eIDAS 2.0 sets one fixed penalty figure, and it applies to trust service providers only. Under Article 16(2) of the amended Regulation, Member States must ensure that infringements by qualified and non-qualified trust service providers are subject to administrative fines with a maximum of at least EUR 5 000 000 where the provider is a natural person, and, where it is a legal person, EUR 5 000 000 or 1% of the total worldwide annual turnover of the undertaking it belongs to in the preceding financial year, whichever is higher. For everyone else the Regulation reaches, including the private relying parties that must accept the European Digital Identity Wallet from 24 December 2027, Article 16(1) leaves the penalties to each Member State, with the standing requirement that they be effective, proportionate and dissuasive.
Two things follow. The EUR 5 million figure is a floor under national maxima, not a cap. And for a trust service provider the fine is rarely the sanction that matters, because Article 20 lets the supervisory body withdraw qualified status, which ends the business the fine was measuring.
| Who | Financial exposure | The sanction that hurts more | Where |
|---|---|---|---|
| Qualified trust service provider | Maximum of at least EUR 5M or 1% of worldwide turnover, higher wins | Withdrawal of qualified status for the provider or the affected service | Articles 16(2), 20(3) |
| Non-qualified trust service provider | The same floor | Ex post supervision and orders to remedy; a national fine on top | Articles 16(2), 19a, 46b |
| Wallet provider | National rules, no EU floor | An order to suspend or cease providing the wallet | Articles 16(1), 46a(5) |
| Relying party | National rules, no EU floor | Suspension or cancellation of registration for illegal or fraudulent use | Articles 16(1), 46a(4)(f) |
What are the fines under eIDAS 2.0?
Article 16 has three paragraphs. Paragraph 1 keeps the wording of the original 2014 Regulation: Member States lay down the rules on penalties for infringements, and those penalties must be effective, proportionate and dissuasive. It is now expressed to be without prejudice to Article 31 of the NIS2 Directive, which matters for reasons covered below. Paragraph 2 is new, and it is the only place the Regulation fixes a number. Paragraph 3 recognises that in some Member States a fine is initiated by the supervisory body and imposed by a court, and requires that route to be as effective as a fine imposed directly.
Recital 44 explains the design. A minimum for the maximum administrative fine is set for both qualified and non-qualified trust service providers so that enforcement is effective across the Union, and Member States are told to weigh the size of the entity, its business model and the severity of the infringement when setting penalties. The phrase to hold onto is a maximum of at least. Each Member State's ceiling must be at least EUR 5 million or 1%, and may be higher.
Recital 45 names one category of infringement specifically: practices that lead to confusion between non-qualified and qualified trust services, or abusive use of the EU trust mark by a non-qualified provider. That is the conduct the drafters had in mind, but Article 16(2) is not limited to it. It covers any infringement of the Regulation by a trust service provider.
Why is losing qualified status the bigger risk?
Because a qualified trust service provider's product is its status, and Article 20 puts that status on a short leash. Under Article 20(1), a qualified provider must be audited at its own expense at least every 24 months by a conformity assessment body, and must send the report to the supervisory body within three working days of receiving it. Under Article 20(1a) it must tell the supervisory body a month before any planned audit and let it attend as an observer. Under Article 20(2) the supervisory body may audit, or order a conformity assessment, at any time and at the provider's expense.
Article 20(3) is the sanction. Where a qualified provider fails any requirement, the supervisory body requires a remedy within a set time limit. If the provider does not remedy it, the supervisory body, where justified by the extent, duration and consequences of the failure, withdraws the qualified status of the provider or of the affected service. Article 20(3a) adds a second trigger: where the NIS2 competent authority informs the supervisory body that the provider is failing the security requirements in Article 21 of that Directive, the same withdrawal follows. The supervisory body then informs the body that keeps the national trusted list under Article 22(3), which is where customers and browsers check whether a service is qualified.
No fine is needed for any of that. A provider can lose its status without paying a cent, and it can pay a fine and keep its status. They are separate tracks, and the second is the one that removes the revenue.
What do relying parties risk?
No EU-level fine, but three real exposures. The first is the national penalty regime under Article 16(1), which every Member State must have and which covers infringements of the relying party duties in Article 5b: registering in the Member State of establishment before relying on the wallet, declaring the data to be requested, not requesting anything beyond what was declared, notifying changes without delay, identifying yourself to the user, validating the attestations you receive, and not refusing pseudonyms where identification is not legally required. Article 5b(10) makes intermediaries acting for relying parties relying parties themselves.
The second is losing access to the wallet. Article 46a(4)(f) gives the wallet supervisory body the power to suspend or cancel a relying party's registration in the case of illegal or fraudulent use of the European Digital Identity Wallet. For a relying party that is under an Article 5f duty to accept the wallet, a cancelled registration is a compliance problem in both directions.
The third is the one most guides miss. Requesting attributes beyond what was declared is, in substance, a data minimisation failure, and the GDPR supervisory authorities are expressly in the loop: Article 46a(4)(g) and Article 46b(4)(f) both require the eIDAS supervisory bodies to inform them without undue delay where personal data rules appear to have been infringed. For a large relying party, the GDPR ceiling of 4% of worldwide turnover is the number that describes the over-collection risk, not anything in eIDAS.
Who is under the acceptance duty in the first place, and the micro and small enterprise carve-out in Article 5f(2), are worked through in our guide to who must comply with eIDAS 2.0.

How does NIS2 change the picture for trust service providers?
Substantially, and Article 16(1) says so by carving out Article 31 of the NIS2 Directive. Trust service providers are within NIS2 regardless of size under its Article 2(2)(a)(ii), and qualified trust service providers are essential entities regardless of size under its Article 3(1)(b). That brings a second penalty regime with higher floors: under NIS2 Article 34(4), essential entities that breach the risk management or reporting duties face fines with a maximum of at least EUR 10 000 000 or 2% of total worldwide annual turnover, and under Article 34(5) important entities face at least EUR 7 000 000 or 1.4%.
The two regimes are wired together rather than run in parallel. The Article 20(1) audit must confirm compliance with Article 21 of NIS2 as well as with eIDAS. Article 20(3a) lets the NIS2 authority's finding trigger withdrawal of qualified status. And Article 19a(1)(a) requires non-qualified providers to manage risk notwithstanding Article 21 of NIS2, with a 24 hour notification of significant security breaches to the supervisory body under Article 19a(1)(b). For a security failure at a qualified provider, then, the operative fine ceiling is the NIS2 one, and the eIDAS floor is the smaller of the two numbers in play. The NIS2 side is set out in our guide to NIS2 fines and penalties.
Who imposes eIDAS 2.0 penalties?
National supervisory bodies, of which there are now two kinds. Article 46b requires each Member State to designate a supervisory body for trust services, with ex ante and ex post supervision of qualified providers, ex post action against non-qualified providers, the power to grant and withdraw qualified status, and the duty to analyse the conformity assessment reports. Article 46a requires one or more supervisory bodies for the wallet framework, supervising wallet providers and holding the registration powers over relying parties. Under Article 46d those bodies can seek mutual assistance across borders where a provider is established in one Member State and operates in another.
The fine itself is imposed under national law. Article 16(3) recognises that in some Member States the supervisory body initiates and a court imposes, and the amount within the national ceiling is a national decision. Nothing in eIDAS 2.0 gives the Commission or ENISA a fining power over trust service providers.
What the other results get wrong
The most common error is reporting EUR 5 million or 1% as the eIDAS 2.0 fine, full stop, as though it applied to every organisation the Regulation touches. Article 16(2) names trust service providers and nobody else. A bank that must accept the wallet from December 2027 is not in that paragraph.
The second is writing whichever is lower. Article 16(2)(b) says whichever is higher, and for any undertaking with worldwide turnover above EUR 500 million the percentage is the binding number. The third is treating the figure as a cap. It is a maximum of at least, which is a floor under each Member State's ceiling, and a Member State that already fines trust service providers more heavily does not have to reduce anything.
The fourth is ignoring NIS2. Guides that compare eIDAS 2.0 fines with GDPR and stop there miss that a qualified trust service provider is an essential entity under NIS2 and carries that regime's 2% ceiling for the same security failures. The fifth is describing relying parties as fine-free. They face national penalties under Article 16(1), registration sanctions under Article 46a, and the GDPR for anything they collect beyond what they declared.

Working out your own exposure
Fill this in. The aim is to find out which track you are on, not to produce a number.
| Question | Your answer | What it decides |
|---|---|---|
| Do you provide a trust service, qualified or not? | If yes, Article 16(2) applies and the floor is EUR 5M or 1%. If no, your exposure is national law. | |
| What is your total worldwide annual turnover? | Above EUR 500M the 1% limb binds rather than the euro figure. | |
| When was your last Article 20 conformity assessment, and when is the next? | Every 24 months at your own expense, with the report to the supervisory body inside three working days. | |
| Are you an essential entity under NIS2? | Qualified providers are, regardless of size, and the NIS2 ceiling of 2% or EUR 10M then applies to security failures. | |
| Which attributes does each of your wallet flows request? | Anything beyond the Article 5b(2)(c) declaration is a relying party breach and a GDPR matter. | |
| Could you notify a significant breach inside 24 hours? | Article 19a(1)(b) for non-qualified providers; the trust service supervisory body is the recipient. |
If most rows are blank, the useful next step is a baseline. What meeting the duties costs is in our guide to eIDAS 2.0 compliance cost, the dates that frame the work are in our guide to the eIDAS 2.0 deadline of 24 December 2027, the framework overview sits on our eIDAS 2.0 page, and a free compliance check gives you a starting position.
Frequently asked questions
What is the maximum fine under eIDAS 2.0?
There is no EU-wide maximum. Article 16(2) requires each Member State's maximum for trust service providers to be at least EUR 5 000 000, or for a legal person at least EUR 5 000 000 or 1% of worldwide annual turnover, whichever is higher. A Member State may set its ceiling above that.
Can a relying party be fined under eIDAS 2.0?
Under national law, yes. Article 16(1) requires every Member State to lay down effective, proportionate and dissuasive penalties for infringements of the Regulation, and the relying party duties in Article 5b are infringements like any other. The EUR 5 million floor in Article 16(2) does not apply to relying parties.
Does the fine apply to non-qualified trust service providers?
Yes. Article 16(2) names qualified and non-qualified trust service providers together, and recital 44 confirms the floor was set for both.
Since when has Article 16(2) applied?
Regulation (EU) 2024/1183 was published in the Official Journal on 30 April 2024 and entered into force on 20 May 2024. The floor has been in the Regulation since then; the national rules that give it effect are each Member State's to adopt.
Is turnover measured EU-wide or worldwide?
Worldwide, and at the level of the undertaking the trust service provider belongs to, in the financial year preceding the infringement. A small EU subsidiary of a large group is measured against the group.
Can we lose qualified status without a fine?
Yes. Article 20(3) withdrawal follows a failure to remedy within the supervisory body's time limit, and it does not depend on a fine having been imposed. The two run on separate tracks.
Primary sources
Penalty floors, the supervisory powers and the relying party duties are taken from Articles 5b, 5f, 16, 19a, 20, 46a, 46b and 46d of Regulation (EU) No 910/2014 as amended by Regulation (EU) 2024/1183, and from recitals 44 and 45 of the amending Regulation. NIS2 scope and fine ceilings are from Articles 2, 3 and 34 of Directive (EU) 2022/2555. Comparative ceilings for the GDPR and the Cyber Resilience Act come from those instruments' own penalty articles. Confirm the current text before relying on a figure.





