The European Business Wallet: eIDAS for companies, not just citizens

The European Business Wallet: eIDAS for companies, not just citizens

Yivi Team 11 min read
European Business Wallet EUDI Wallet eIDAS digital identity QERDS SMEs open standards

Europe’s digital identity story so far has mostly been told from the citizen’s point of view: the EU Digital Identity (EUDI) Wallet, the ability to log in, prove your age, or share a diploma with a tap. On 19 November 2025, the European Commission proposed a companion piece aimed squarely at businesses. It is called the European Business Wallet (EBW), and it is worth understanding, both because of what it will let companies do and because of how it is built on the same foundations as the citizen wallet.

The proposal, COM(2025) 838 final, 2025/0358 (COD) , rests on the EU’s power to harmonise the single market (Article 114 TFEU), meaning it is meant to replace 27 national approaches with one common set of rules. And it does not invent a new legal universe: it plugs into the same rulebook that already governs the citizen wallet, the eIDAS Regulation (Regulation (EU) No 910/2014), as updated in 2024 by Regulation (EU) 2024/1183, the amendment that created the EUDI Wallet. It has not been adopted yet, it is a Commission proposal working its way through the European Parliament and Council, but the shape of it is already clear, and it is ambitious.

What the European Business Wallet actually is

A European Business Wallet is a digital wallet for economic operators, companies, SMEs, sole traders, and any other entity conducting economic activity, and for public sector bodies. It lets them identify themselves, authenticate, sign or seal documents, and exchange verified data and attestations with other businesses and with government, with full legal effect across EU borders.

Two design choices stand out. First, the proposal is technology-neutral and market-driven: it defines a common minimum layer of functionality and lets private providers build the actual wallets on top of it. Here it has clearly learned from the EUDI Wallet rollout: rather than repeat the heavy burden that citizen-wallet providers shoulder today, the EBW is deliberately set up to be lighter for providers to deliver. Second, entry to the market is notification-based rather than a heavy prior-authorisation regime: a provider notifies a national supervisory body, gets reviewed within roughly 30 days, and, if it already holds qualified trust service provider status, is fast-tracked.

Underpinning all of it is the principle of legal equivalence (Article 4): an action carried out through a European Business Wallet, such as signing a contract or submitting a filing, has the same legal effect as doing it in person, on paper, or through any other compliant means. That single principle is what makes the wallet more than a convenience app. It is what lets a KYC check that today takes 30 to 50 days per corporate client, according to the Commission’s own impact assessment, actually be replaced rather than duplicated alongside the paper process. The regulation puts it in plain terms:

“Where a European Business Wallet owner makes use of any of the core functionalities of a European Business Wallet referred to in Article 5(1), the resulting action shall have the same legal effect as if the action had been lawfully carried out in person, in paper form, or via any other means or processes that would be deemed compliant with applicable legal, administrative, or procedural requirements.”

— Article 4, Principle of equivalence, COM(2025) 838 final

How it complements the citizen wallet

It helps to be precise about the division of labour. The EUDI Wallet is for natural persons: it is built around privacy and data minimisation, letting a citizen prove exactly what is needed and nothing more. The European Business Wallet is the business-to-government and business-to-business counterpart. Companies operate under different expectations: transparency, traceability, auditability, and accountability to regulators, tax authorities, and business partners matter in ways they do not for an individual proving their age at a shop counter. The EBW is designed around that reality, with transaction logs, exportable interaction records, and auditable authorisation trails built in from the start.

The two wallets are not siloed from each other. The proposal explicitly requires wallet-to-wallet and wallet-to-EUDI-wallet interaction, so a Business Wallet can securely receive, validate, and share data with an EUDI Wallet and vice versa, on the shared eIDAS trust infrastructure that already anchors trusted lists, qualified certificates, and qualified trust services across the Union.

There is also a deliberate accommodation for the smallest operators. Sole traders and self-employed people do not need to run a full Business Wallet just to get the benefits. The qualified electronic registered delivery service (QERDS) that sits at the heart of the EBW’s secure communication channel must be offered as a standalone service to EUDI Wallet users, so a self-employed plumber or freelance consultant can authenticate and exchange legally valid documents in a business capacity using the same personal wallet they already carry, without acquiring a separate business identity. The Commission’s own estimate puts the likely annual cost of that standalone access at around 45 euros, low enough that adoption is a realistic option even for the smallest businesses.

What features are expected

The proposal sets out a minimum set of core functionalities (Article 5(1) ) that every provider must support. Stripped of legal phrasing, a Business Wallet is expected to let its owner:

  • Issue, request, store, combine, and selectively disclose electronic attestations of attributes, so a company can share only the specific data a counterparty needs, not an entire document
  • Sign with qualified electronic signatures and seal with qualified electronic seals
  • Time-stamp data with qualified electronic time stamps
  • Issue attestations to other Business Wallets and to EUDI Wallets, including attestations chained or linked to other relevant attestations
  • Send and receive documents through the QERDS, the secure, legally recognised delivery channel
  • Authorise multiple users to operate the wallet on the owner’s behalf, and revoke that authorisation at any time, which matters enormously for companies where several employees need to act under a mandate
  • Authorise which relying parties may request specific attestations, and revoke that too
  • Export all wallet data, identification records, attestations, communication logs, on request or when a provider relationship ends
  • Access a full log of every transaction, and a dashboard for the QERDS communications specifically

On top of that, a set of technical features (Article 6) is meant to make the wallet actually usable at the scale businesses operate at, rather than one document at a time. That includes automated machine-to-machine interaction so systems can exchange attestations without a person clicking through each one, secure remote onboarding through an authorised representative, and a unique digital address for every owner, tied into a Commission-run European Digital Directory that exposes both a machine-readable API and a web portal so businesses and public bodies can find and contact each other. Every wallet owner also gets a single unique identifier, and wherever possible that means reusing the European Unique Identifier (EUID) that companies already hold under EU company law, rather than inventing a new number that duplicates BRIS and BORIS.

One requirement worth calling out specifically: where multiple users are authorised to act on a company’s wallet, the system must automatically detect and prevent over-delegation and expired authorisations in real time, and the whole authorisation structure has to be verifiable, auditable, and interoperable across Member States. Delegated authority in a business context is exactly where things go wrong quietly, so building real-time detection into the technical baseline is a meaningful design choice. The requirement is spelled out in the technical features article:

Providers of European Business Wallets shall […] ensure that, for the purposes of the functionality referred to in Article 5(1), point (j): mappings between roles and attributes are verifiable, auditable, revocable and traceable to their legitimate issuers; conflicts of roles, over-delegation, or expired authorisations are automatically detected and prevented in real time; all authorisation logic is interoperable across Member States.

— Article 6(2), point (b), COM(2025) 838 final

Identity is where the Business Wallet leans hardest on infrastructure that already exists. Rather than mint a fresh business identity, the proposal ties every wallet owner back to the official registers that already hold company data, the KVK Handelsregister in the Netherlands.

Every owner carries owner identification data (Article 8 ), issued as an electronic attestation of attributes by a qualified trust service provider, by a public sector body responsible for an authentic source, or by the Commission for EU institutions. That data must contain at least the operator’s official name “as recorded in the relevant register or official record” and a unique identifier. Member States have to tell the Commission which registers count as the authentic source behind it:

Member States shall notify to the Commission the relevant authentic sources for the verification of the required attributes for the issuance of the European Business Wallet owner identification data.

— Article 8(2), COM(2025) 838 final

Those authentic sources are, in the words of the recitals, “business registers and other registers”, and the regulation is explicit that it should not change how those registers work but should “build upon and complement the existing infrastructure”. A business register can even issue the attestation directly. For the Netherlands that authentic source is the KVK: it holds the official company name and the attributes behind the identification data, and the Netherlands would notify the KVK Handelsregister to the Commission as such.

The unique identifier is not new either (Article 9 ). Where a company already has a European Unique Identifier (EUID), the number assigned under EU company law (Directive (EU) 2017/1132) and published through BRIS, that EUID becomes the wallet’s identifier. For a Dutch company the EUID is built from its KVK registration, so the wallet reuses the KVK number rather than inventing another. Only where no EUID exists do Member States fall back on another national register and its registration number.

The upshot is that a Dutch company does not get a separate “wallet identity”. It is identified as the same legal entity the KVK already knows, and that is exactly what lets a signature or filing made through the wallet carry the same weight as its paper equivalent.

Public sector acceptance, and the timeline

Adoption for businesses is voluntary, the proposal is explicit that no obligation is placed on economic operators. The obligation sits with public sector bodies: within an expected 24 months of the regulation entering into force, they must enable economic operators to use the wallet’s core functionalities to identify and authenticate themselves, sign or seal, submit documents, and send or receive notifications in administrative and reporting procedures. Where documents or notifications are involved, the public body itself must hold a Business Wallet and use the QERDS. A transitional derogation, expected to run until 36 months after entry into force, lets public bodies bridge the gap with other eIDAS-compliant QERDS setups before fully adopting Business Wallets.

None of these dates are final yet; the regulation still needs to pass through the ordinary legislative procedure, so treat the 24 and 36 month figures as the Commission’s proposed timeline, not settled law. What is already reasonably clear is the direction: a harmonised, EU-wide floor for how companies and governments transact digitally, replacing today’s patchwork of national portals, paper filings, and bilateral verification processes that the Commission’s own figures put at roughly 1.8% of turnover in compliance costs for firms overall, and 2.5% for smaller ones.

Where Yivi fits

Yivi is a citizen-facing wallet, not a Business Wallet, but it is built on exactly the open standards this ecosystem is designed around: OpenID4VP, OpenID4VCI, and SD-JWT VC. Those are the same protocols and credential format that the EUDI Wallet relies on, and that the European Business Wallet is required to interoperate with through wallet-to-wallet and wallet-to-EUDI-wallet interaction. A future where a sole trader authenticates with their personal Yivi wallet against a business counterparty, or where a Business Wallet requests an attestation that a citizen wallet like Yivi can present, is exactly the kind of interoperability this framework is designed to make ordinary rather than exceptional.

We are not just watching this from the sidelines: we are already building a prototype of a Yivi Business Wallet, so we can put these ideas to the test rather than just write about them.

A few highlights from the prototype:

business.yivi.app
Passwordless login screen for the Yivi Business Wallet with a QR code
Passwordless login — members sign in with their EU Digital Identity wallet by scanning a QR code, disclosing only their e-mail address. No passwords, no shared secrets.
business.yivi.app/register
Onboarding step asking the user to prove their identity with their EU Digital Identity wallet
Verified onboarding — a new organisation registers against the KVK and the representative proves their identity with their EU Digital Identity wallet, so every wallet is tied to a real, register-verified entity.
business.yivi.app/invite
Invitation screen inviting a colleague to join the organisation in the Yivi Business Wallet
Invite members, assign roles — colleagues receive an invitation to join the organisation for a specific role and accept with their EU Digital Identity wallet, so every member is a verified person and authority stays explicit and revocable.
business.yivi.app/attestations
Attestation templates in the Yivi Business Wallet: approved supplier, employee and corporate e-mail
Reusable attestation templates — define credentials such as approved supplier, employee, or corporate e-mail once, then issue them to members and external partners in a few clicks.
business.yivi.app/audit
Audit log in the Yivi Business Wallet listing when, who and what for every action
Complete audit trail — every issuance, disclosure, signature and configuration change is recorded with the actor, action and subject, then filtered and exported for the accountability regulators and partners expect.

Learn more or get started