Skip to content
Tamga Network

Europe

eIDAS 2.0 and the ARF: what they mean for the Turkic world

What the EU built with eIDAS 2.0 and its reference framework, when it applies, why alignment matters for states outside the EU, and where its limits are.

Tamga Network 11 min read

eIDAS 2.0 is the EU law that makes every member state offer a digital identity wallet by the end of 2026. The Architecture and Reference Framework (ARF) is the technical blueprint behind it. Together they define a complete trust system: the wallet, the identity data issued by the state, attestations such as diplomas, signed trust lists, registration of every service that asks for data, and certification. For the Turkic world the law itself does not apply, but its standards are becoming the shared language that EU banks, universities and employers will read. A state outside the EU can adopt that language now. Recognition by the EU is a separate step, and it is taken by governments.

What did the EU build with eIDAS 2.0?

Regulation (EU) 2024/1183, called eIDAS 2.0, amends the 2014 eIDAS regulation (EUR-Lex). The 2014 text dealt mainly with national eID schemes and electronic signatures. The 2024 text adds a full ecosystem around a wallet on the phone. Six building blocks carry it:

Six building blocks of eIDAS 2.0: wallet, PID, attestations, trust lists, relying party registration, certification
Building blockWhat it isLegal basis
European Digital Identity WalletThe app that holds a person's identity data and credentials and shares them under the person's controlArt. 5a
PID (person identification data)The core identity data, issued by or for the state at a high level of assuranceArt. 5a, Implementing Regulation 2024/2977
Electronic attestations of attributesEvery other credential: diplomas, licences, memberships. A qualified attestation (QEAA) comes from a qualified trust service provider; a public-sector attestation (PuB-EAA) comes from a body responsible for an authentic sourceArt. 45b–45h, Implementing Regulation 2025/1569
Trust listsSigned lists that say which providers are trusted, for whatArt. 22; ETSI TS 119 612 and ETSI TS 119 602
Relying party registrationEvery service that wants to ask a wallet for data registers in a member state and declares what it will ask for and whyArt. 5b, Implementing Regulation 2025/848
CertificationWallets are certified by conformity assessment bodies before they are offeredArt. 5c, Implementing Regulation 2024/2981

Two points are easy to miss. First, the trust lists are what make the system work across borders. A verifier in one country does not need a private arrangement with every university in another; it reads one signed list (how a signed trust list works). Second, relying party registration protects the person as much as the signature does: the wallet can compare what a service asks for with what it registered to ask for, and warn when the request goes further.

What is the ARF, and how does it relate to the law?

The regulation sets obligations. The implementing regulations fix the technical details and point to standards. The ARF is the reference document that ties all of it into one architecture: roles, flows, the data model, the trust model, high-level requirements per role, and rulebooks for each credential type. The European Commission publishes it openly on GitHub. Its current version, 3.0.0, was released on 23 July 2026 (ARF release).

Underneath sit open standards that anyone may use: IETF SD-JWT VC and ISO/IEC 18013-5 mdoc for credentials, OpenID4VCI and OpenID4VP with the HAIP profile for issuing and presenting them, the IETF Token Status List for revocation, X.509 certificates for institutions, and the ETSI trust list formats. ETSI TS 119 602 defines lists of trusted entities (LoTE), the JSON list format used for wallet providers, PID providers and other entities that are not qualified trust service providers (ETSI TS 119 602).

None of these standards is restricted to the EU. That is the opening for everyone else.

When does each part apply?

The eIDAS 2.0 timeline from the regulation in 2024 to the duty to accept wallets at the end of 2027
DateEventSource
20 May 2024Regulation (EU) 2024/1183 enters into forceArt. 2 of the regulation
24 December 2024First five implementing regulations in force: 2024/2977 (PID and attestations), 2024/2979 (wallet integrity and core functions), 2024/2980 (notifications), 2024/2981 (certification), 2024/2982 (protocols and interfaces)adopted 28 November 2024, published 4 December 2024
7 May 20252025/848 (registration of relying parties) and 2025/849 (list of certified wallets) publishedadopted 6 May 2025
30 July 20252025/1569 (qualified and public-sector attestations) publishedadopted 29 July 2025
22 July 20262026/1731 published, updating the standards referenced in four of the first actsadopted 15 July 2026
23 July 2026ARF 3.0.0 releasedGitHub
End of 2026Every member state provides at least one walletArt. 5a(1): 24 months after the implementing acts
End of 2027Private services that must use strong authentication (banking, transport, energy, health, education, telecoms and others) accept the wallet when the user asksArt. 5f(2): 36 months

For a verifier, the last row matters most. From the end of 2027 a bank in the EU must accept identification with a wallet when a person asks for it. The same dates, step by step, are in The European timeline.

How was it tested before the deadline?

The Commission funded large-scale pilots that ran the ARF in real services. Four of them started in April 2023: EWC (travel credentials), POTENTIAL (government services, banking, telecoms, driving licences, signatures and health), NOBID (payments) and DC4EU (education and social security). According to the Commission, they brought together more than 350 public and private organisations from 26 member states, Norway, Iceland and Ukraine (Commission: EUDI Wallet implementation). Two further pilots, WE BUILD and APTITUDE, started in 2025.

Ukraine's place in that list is worth noting. A country outside the EU took part in testing the system alongside member states. Taking part in pilots does not create legal recognition. It does show that the technical work is open to neighbours. DC4EU also tested education credentials, the kind that matters most for students and graduates moving between the Turkic states and Europe.

Why does alignment matter for a country outside the EU?

Because people, goods and qualifications already cross the border, and the paperwork is about to become digital on one side of it. Three situations recur:

  • Education. A graduate from Bishkek applies for a master's programme in Germany. If the diploma is a signed credential in an EU format, the admissions office's software can check it in seconds. If it is a scanned PDF, someone writes an email and waits.
  • Work and mobility. An engineer from Tashkent moves to Munich. Employers and banks in the EU will be set up to read wallet credentials; a credential in the same format slots into the same process.
  • Trade. A company in Baku proves its registration, licences or certificates to an EU partner. The same lists and formats that carry personal credentials carry those attestations.

In each case two different things have to be true. The credential must be readable, which is a matter of formats and protocols. And its issuer must be trusted, which is a matter of lists and recognition. The Tamga Trust Framework separates interoperability into three levels for this reason:

Three levels of interoperability: portability and trust are technical, legal recognition is political
  1. Portability. Same formats and protocols. An EU wallet or verifier can technically process the credential. This can be achieved today, by engineering.
  2. Trust. Trust lists that point to each other, with each list allowed to vouch only for a defined scope. This is technical too, but it needs a decision on each side about which lists to trust.
  3. Legal recognition. A state, or the EU, accepts another's credentials as having legal effect. This is decided by governments, through law or agreement.

The first two levels can be built ahead of the third, and that is the point of building early. When two governments decide to recognise each other's credentials, the systems that carry them are already compatible. Nobody has to reissue a diploma because the format changed.

What is the Turkic world already doing on digital trust?

The Organization of Turkic States has placed digital cooperation on its agenda. Its member states signed a Digital Economy Partnership Agreement at the Bishkek summit on 6 November 2024, covering e-commerce, paperless trade, electronic signatures, data protection and cybersecurity; Türkiye's ratification law was published in its Official Gazette in June 2026 (Daily Sabah). The informal summit in Turkistan on 15 May 2026 took artificial intelligence and digital development as its theme. Its declaration, as reported, calls on member states to complete their consideration of a draft agreement on the mutual recognition of electronic digital signatures, and Kazakhstan's president proposed mutual recognition of digital signatures and electronic documents (The Astana Times).

Mutual recognition of signatures is the legal level of the model above. A shared trust layer is the technical level underneath it. Tamga Network has no agreement with the Organization of Turkic States or any of its member states; it builds the technical level so that it is ready if states want to use it.

What does Tamga Network take from the EU model?

The technical layer, unchanged. Tamga's rule is that its credential, protocol and trust list formats do not depart from EU standards, and that any Tamga-specific addition goes through a standard extension point without breaking standard clients (ADR-0035).

EU elementIn Tamga Network
SD-JWT VC and ISO mdocthe same; identity credentials in both formats
OpenID4VCI, OpenID4VP, HAIP 1.0the same
Token Status Listthe same
LOTL and national trust liststhe same two-level model; a slot for each Turkic state
LoTE (ETSI TS 119 602)the first format read for external lists
Relying party registration and registration certificatesthe EU's common registration dataset and certificate model
The ARF role setevery role has a place in each national list, even when empty

The governance layer is written for the Turkic world: each state is the only author of its own list, and recognition between states is decided by each state for itself. The full mapping, and where Tamga's rules differ from the EU's and why, is in Tamga ARF: how we adapted the European framework.

The network's list of trusted lists already carries a slot for each member state of the Organization of Turkic States and for two observer states, and each state can take over its own list (why the network is bound for a foundation). Today only the Türkiye list is active, and Tamga publishes it provisionally on behalf of the national authority, as the list itself states. The others are reserved. You can read the live list at trust.tamga.network.

What are the honest limits?

  • Tamga Network is not recognised by the EU. It is EU-compatible: it speaks the same standards and shows this with tests. "EUDI Wallet" is a legal status for wallets provided or recognised by a member state and certified under EU rules. No network or wallet outside the EU can claim it today.
  • There is no shortcut through the regulation. Article 14 of eIDAS allows trust services from a third country to be treated as equivalent to EU qualified trust services, but only through an EU implementing act or an agreement between the EU and that country under Article 218 TFEU. That is a negotiation between governments. Tamga can make the technical side ready; it cannot start or conclude that process.
  • No external list has been added yet. The mechanism for pointing to another state's list or to an EU list is in place, with a pinned signer and a defined scope (ADR-0036). Each addition is a separate, recorded decision, and none has been made.
  • The trust anchor rests on one operator today. The lists are signed, versioned and publicly logged, but until a second independent operator joins, the network relies on a single signature. This is stated in the framework as a known limit (Tamga ARF).
  • Recognition between Turkic states is also political. A Kazakh verifier trusting a Turkish university is a decision for Kazakhstan. The network makes that decision easy to express and to enforce in software; it does not make it.

Frequently asked questions

Does eIDAS 2.0 apply to Türkiye or the Central Asian states?

No. It binds EU member states and services covered in the EU. Its standards are open, so any state or institution can use them, and companies offering services inside the EU should check their own obligations with a lawyer.

Can a credential issued in Türkiye be accepted in the EU?

It can be read by EU software if it uses the same formats, which Tamga credentials do. Being trusted with legal effect needs recognition of its issuer, through trust lists and, for qualified status, an agreement or implementing act under Article 14.

What is the difference between the regulation and the ARF?

The regulation and its implementing acts are law. The ARF is the Commission's technical reference that describes the architecture, roles and requirements those acts rely on. Version 3.0.0 is current, released on 23 July 2026.

Is Tamga Network working with the Organization of Turkic States?

No. There is no agreement with the organisation or its member states. The network reserves a list slot for each of them and is designed so that a state can take over its own list whenever it chooses.

Why build now if recognition depends on governments?

Because the technical levels take time and do not depend on a political decision. If they are ready, a later recognition decision applies to credentials people already hold, without reissuing them.

Sources

Build on the network

Learn the concepts from scratch, or see how an institution, verifier, wallet or state joins.

Back to all posts