimates made for legislative purposes describe a whole economy, not your organisation. Confirm the current text before relying on a figure.





